The Statement of Applicability (SoA) is often described as the heartbeat of your Information Security Management System (ISMS). While the risk assessment identifies the ‚why‘, the SoA defines the ‚what‘ and the ‚how‘. It is the single most important document during your certification audit and the definitive roadmap for your internal security operations.
At Instant 27001, we believe compliance shouldn’t be a manual burden. We help you move from static, error-prone spreadsheets to a dynamic, automated SoA that evolves with your business.
A common misconception is that the SoA is merely a checkbox for the auditor. In reality, a well-crafted SoA acts as a strategic filter for your organisation:
If you are pursuing ISO 27001 certification, the SoA isn’t optional. It’s the core requirement. But its utility extends far beyond the compliance department:
In the 2022 update, ISO 27001 underwent a massive architectural shift. The standard moved away from the fragmented 14-domain structure of the past, consolidating 114 controls down to 93 modern security measures. These controls are now organized into four logical themes. This restructuring isn’t just about brevity; it’s about aligning information security with the way modern, cloud-first businesses actually operate.
The definition
Organizational controls serve as the „Operating System“ of your ISMS. They define the high-level logic, governance frameworks, and operational protocols that dictate how your entire company approaches security.
The shift
ISO moved away from scattered compliance requirements to a unified governance model. By merging previously separate domains like „Supplier Security“ and „Security Organization,“ the standard now aligns directly with global risk management methodologies like ISO 31000.
The business advantage
This pillar eliminates „policy overlap,“ reducing administrative bloat. For leadership, it provides a single, coherent framework for decision-making, ensuring that security is a boardroom priority rather than an IT-only concern.
Critical controls to watch:
The definition
Organizational controls serve as the „Operating System“ of your ISMS. They define the high-level logic, governance frameworks, and operational protocols that dictate how your entire company approaches security.
The shift
ISO moved away from scattered compliance requirements to a unified governance model. By merging previously separate domains like „Supplier Security“ and „Security Organization,“ the standard now aligns directly with global risk management methodologies like ISO 31000.
The business advantage
This pillar eliminates „policy overlap,“ reducing administrative bloat. For leadership, it provides a single, coherent framework for decision-making, ensuring that security is a boardroom priority rather than an IT-only concern.
Critical controls to watch:
The definition
Physical controls protect the tangible assets like, facilities, hardware, and infrastructure, that house your digital data. This includes everything from office entry points to the security of home-office workstations.
The shift
This pillar has been modernized for the Hybrid Work Era. It acknowledges that the „office“ is no longer a single building, but a distributed network of home offices, coworking spaces, and data centers.
The business advantage
By securing the „Physical-Digital“ intersection, you ensure that high-value intellectual property is protected regardless of where your team is working. It provides a standardized framework for managing the risks of a borderless workforce.
Critical controls to watch:
The definition
Technological controls are the digital „locks and keys“ of your infrastructure. This pillar focuses on technical implementations like encryption, network security, and secure software development.
The shift
The 2022 update introduces „Privacy by Design.“ It adds technical mandates for data masking and leakage prevention that didn’t exist in the 2013 version, aligning the standard with modern cyber threats like ransomware and SaaS exploits.
The business advantage
For tech companies, this pillar is the ultimate „Trust Builder.“ It proves to your clients that your software is built securely (Secure Coding) and that their sensitive data is technically shielded from unauthorized access or accidental transfer.
Critical controls to watch:
Manually mapping these 93 controls to your specific risks is a recipe for error. Instant 27001 automates this mapping, providing you with a pre-configured framework where these controls are already translated into actionable tasks.
Ready to see the 93 controls in action?
One of the most frequent points of confusion in ISO 27001 is the difference between these two documents. While they are inextricably linked, they serve fundamentally different purposes.
| Feature | Risk Assessment Report (RAR) | Risk Assessment Report (RAR) |
|---|---|---|
| Primary goal | To identify vulnerabilities and threats to your information assets. | To declare which security controls are in place to mitigate those risks. |
| Focus | „The problem“: what could go wrong? | „The solution“: what are we doing about it? |
| Content | A list of assets, threats, vulnerabilities, and their impact/likelihood levels. | A definitive list of the 93 Annex A controls with justifications for each. |
| Audience | Primarily internal (risk owners and management). | Both internal and external (auditors, partners, and clients). |
| The relationship | The RAR provides the input for the SoA. | The SoA provides the output of your security decisions. |
Important note: you cannot have a compliant SoA without a thorough Risk Assessment, and you haven’t „treated“ your risks until they are mapped in the SoA.
A „Solid SoA“ is not a static document; it is the result of a rigorous, repeatable process.
You don’t select controls because they sound good; you select them because they solve a problem. Every „Applicable“ control in your SoA should have a direct lineage back to a risk identified in your assessment.
ISO 27001 doesn’t require you to be perfect from day one, but it does require honesty. We categorise controls as:
Before finalising, you must cross-reference your selection against the full Annex A list. This „sanity check“ ensures that in your focus on specific risks, you haven’t missed a foundational security requirement.
The manual era of ISO 27001 is over. Instant 27001 provides a high-velocity environment to manage your SoA:
While you can share a template, each legal entity or specific scope usually needs its own SoA to reflect its unique risk environment and local regulations.
During an audit, this is usually classified as a major non-conformity. The SoA defines the scope of the certificate; missing a control means the ISMS certificate is fundamentally flawed.
Instant 27001 provides specific guidance for the 11 new controls (like data leakage prevention and monitoring activities), helping you determine if they apply to your current stack.