ISO 27001:2022 Statement of Applicability (SoA) Template
Document the applicability of all 93 ISO 27001:2022 Annex A controls along with their justifications.
In short
The Statement of Applicability (SoA) is the document declaring which Annex A controls an organisation applies, which it excludes, and the reasoning behind each decision. ISO 27001:2022 clause 6.1.3 d) requires it, and the SoA is the first document an auditor reads — before the policies, before the risk register.
- Format
- XLSX · DOCX
- Size
- 24 KB
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
What This Document Is For
The SoA is often treated as a tick-box list produced the day before an audit. Auditors recognise the pattern quickly: a justification column repeating the same sentence ninety-three times, and an implementation status claiming everything is running while the supporting documents carry no date.
This template carries all 93 ISO/IEC 27001:2022 Annex A controls — grouped into the four 2022 themes (organisational, people, physical, technological), not the 114-control structure of the 2013 version. Each row provides room for the applicability decision, its reasoning, implementation status, and a reference to the document or system that evidences it.
Most Useful For
- Organisations producing their first SoA for a certification audit
- ISO 27001:2013 certificate holders transitioning to the 2022 revision
- Teams needing to show the link between assessed risks and selected controls
What's Inside
93 Annex A 2022 controls
Complete with official numbering and titles, grouped as A.5 Organisational, A.6 People, A.7 Physical, and A.8 Technological.
Applicability column
Applied or excluded, with written justification — the column auditors check row by row.
Implementation status
Not started, in progress, or operating, so the SoA doubles as a project progress map.
Evidence reference
A pointer to the policy, procedure, or system proving the control actually operates.
Risk mapping
A column linking to risk numbers in the risk register, so control selection visibly follows from the risk assessment.
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 6.1.3 d) | The requirement to produce a Statement of Applicability with justifications for inclusion and exclusion. |
| ISO/IEC 27001:2022 | Annex A (93 controls) | Every control across themes A.5–A.8 in the 2022 structure. |
| SNI ISO/IEC 27001:2022 | Identical | The Indonesian national adoption — clauses and Annex A are the same, so one SoA serves both. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
Can Annex A controls be excluded?
Yes, and it is normal. What is not acceptable is excluding without a sensible reason. A commonly accepted exclusion: application development controls at an organisation that develops no software. One that will be challenged: excluding cryptographic controls because there was no time.
How does a 2013 SoA differ from a 2022 one?
The 2013 version carried 114 controls across 14 domains; 2022 carries 93 across 4 themes, with 11 new controls and several old ones merged. An old SoA cannot be reused as-is — remapping is mandatory, and this template already uses the new structure.
How detailed should each justification be?
One or two sentences explaining why the control is relevant (or not) to your organisation specifically. A justification that restates the control title explains nothing and will produce a finding.
Related Reading
Background that helps you fill this document in correctly, rather than merely filling it in.
Documents Often Taken Together With This One
Risk Register Template
Manage information security risk identification, assessment, and mitigation in one structured worksheet.
Free DownloadInformation Security Policy Template
An organization-level information security policy framework ready to tailor to your business context.
Free DownloadROPA Template — Records of Processing Activities
Document all of your organization's personal data processing activities in a structured format, as mandated by Indonesia's PDP Law No. 27 of 2022.
Free DownloadNeed guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.