Templates
ISO 27001:2022 Statement of Applicability (SoA) Template
Document the applicability of all 93 ISO 27001:2022 Annex A controls along with their justifications.
- Format
- XLSX · DOCX
- Size
- 24 KB
- Language
- Indonesian & English
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
In short
The Statement of Applicability (SoA) is the document declaring which Annex A controls an organisation applies, which it excludes, and the reasoning behind each decision. ISO 27001:2022 clause 6.1.3 d) requires it, and the SoA is the first document an auditor reads — before the policies, before the risk register.
What This Document Is For
The SoA is often treated as a tick-box list produced the day before an audit. Auditors recognise the pattern quickly: a justification column repeating the same sentence ninety-three times, and an implementation status claiming everything is running while the supporting documents carry no date.
This template carries all 93 ISO/IEC 27001:2022 Annex A controls — grouped into the four 2022 themes (organisational, people, physical, technological), not the 114-control structure of the 2013 version. Each row provides room for the applicability decision, its reasoning, implementation status, and a reference to the document or system that evidences it.
What's Inside
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 6.1.3 d) | The requirement to produce a Statement of Applicability with justifications for inclusion and exclusion. |
| ISO/IEC 27001:2022 | Annex A (93 controls) | Every control across themes A.5–A.8 in the 2022 structure. |
| SNI ISO/IEC 27001:2022 | Identical | The Indonesian national adoption — clauses and Annex A are the same, so one SoA serves both. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
Can Annex A controls be excluded?
Yes, and it is normal. What is not acceptable is excluding without a sensible reason. A commonly accepted exclusion: application development controls at an organisation that develops no software. One that will be challenged: excluding cryptographic controls because there was no time.
How does a 2013 SoA differ from a 2022 one?
The 2013 version carried 114 controls across 14 domains; 2022 carries 93 across 4 themes, with 11 new controls and several old ones merged. An old SoA cannot be reused as-is — remapping is mandatory, and this template already uses the new structure.
How detailed should each justification be?
One or two sentences explaining why the control is relevant (or not) to your organisation specifically. A justification that restates the control title explains nothing and will produce a finding.
Need guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.