ISO 27001

Statement of Applicability

Generate the mandatory ISO 27001 Statement of Applicability from your program: every Annex A control, its applicability, justification, and status, exported as a branded PDF.

Start free See pricing
Statement of Applicability walkthrough

The Statement of Applicability is the document every ISO 27001 auditor asks for first, the required output of Clause 6.1.3 that says, for each Annex A control, whether it applies to you, why, and how it’s implemented. Keel builds it from the program you’re already running: all 93 Annex A:2022 controls, their applicability, a justification for each, and a live implementation status drawn from the controls you’ve mapped, then exports a branded, auditor-ready PDF.

The SoA is mandatory, and usually maintained by hand

Most teams keep their Statement of Applicability in a spreadsheet that’s copied from a template and drifts out of date the moment a control changes. When the auditor asks for it, someone reconciles 93 rows against the real program from memory. It’s the one ISO 27001 artifact you can’t skip, and the easiest one to let rot.

What statement of applicability does

All 93 Annex A:2022 controls, pre-loaded

Keel ships the full ISO/IEC 27001:2022 Annex A set, the four themes (Organizational, People, Physical, Technological) and every control within them, so your SoA starts complete instead of from a blank template.

Applicability that stays in sync

Applicability is driven by your scope: include or exclude a control on the SoA (or on the Scope page) and both update together, along with your readiness score. One decision, one place, no divergence between your SoA and your program.

A justification for every control

Record why each control applies (often from your risk assessment or a legal, regulatory, or contractual requirement) or the reason you’ve excluded it. Clause 6.1.3 asks for exactly this, and it prints on the SoA.

Implementation status, pulled live

For each Annex A control, Keel rolls up the status of the controls you’ve crosswalked to it (implemented, in progress, or a gap), so the SoA reflects your real posture instead of a static claim.

Document control built in

Set a version, the ISMS scope statement, and who approved the SoA and when. Those details print on the document header, so what you hand the auditor is a controlled record, not a loose export.

Branded, auditor-ready PDF

Export the whole Statement of Applicability as a branded, print-ready PDF in a click, the artifact your certification auditor expects, generated from live data every time.

Why it matters

  • Produce the mandatory ISO 27001 SoA without maintaining a spreadsheet
  • Keep applicability, scope, and readiness in lockstep automatically
  • Show a justification and a real implementation status for all 93 Annex A controls
  • Hand your auditor a branded, current SoA PDF on demand

Get audit-ready, and prove it

Statement of Applicability is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.

Start free

Frequently asked questions

What is a Statement of Applicability?

It’s the mandatory ISO 27001 document required by Clause 6.1.3 d. For every Annex A control it records whether the control is applicable, the justification for including or excluding it, and its implementation status. It’s typically the first artifact a certification auditor reviews.

How many Annex A controls does it cover?

ISO/IEC 27001:2022 Annex A has 93 controls across four themes: Organizational, People, Physical, and Technological. Keel pre-loads all of them, so your SoA is complete from the start.

Where does the implementation status come from?

From your own controls. Keel crosswalks the controls you implement to the Annex A references they satisfy, then rolls those up per control, so the SoA shows implemented, in progress, or gap based on your live program, not a manual entry.

Can I exclude controls that don’t apply?

Yes. Mark a control excluded on the SoA (or on the Scope page) and record the justification. Excluding it removes it from your readiness calculation too, so your SoA and your program never disagree.

Can I export it for my auditor?

Yes. Export the full Statement of Applicability as a branded, print-ready PDF, with your version, ISMS scope statement, and approver details on the header.