ISO 27001 Statement of Application (SoA) template
How to build a SoA document for certification.
Statement of Application - ISO 27001 mandatory document which lists all 93 Annex A controls with a mark on their applicability. For each control: 1) Control ID (A.5.1, A.5.2) and title; 2) Used (Yes/No); 3) Justification for exclusion (if No) or links to policies/procedures (if Yes); 4) Implementation status (planned, partial, implemented, optimised); 5) Responsible; 6) Date of verification. SoA is reviewed annually and after major changes in infrastructure or business context. This is the main document verified by external auditors during certification.