Definition

Statement of Applicability

The Statement of Applicability, or SoA, is the ISO 27001 document that lists every Annex A control, states whether you apply it, and explains why. When you exclude a control, you record the reason; when you include one, you note how you implement it. Auditors treat the SoA as the map of your ISMS, because it links your risk assessment to the specific safeguards you chose. It is one of the few ISO 27001 documents that is mandatory by name, and certification bodies review it closely to confirm your control selection actually matches the risks you identified.

FINAUDIT CPA · ASSURANCE · VERIFIED · INDEPENDENT ·

Ready when you are

Ready to make trust your competitive advantage?

One licensed CPA firm for your SOC, ISO, HIPAA, and VAPT programs — and the financial audits behind them. Talk to a senior auditor, not a sales rep.

Call Book a Consultation