What is the Statement of Applicability?
The Statement of Applicability (SoA) is a fundamental component of an organization’s Information Security Management System (ISMS) and a critical document in achieving ISO 27001 certification.
An organization’s Statement of Applicability benchmarks against ISO 27001’s full Annex A control set and includes justification for inclusion or exclusion of each control as part of the organization’s ISMS implementation. In addition, the SoA links an organization’s risk assessment with its risk treatment plan.
The Statement of Applicability is one of the first documents an auditor will review as part of the ISO 27001 audit process. The SoA helps the auditor understand the organization and what controls have been implemented and assessed as part of that organization’s audit.
{{cta_withimage2="/cta-modules"}}
Join our upcoming webinar, where leading cybersecurity experts Ciaran Martin and Victoria Baines will discuss findings from Vanta’s second annual State of Trust Report. Understand the risks facing UK organisations, why good security means good business and how to minimise manual security work through AI and automation.
Join Danny Sheridan, Co-founder and CEO at Fern (YC W23), and Brian Kuan, Product Marketing Manager at Vanta (YC W18), for a deep dive into why startups should prioritize compliance early in their journey, and how Vanta can help you become SOC 2-ready in as little as four weeks—giving time back for you to focus on building a company.