The Statement of Applicability (SoA) is often described as the heartbeat of your Information Security Management System (ISMS). While the risk assessment identifies the ‘why’, the SoA defines the ‘what’ and the ‘how’. It is the single most important document during your certification audit and the definitive roadmap for your internal security operations.

At Instant 27001, we believe compliance shouldn’t be a manual burden. We help you move from static, error-prone spreadsheets to a dynamic, automated SoA that evolves with your business.


Why the SoA is non-negotiable

A common misconception is that the SoA is merely a checkbox for the auditor. In reality, a well-crafted SoA acts as a strategic filter for your organisation:

  • Risk mitigation mastery: it ensures that every significant risk identified in your assessment has a corresponding defensive measure.
  • Resource optimisation: by justifying exclusions, you prevent “security bloat”: the practice of implementing costly controls that provide no actual value to your specific business model.
  • Stakeholder transparency: in an era of supply-chain attacks, your SoA is your “Security Passport”. It provides a granular level of detail that a simple certificate cannot, proving to high-value clients exactly how you protect their intellectual property.

Who is the SoA for? (And who demands it?)

If you are pursuing ISO 27001 certification, the SoA isn’t optional. It’s the core requirement. But its utility extends far beyond the compliance department:

  • Fast-growth SaaS & tech teams: to prove to enterprise clients that your “secure-by-design” claims are backed by specific, documented Annex A controls.
  • Compliance & security officers: to create a central “Source of Truth” that prevents internal confusion and ensures every department knows its security obligations.
  • External auditors: this is the first document they touch. A precise SoA sets the tone for a smooth, successful audit.
  • Stakeholders & board members: to provide a high-level yet verifiable overview of the company’s risk posture and investment in security infrastructure.

Deep dive into the ISO 27001:2022 structure

In the 2022 update, ISO 27001 underwent a massive architectural shift. The standard moved away from the fragmented 14-domain structure of the past, consolidating 114 controls down to 93 modern security measures. These controls are now organized into four logical themes. This restructuring isn’t just about brevity; it’s about aligning information security with the way modern, cloud-first businesses actually operate.

1. Organizational controls (37 controls)

The definition
Organizational controls serve as the “Operating System” of your ISMS. They define the high-level logic, governance frameworks, and operational protocols that dictate how your entire company approaches security.

The shift
ISO moved away from scattered compliance requirements to a unified governance model. By merging previously separate domains like “Supplier Security” and “Security Organization,” the standard now aligns directly with global risk management methodologies like ISO 31000.

The business advantage
This pillar eliminates “policy overlap,” reducing administrative bloat. For leadership, it provides a single, coherent framework for decision-making, ensuring that security is a boardroom priority rather than an IT-only concern.

Critical controls to watch:

  • A.5.7 – Threat Intelligence (New): Moves you from reactive defense to proactive hunting by analyzing external threat data.
  • A.5.23 – Cloud Services Security: Specifically addresses the “Shared Responsibility Model” for SaaS and cloud-native environments.
  • A.5.31 – Legal & Regulatory Compliance: A consolidated “master control” for managing GDPR, CCPA, and contractual obligations.

 2. People controls (8 controls)

The definition
Organizational controls serve as the “Operating System” of your ISMS. They define the high-level logic, governance frameworks, and operational protocols that dictate how your entire company approaches security.

The shift
ISO moved away from scattered compliance requirements to a unified governance model. By merging previously separate domains like “Supplier Security” and “Security Organization,” the standard now aligns directly with global risk management methodologies like ISO 31000.

The business advantage
This pillar eliminates “policy overlap,” reducing administrative bloat. For leadership, it provides a single, coherent framework for decision-making, ensuring that security is a boardroom priority rather than an IT-only concern.

Critical controls to watch:

  • A.5.7 – Threat Intelligence (New): Moves you from reactive defense to proactive hunting by analyzing external threat data.
  • A.5.23 – Cloud Services Security: Specifically addresses the “Shared Responsibility Model” for SaaS and cloud-native environments.
  • A.5.31 – Legal & Regulatory Compliance: A consolidated “master control” for managing GDPR, CCPA, and contractual obligations.

3. Physical controls (14 controls)

The definition
Physical controls protect the tangible assets like, facilities, hardware, and infrastructure, that house your digital data. This includes everything from office entry points to the security of home-office workstations.

The shift
This pillar has been modernized for the Hybrid Work Era. It acknowledges that the “office” is no longer a single building, but a distributed network of home offices, coworking spaces, and data centers.

The business advantage
By securing the “Physical-Digital” intersection, you ensure that high-value intellectual property is protected regardless of where your team is working. It provides a standardized framework for managing the risks of a borderless workforce.

Critical controls to watch:

  • A.7.5 – Secure Remote Working: The definitive standard for securing a hybrid workforce and preventing data leaks from home offices.
  • A.7.4 – Physical Security Monitoring: Moves beyond passive locks to active, real-time intrusion detection and surveillance.

4. Technological controls (34 controls)

The definition
Technological controls are the digital “locks and keys” of your infrastructure. This pillar focuses on technical implementations like encryption, network security, and secure software development.

The shift
The 2022 update introduces “Privacy by Design.” It adds technical mandates for data masking and leakage prevention that didn’t exist in the 2013 version, aligning the standard with modern cyber threats like ransomware and SaaS exploits.

The business advantage
For tech companies, this pillar is the ultimate “Trust Builder.” It proves to your clients that your software is built securely (Secure Coding) and that their sensitive data is technically shielded from unauthorized access or accidental transfer.

Critical controls to watch:

  • A.8.9 – Configuration Management: directly addresses the leading cause of cloud breaches: human misconfiguration.
  • A.8.12 – Data Leakage Prevention (DLP): technical safeguards to ensure sensitive data never leaves your controlled environment.
  • A.8.28 – Secure Coding: essential for software companies to ensure security is baked into the development lifecycle from day one.

Why managing controls with Instant 27001 matters 

Manually mapping these 93 controls to your specific risks is a recipe for error. Instant 27001 automates this mapping, providing you with a pre-configured framework where these controls are already translated into actionable tasks.

Ready to see the 93 controls in action?


The strategic divide: SoA vs. Risk Assessment report

One of the most frequent points of confusion in ISO 27001 is the difference between these two documents. While they are inextricably linked, they serve fundamentally different purposes.

FeatureRisk Assessment Report (RAR)Risk Assessment Report (RAR)
Primary goalTo identify vulnerabilities and threats to your information assets.To declare which security controls are in place to mitigate those risks.
Focus“The problem”: what could go wrong?“The solution”: what are we doing about it?
ContentA list of assets, threats, vulnerabilities, and their impact/likelihood levels.A definitive list of the 93 Annex A controls with justifications for each.
AudiencePrimarily internal (risk owners and management).Both internal and external (auditors, partners, and clients).
The relationshipThe RAR provides the input for the SoA.The SoA provides the output of your security decisions.

Important note: you cannot have a compliant SoA without a thorough Risk Assessment, and you haven’t “treated” your risks until they are mapped in the SoA.


The SoA cycle: 4 steps to audit success asked questions

A “Solid SoA” is not a static document; it is the result of a rigorous, repeatable process.

Step 1: the risk-control calibration

You don’t select controls because they sound good; you select them because they solve a problem. Every “Applicable” control in your SoA should have a direct lineage back to a risk identified in your assessment.

Step 2: the strictness of justification

  • Inclusion: you must state why a control is selected (e.g., “Required to mitigate the risk of unauthorised data access” or “Contractual requirement for Client X”).
  • Exclusion: this is where auditors focus. A vague “Not applicable” will trigger a non-conformity. A strong justification explains why the risk doesn’t exist (e.g., “No physical office; all operations are 100% remote/cloud-based”).

Step 3: the reality check (implementation status)

ISO 27001 doesn’t require you to be perfect from day one, but it does require honesty. We categorise controls as:

  • Implemented: evidence is ready for inspection.
  • Planned: a timeline and owner are assigned.
  • Partially implemented: progress is documented.

Step 4: the cross-reference check

Before finalising, you must cross-reference your selection against the full Annex A list. This “sanity check” ensures that in your focus on specific risks, you haven’t missed a foundational security requirement.


How Instant 27001 reduces the complexity

The manual era of ISO 27001 is over. Instant 27001 provides a high-velocity environment to manage your SoA:

  • Dynamic mapping: our engine links risks to controls automatically. When your risk landscape shifts, the platform prompts you to update your SoA, ensuring you never fall out of compliance.
  • Justification library: stop staring at a blank screen. Access hundreds of expert-written justifications that have already passed dozens of audits in various sectors (SaaS, FinTech, Healthcare).
  • Version control & audit history: every change is logged. When an auditor asks for the history of your SoA, you can provide a complete, timestamped report with one click.
  • ISO 27001:2022 native: built from the ground up for the latest standard. We handle the “mapping headache” so you can focus on actual security.

Frequently asked questions

Can we have a “generic” SoA for the whole group?

While you can share a template, each legal entity or specific scope usually needs its own SoA to reflect its unique risk environment and local regulations.

What happens if we miss a control in the SoA?

During an audit, this is usually classified as a major non-conformity. The SoA defines the scope of the certificate; missing a control means the ISMS certificate is fundamentally flawed.

How do we handle “new” controls in the 2022 update?

Instant 27001 provides specific guidance for the 11 new controls (like data leakage prevention and monitoring activities), helping you determine if they apply to your current stack.


  • 15 mei 2026
  • News

100% first time success! Start with confidence.

Order now   Book a demo

Ontdek meer van Instant 27001

Abonneer je nu om meer te lezen en toegang te krijgen tot het volledige archief.

Lees verder