Statement of Applicability (SoA) in ISO 27001 Certification

Martin Bastius
28.10.2025
5
min.

Use AI to summarize this article

What is a Statement of Applicability (SoA)?

The Statement of Applicability (SoA) is a document that defines which security controls from Annex A of ISO 27001 apply to your Information Security Management System (ISMS).

The SoA connects three key elements: your risk assessment, the security controls you've selected, and evidence that no relevant controls have been overlooked. This makes it one of the first documents auditors typically request – and one that customers may also want to review as part of their security questionnaires.

Mandatory SoA Requirements Under ISO 27001:2022

Clause 6.1.3 d) requires four specific pieces of information. Two additional fields are not mandatory under the standard but can make the audit process significantly easier.

Control Applicable Justification Status Evidence
5.23 Information Security for Use of Cloud Services Yes R-07 hosting provider outage; customer contracts Implemented Cloud policy v2, provider assessment
6.3 Information Security Awareness, Education and Training Yes R-02 phishing; ISO requirement Implemented LMS training records
7.8 Equipment Siting and Protection No No company-owned server room, office workstations only – Scope document
8.12 Data Leakage Prevention Yes R-11 leakage of customer data Partially implemented, target 31 March DLP concept, ticket SEC-42
8.28 Secure Coding Yes R-14 vulnerabilities in proprietary code Implemented Secure coding guideline, CI scans

Overview of the 93 Controls in Annex A

ISO 27001:2022 streamlined the previous 114 controls across 14 domains into 93 controls organized into four themes.

Topic Clause Number of Controls Examples
Organizational Controls A.5 37 Policies, supplier relationships, incident management
People Controls A.6 8 Screening, training, remote working
Physical Controls A.7 14 Physical access control, clear desk, disposal of storage media
Technological Controls A.8 34 Access rights, backups, logging, secure development

These 11 Controls Were Introduced in 2022

  1. 5.7 Threat Intelligence
  2. 5.23 Information Security for Use of Cloud Services
  3. 5.30 ICT Readiness for Business Continuity
  4. 7.4 Physical Security Monitoring
  5. 8.9 Configuration Management
  6. 8.10 Information Deletion
  7. 8.11 Data Masking
  8. 8.12 Data Leakage Prevention (DLP)
  9. 8.16 Monitoring Activities
  10. 8.23 Web Filtering
  11. 8.28 Secure Coding

These are precisely the controls that are often missing from SoAs copied from outdated ISO 27001:2013 templates.

How to Create an SoA in 6 Steps

  1. Define the scope. Identify the locations, systems, processes, and service providers covered by your ISMS. These determine which controls may be relevant in the first place.
  2. Assess your risks. Identify assets, threats, and vulnerabilities, then evaluate each risk based on its likelihood and potential impact.
  3. Plan risk treatment. Define appropriate measures for every risk that cannot be accepted, regardless of where those measures originate.
  4. Cross-check against Annex A. Review all 93 controls to ensure no necessary controls have been overlooked. Justify each decision based on risks, legal requirements, or contractual obligations.
  5. Document implementation status and evidence. Record the implementation status, responsible owners, and supporting evidence for each control.
  6. Approve and maintain version control. Have senior management approve the SoA and review it whenever the scope changes, following security incidents, and at least once a year.

Example: What a Completed SoA Looks Like

Fictional example: a SaaS company with 40 employees, operating entirely in the cloud, with no dedicated data center.

Control Applicable Justification Status Evidence
5.23 Information Security for Use of Cloud Services Yes R-07 hosting provider outage; customer contracts Implemented Cloud policy v2, provider assessment
6.3 Information Security Awareness, Education and Training Yes R-02 phishing; ISO requirement Implemented LMS training records
7.8 Equipment Siting and Protection No No company-owned server room, office workstations only – Scope document
8.12 Data Leakage Prevention Yes R-11 leakage of customer data Partially implemented, target 31 March DLP concept, ticket SEC-42
8.28 Secure Coding Yes R-14 vulnerabilities in proprietary code Implemented Secure coding guideline, CI scans

Common Mistakes in the SoA

Mistake Impact on the Audit Solution
Exclusion Without Justification Nonconformity Justify every exclusion based on scope or risk
Template Adopted Without Review Controls do not fit the organization Relate each row to the organization’s actual risks
Still Using the 2013 Structure (114 Controls) SoA is not aligned with the current standard Update to the 93 controls of the 2022 version
No Link to the Risk Assessment Control selection is not traceable Reference risk IDs in the justification
No Version Control Unclear which version is valid Include version, date and approval in the SoA header
“Implemented” Without Evidence Finding during Stage 2 Link evidence for each control

The SoA in the Certification Audit

During Stage 1, the certification body checks whether the SoA is complete and aligned with the risk assessment. In Stage 2, auditors conduct sample checks to verify whether controls marked as "implemented" are actually effective in practice. After certification, the SoA remains a key reference document for annual surveillance audits.

Automating and Managing Your SoA with heyData

At heyData, we support companies throughout their entire journey to ISO 27001 certification – and the Statement of Applicability (SoA) plays a central role in that process. We don't just provide a tool to document your SoA. We actively help you build it correctly and continuously adapt it as your ISMS evolves.

Our approach ensures that your SoA doesn't remain a static document but becomes a dynamic reflection of your information security strategy.

With heyData, you can:

  • Link Annex A controls to your risk assessment and security policies.
  • Generate your SoA based on your asset and risk registers, with clear traceability and supporting evidence for every control.
  • Track implementation progress and assign responsibilities transparently.
  • Stay audit-ready with version control and change tracking for every SoA update.
  • Drive continuous improvement by incorporating findings from audits and management reviews directly into your SoA.

In short: heyData transforms your SoA from a compliance requirement into a living management tool that brings governance, risk, and security together in one central system.

FAQ

What is the Statement of Applicability under ISO 27001:2022?

The SoA is a mandatory document that lists all 93 security controls (Annex A controls) and describes whether they're implemented, planned, or excluded.

Why is the SoA so important?

It's the central proof for auditors that your ISMS is based on a conscious risk assessment.

How often should the SoA be updated?

At least once a year or after significant changes in the company.

Who creates the SoA?

Usually the ISMS team or the data protection or information security officer.

How can I automate the SoA?

With tools like heyData, you can automatically maintain your SoA, version it, and export it audit-ready.

Published
28.10.2025
Last updated
08.10.2026
Martin Bastius
Co-Founder & CLO

More articles

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
View all articles
Information Security & ISO 27001
9/30/26

The hardest part of the ISO 27001 standard is not the security

The hardest part of the ISO 27001 standard is not the security
Information Security & ISO 27001
9/9/26

ISO 27001 as a sales tool: How certification is changing enterprise procurement

ISO 27001 as a sales tool: How certification is changing enterprise procurement
Information Security & ISO 27001
8/19/26

ISO 27001 certified – Why are you still getting hacked?

ISO 27001 certified – Why are you still getting hacked?
Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Discover all stories