Back to glossary

Statement of Applicability

1 min read

The Statement of Applicability is the document, required by ISO/IEC 27001, that lists the Annex A controls, states whether each is applicable, justifies every inclusion and every exclusion, and records its implementation status. It is the first artefact an auditor asks for and the one that most often fails to survive scrutiny.

July 29, 2026
Compartir:

Its function is to connect the risk assessment to the controls. Each decision is supposed to be traceable: this risk was identified, this control treats it, therefore it is applicable and here is its status. Exclusions carry the same burden in reverse, and a justification that amounts to a statement that the control is not relevant is the single most common audit finding against the document.

Two things to get right on the current edition. The 2022 revision restructured Annex A into 93 controls grouped in four themes, so a statement built from the earlier structure is immediately identifiable as stale, and an organisation transitioning has to be able to show the mapping. And the scope boundary has to be real: an ISMS scoped to exclude the systems where the interesting data actually lives produces a certificate that says less than the client believes it says, which is worth knowing when a certificate is offered as supplier assurance.

Where this meets technical work is evidence. Marking a control as implemented is a claim, and the auditor will ask what demonstrates it. That is where a test report, a configuration baseline or an asset inventory becomes the supporting artefact, and where a control marked implemented with nothing behind it becomes a nonconformity. Producing that evidence is part of the certification support where the applicability statement is built from the risk assessment.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.