Get started

Compliance Tools

The Statement of Applicability (SoA) is the central document in ISO 27001 certification. It lists all 93 Annex A controls from the 2022 revision and records whether each one applies to your organisation, how it's implemented, and what evidence supports it.

What is a Statement of Applicability?

An SoA is required for ISO 27001 certification. For each of the 93 security controls, you must declare:

  • Applicable — the control is relevant and must be implemented
  • Not Applicable — the control does not apply (with a documented justification)
  • Inherited — another part of your organisation or a third-party service satisfies this control

Your certification auditor will walk through every row of the SoA during their Stage 2 audit.

How to use the SoA Builder

Navigate to Compliance Command Center → ISO 27001 tab.

Control groups

The 93 controls are organised into four groups:

GroupNameControls
A.5Organisational Controls37
A.6People Controls8
A.7Physical Controls14
A.8Technological Controls34

Marking applicability

Every control is marked by hand: you set each one Applicable or Not Applicable and record the justification. Your AOCL and VOLT governance data is the natural evidence source to cite for A.8 Technological Controls, and automatic pre-marking from that data is on the roadmap but not in the product today.

Working with the table

  • Click a group header to expand or collapse it
  • Click the applicability toggle (Yes / N/A / Inherited) on any control to set its status
  • Click the justification field to add a note explaining your decision
  • Use the filter bar to show only controls from a specific group, or filter by assessment status
  • Select multiple controls (via the group checkbox) and use bulk actions to mark them all at once

Lifecycle

Your SoA has three states:

  1. Draft — you're still working on it
  2. Review — submitted for internal review before sharing with your auditor
  3. Approved — finalised and ready for your certification auditor

Export

Click the export button to download your SoA as JSON (for system integration) or CSV (for spreadsheets).

Frequently asked questions

What is a Statement of Applicability and why do we need one?

The SoA is the central document in ISO 27001 certification. It lists all 93 Annex A controls from the 2022 revision and records whether each applies to your organisation, how it's implemented, and what evidence supports it. Your certification auditor will walk through every row of the SoA during their Stage 2 audit.

What are the three status options for each control?

Applicable, meaning the control is relevant and must be implemented; Not Applicable, meaning the control does not apply and needs a documented justification; or Inherited, meaning another part of your organisation or a third party service satisfies it.

Are any controls detected automatically?

Not yet. Every control is marked by hand today, with your justification recorded per control. Automatic pre-marking of A.8 Technological Controls from AOCL and VOLT evidence is on the roadmap but not in the product.

What formats can we export the SoA in?

You can download your SoA as JSON, for system integration, or CSV, for spreadsheets.

Glossary

TermDefinition
SoAStatement of Applicability — the ISO 27001 document listing every Annex A control and your decision about it
Annex AThe section of ISO 27001:2022 containing the 93 security controls
Stage 2 AuditThe on-site (or remote) certification audit where the auditor tests whether your ISMS is actually implemented
ISMSInformation Security Management System — the overall framework of policies, procedures, and controls