Statement of Applicability
A Statement of Applicability (SoA) is a core document used when building an information security management system under the ISO/IEC 27001 standard. It records which security controls an organization has decided are relevant, which it has excluded, and the reasoning behind each decision. Note that ISO/IEC 27001 is a voluntary standard rather than a law, though organizations may be required to follow it by contract or as a step toward certification.
The Statement of Applicability (SoA) is a mandatory document within an ISO/IEC 27001 Information Security Management System (ISMS) that identifies the information security controls selected by the organization, justifies their inclusion or exclusion, and links them to the results of risk treatment decisions. It functions as a central reference mapping applicable controls to the organization's security posture and is generally required for those pursuing ISO/IEC 27001 certification. The SoA reflects a voluntary or contractual obligation under the standard rather than a statutory requirement, and its specific content and format depend on the version of ISO/IEC 27001 in force (for example, the controls set in the 2022 revision); readers should verify requirements against the current official ISO/IEC text and applicable certification scheme.
Why it matters
The Statement of Applicability sits at the heart of an ISO/IEC 27001 Information Security Management System because it is where an organization's abstract risk decisions become a documented, auditable record. Rather than simply asserting that controls are in place, the SoA obliges the organization to state explicitly which controls it has selected, which it has excluded, and the justification for each choice. For anyone pursuing ISO/IEC 27001 certification, this is a mandatory document, and certification auditors typically use it as a primary reference point when checking whether the ISMS as described matches the controls actually implemented.
The SoA matters because it links risk treatment decisions to concrete controls in a single traceable place. Gaps, unsupported exclusions, or inconsistencies between the SoA and operational reality are among the issues an auditor is likely to scrutinize. Because ISO/IEC 27001 is a voluntary standard rather than a statutory requirement, the obligation to maintain an SoA generally arises from the pursuit of certification or from contractual commitments to customers or partners, not from law. Organizations should treat it as a living document that reflects their current security posture rather than a one-time compliance artifact.
Readers should note that the specific control set an SoA references depends on the version of ISO/IEC 27001 in force, and the standard is periodically revised. The content, expected format, and the way certification bodies assess an SoA can therefore change over time, and requirements should be verified against the current official ISO/IEC text and the applicable certification scheme rather than assumed to be fixed.
Who it's relevant to
Inside SoA
Common questions
Answers to the questions practitioners most commonly ask about SoA.

