Free resource · ISO/IEC 27001:2022

ISO 27001 Statement of Applicability Template

Build your mandatory SoA across all four Annex A 2022 themes — with applicability, justification and implementation-status columns, including the 11 new controls. Download the CSV to start.

A.5

Organizational controls

37 controls

Policies, roles, access control, supplier & cloud security, incident management, ICT continuity, threat intelligence (new in 2022).

A.6

People controls

8 controls

Screening, awareness training, disciplinary process, remote working, event reporting.

A.7

Physical controls

14 controls

Perimeters, physical entry, monitoring (new in 2022), storage media, secure disposal.

A.8

Technological controls

34 controls

Endpoints, authentication, malware, vulnerability & configuration management (new), DLP (new), logging & monitoring (new), cryptography, secure development & coding (new), web filtering (new).

Your SoA needs a row per Annex A control with four things: applicable (Y/N), the justification (legal / contractual / business / risk-treatment, or reason for exclusion), the implementation status, and a reference to the control’s evidence. The downloadable CSV lays out these columns across all four themes and flags the 11 controls new in 2022.

Based on ISO/IEC 27001:2022 Annex A (93 controls). The CSV includes a representative selection across all four themes and every new-in-2022 control — extend it to the full 93 for your live SoA. See iso.org for the authoritative standard.

Statement of Applicability FAQ

What is a Statement of Applicability?
The Statement of Applicability (SoA) is the central ISO 27001 document that lists every Annex A control, states whether it is applicable, gives the justification for including or excluding it, and records its implementation status. It is mandatory (clause 6.1.3 d) and is one of the first things an auditor asks to see — it ties your risk treatment to specific controls.
How many controls are in Annex A of ISO 27001:2022?
ISO/IEC 27001:2022 has 93 Annex A controls, reorganised into four themes — Organizational (A.5, 37 controls), People (A.6, 8), Physical (A.7, 14) and Technological (A.8, 34). The 2013 version had 114 controls in 14 domains; the 2022 revision merged many and added 11 new controls (e.g. threat intelligence, cloud services, DLP, configuration management, secure coding).
How do I justify including or excluding a control?
For each control record why it applies — typically a legal, contractual, business or risk-treatment reason — or, if excluded, the justification for exclusion. Exclusions must be defensible: you cannot simply drop a control because it is inconvenient. This template gives you the applicability, justification and status columns to make that explicit.
Can CATAAM generate the SoA for me?
CATAAM maintains an Annex A control library, links controls to your risk treatment, and continuously collects evidence for the technical controls — so your Statement of Applicability and its implementation status stay current automatically instead of drifting from reality between audits.

Keep your SoA true to reality

CATAAM links Annex A controls to your risk treatment and collects the evidence continuously — so your Statement of Applicability and its status never drift from what’s actually running.