What is a Statement of Applicability (SoA)?
The Statement of Applicability (SoA) is a document that defines which security controls from Annex A of ISO 27001 apply to your Information Security Management System (ISMS).
The SoA connects three key elements: your risk assessment, the security controls you've selected, and evidence that no relevant controls have been overlooked. This makes it one of the first documents auditors typically request – and one that customers may also want to review as part of their security questionnaires.
Mandatory SoA Requirements Under ISO 27001:2022
Clause 6.1.3 d) requires four specific pieces of information. Two additional fields are not mandatory under the standard but can make the audit process significantly easier.
Overview of the 93 Controls in Annex A
ISO 27001:2022 streamlined the previous 114 controls across 14 domains into 93 controls organized into four themes.
These 11 Controls Were Introduced in 2022
- 5.7 Threat Intelligence
- 5.23 Information Security for Use of Cloud Services
- 5.30 ICT Readiness for Business Continuity
- 7.4 Physical Security Monitoring
- 8.9 Configuration Management
- 8.10 Information Deletion
- 8.11 Data Masking
- 8.12 Data Leakage Prevention (DLP)
- 8.16 Monitoring Activities
- 8.23 Web Filtering
- 8.28 Secure Coding
These are precisely the controls that are often missing from SoAs copied from outdated ISO 27001:2013 templates.
How to Create an SoA in 6 Steps
- Define the scope. Identify the locations, systems, processes, and service providers covered by your ISMS. These determine which controls may be relevant in the first place.
- Assess your risks. Identify assets, threats, and vulnerabilities, then evaluate each risk based on its likelihood and potential impact.
- Plan risk treatment. Define appropriate measures for every risk that cannot be accepted, regardless of where those measures originate.
- Cross-check against Annex A. Review all 93 controls to ensure no necessary controls have been overlooked. Justify each decision based on risks, legal requirements, or contractual obligations.
- Document implementation status and evidence. Record the implementation status, responsible owners, and supporting evidence for each control.
- Approve and maintain version control. Have senior management approve the SoA and review it whenever the scope changes, following security incidents, and at least once a year.
Example: What a Completed SoA Looks Like
Fictional example: a SaaS company with 40 employees, operating entirely in the cloud, with no dedicated data center.
Common Mistakes in the SoA
The SoA in the Certification Audit
During Stage 1, the certification body checks whether the SoA is complete and aligned with the risk assessment. In Stage 2, auditors conduct sample checks to verify whether controls marked as "implemented" are actually effective in practice. After certification, the SoA remains a key reference document for annual surveillance audits.
Automating and Managing Your SoA with heyData
At heyData, we support companies throughout their entire journey to ISO 27001 certification – and the Statement of Applicability (SoA) plays a central role in that process. We don't just provide a tool to document your SoA. We actively help you build it correctly and continuously adapt it as your ISMS evolves.
Our approach ensures that your SoA doesn't remain a static document but becomes a dynamic reflection of your information security strategy.
With heyData, you can:
- Link Annex A controls to your risk assessment and security policies.
- Generate your SoA based on your asset and risk registers, with clear traceability and supporting evidence for every control.
- Track implementation progress and assign responsibilities transparently.
- Stay audit-ready with version control and change tracking for every SoA update.
- Drive continuous improvement by incorporating findings from audits and management reviews directly into your SoA.
In short: heyData transforms your SoA from a compliance requirement into a living management tool that brings governance, risk, and security together in one central system.
FAQ
What is the Statement of Applicability under ISO 27001:2022?
What is the Statement of Applicability under ISO 27001:2022?
The SoA is a mandatory document that lists all 93 security controls (Annex A controls) and describes whether they're implemented, planned, or excluded.
Why is the SoA so important?
Why is the SoA so important?
It's the central proof for auditors that your ISMS is based on a conscious risk assessment.
How often should the SoA be updated?
How often should the SoA be updated?
At least once a year or after significant changes in the company.
Who creates the SoA?
Who creates the SoA?
Usually the ISMS team or the data protection or information security officer.
How can I automate the SoA?
How can I automate the SoA?
With tools like heyData, you can automatically maintain your SoA, version it, and export it audit-ready.








