A Statement of Applicability, also known as an SoA, is a document that assesses an organization's security risks and outlines the specific controls that have been put in place to mitigate those risks. An SoA is typically required as part of a compliance audit, such as ISO 27001 or SOC 2.
An SoA is divided into three sections:
1. The first section lists all security risks that have been identified for the organization in question.
2. The second section describes the specific controls that have been implemented to mitigate those risks.
3. The third section outlines the planned future measures the organization will take to further reduce its risk profile.
The content of a Statement of Applicability depends on the specific compliance requirements an organization is trying to meet. However, all Statements of Applicability should be clear, concise, and easy to understand.
Why Are Statements of Applicability Important?
Organizations use Statements of Applicability to demonstrate their commitment to security and to show that they have taken steps to address their specific security risks. For example, a Statement of Applicability may be requested by a potential customer or business partner as part of due diligence. In any case, an SoA is an important document that can help build trust in a company's security posture.
How Do I Create a Statement of Applicability?
The process for creating a Statement of Applicability depends on the specific compliance requirements you are trying to meet. However, there are some general best practices you should follow when creating an SoA:
1. Make sure your Statement of Applicability is clear, concise, and easy to understand. Keep in mind that your audience may not be familiar with technical jargon or industry-specific terminology.
2. Use plain language and avoid abbreviations or acronyms where possible.
3. Be honest and transparent in your risk assessment, and don't try to downplay the significance of any particular control.
4. Provide a contact name and email address so readers can obtain further information if needed.
5. Review your SoA regularly and update it whenever your security posture changes (e.g., after implementing new controls or when an incident occurs).
Conclusion
Companies use Statements of Applicability to demonstrate their commitment to security and to outline the steps they have taken to address their specific security risks. Creating a well-crafted Statement of Applicability requires taking some time upfront to assess your organization's risks and determine which controls are appropriate to mitigate them.
FAQ
What is the Statement of Applicability (SoA) in ISO 27001, and what is its function?
What is the Statement of Applicability (SoA) in ISO 27001, and what is its function?
The Statement of Applicability is a central document within an information security management system (ISMS). It clearly lists all information security controls contained in Annex A of the ISO 27001 standard. For each individual control, it is bindingly determined whether it applies to the company or not. The main function of the SoA is to transparently demonstrate to the certification auditor and external partners which security standards apply in the company, how they are implemented, and why certain measures may have been excluded.
How is the SoA connected to the risk assessment?
How is the SoA connected to the risk assessment?
The SoA is the direct result of the previously conducted risk assessment. In a first step, a company identifies its specific IT and information security risks. It then reviews the controls in Annex A of the standard to determine which measures are suitable for reducing these risks to an acceptable level. The SoA documents this connection without gaps: every selection or exclusion of a control must be conclusively derived from the risk analysis, legal requirements, or contractual obligations.
Can a company exclude certain ISO 27001 controls from the SoA?
Can a company exclude certain ISO 27001 controls from the SoA?
Yes, this is expressly permitted and often sensible. Not every control from Annex A fits every business model. For example, if a company develops pure cloud software and doesn't operate its own physical servers or data centers, controls for the physical security of data centers can be excluded. What matters, however, is the justification: every exclusion must be comprehensibly justified in the SoA, for example by the absence of corresponding risks, physical circumstances, or regulatory requirements.
What information must a compliant SoA contain at a minimum?
What information must a compliant SoA contain at a minimum?
For the Statement of Applicability to successfully pass an ISO 27001 audit, it should contain the following core information for all controls from Annex A:
- List of all controls: A completeness check of all measures defined in Annex A of ISO 27001.
- Applicability status: A clear indication for each control of whether it is applicable or not ("Yes" / "No").
- Justification for selection or exclusion: A comprehensible rationale for why a measure was chosen or justifiably omitted.
- Implementation status: Information on whether the measure is already fully implemented, in planning, or in continuous operation.
- References to policies: References to internal documents, work instructions, or policies that put the respective control into practice.







