TemplatesFree

ISO 27001:2022 Statement of Applicability (SoA) Template

Document the applicability of all 93 ISO 27001:2022 Annex A controls along with their justifications.

In short

The Statement of Applicability (SoA) is the document declaring which Annex A controls an organisation applies, which it excludes, and the reasoning behind each decision. ISO 27001:2022 clause 6.1.3 d) requires it, and the SoA is the first document an auditor reads — before the policies, before the risk register.

Format
XLSX · DOCX
Size
24 KB
Price
Free

Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.

What This Document Is For

The SoA is often treated as a tick-box list produced the day before an audit. Auditors recognise the pattern quickly: a justification column repeating the same sentence ninety-three times, and an implementation status claiming everything is running while the supporting documents carry no date.

This template carries all 93 ISO/IEC 27001:2022 Annex A controls — grouped into the four 2022 themes (organisational, people, physical, technological), not the 114-control structure of the 2013 version. Each row provides room for the applicability decision, its reasoning, implementation status, and a reference to the document or system that evidences it.

Most Useful For

  • Organisations producing their first SoA for a certification audit
  • ISO 27001:2013 certificate holders transitioning to the 2022 revision
  • Teams needing to show the link between assessed risks and selected controls

What's Inside

01

93 Annex A 2022 controls

Complete with official numbering and titles, grouped as A.5 Organisational, A.6 People, A.7 Physical, and A.8 Technological.

02

Applicability column

Applied or excluded, with written justification — the column auditors check row by row.

03

Implementation status

Not started, in progress, or operating, so the SoA doubles as a project progress map.

04

Evidence reference

A pointer to the policy, procedure, or system proving the control actually operates.

05

Risk mapping

A column linking to risk numbers in the risk register, so control selection visibly follows from the risk assessment.

Standards & Regulations It Helps Satisfy

Standard / RegulationClause / ArticleWhat this document covers
ISO/IEC 27001:2022Clause 6.1.3 d)The requirement to produce a Statement of Applicability with justifications for inclusion and exclusion.
ISO/IEC 27001:2022Annex A (93 controls)Every control across themes A.5–A.8 in the 2022 structure.
SNI ISO/IEC 27001:2022IdenticalThe Indonesian national adoption — clauses and Annex A are the same, so one SoA serves both.

This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.

Questions About This Document

Can Annex A controls be excluded?

Yes, and it is normal. What is not acceptable is excluding without a sensible reason. A commonly accepted exclusion: application development controls at an organisation that develops no software. One that will be challenged: excluding cryptographic controls because there was no time.

How does a 2013 SoA differ from a 2022 one?

The 2013 version carried 114 controls across 14 domains; 2022 carries 93 across 4 themes, with 11 new controls and several old ones merged. An old SoA cannot be reused as-is — remapping is mandatory, and this template already uses the new structure.

How detailed should each justification be?

One or two sentences explaining why the control is relevant (or not) to your organisation specifically. A justification that restates the control title explains nothing and will produce a finding.

Related Reading

Background that helps you fill this document in correctly, rather than merely filling it in.

Need guidance, not just a template?

A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.