A Statement of Applicability (SoA) is a mandatory document in ISO 27001 — but it's also where many ISMS projects stall. Listing your controls isn't enough; you need to justify why each control from Annex A is included or excluded, and show how that connects back to your risk assessment. This guide walks you through the process — from risk identification to a finished SoA.

This whitepaper includes:

  • How to move from risk identification and analysis to a concrete selection of controls
  • The 4 ways to treat a risk — and when to choose which
  • Which sources beyond ISO 27002 you can draw on when selecting controls — e.g. GDPR, PCI DSS, and sector-specific requirements
  • The 4 elements every control in your SoA should document, so it holds up under an auditor's review

Who is this guide for?

This guide is written for teams preparing for ISO 27001 certification who need to get their SoA right as part of their ISMS — typically CISOs, compliance officers, and risk managers.