NEWVenvera speaks your language: the full platform, in English, German, Spanish and Bulgarian.See what’s new →
ISO 27001 Statement of Applicability Template (Excel, 2022)
Resources

ISO 27001 Statement of Applicability Template (Excel, 2022)

·Alexander Sverdlov

The Statement of Applicability (SoA) is the one document your ISO 27001 auditor opens first. It lists every Annex A control, says whether it applies to you, and justifies each decision. It is mandatory under clause 6.1.3 d of the standard, and building it from a blank page is slow and error prone. This free template gives you all 93 Annex A controls from ISO/IEC 27001:2022, already laid out with the columns an auditor expects, so you fill in your decisions rather than rebuild the control list. Download it below, then read on for how to complete it.

Free download

Get the ISO 27001 Statement of Applicability template

All 93 Annex A controls from ISO/IEC 27001:2022, laid out with applicability, justification, status, evidence and owner columns. Editable Excel, ready to fill in.

By downloading, you agree to receive occasional relevant emails from Venvera. Unsubscribe anytime. See our Privacy Policy. This template is a starting point, not legal advice.

What an ISO 27001 Statement of Applicability template gives you

A good SoA template does two things: it saves you from transcribing 93 controls by hand, and it structures the exact evidence trail an auditor will ask for. This one is a single Excel workbook. Each row is one Annex A control, pre-filled with its reference, theme, title and the official control objective, followed by empty columns for your decisions.

ISO 27001 gap assessment scoring the Annex A controls
A gap assessment scores each Annex A control against your current state - the input to your SoA decisions.

What is inside the template

The workbook has one sheet for the Statement of Applicability and one for how to use it. For every control you record:

  • Applicable? (Yes / No) - whether the control is in scope for your organisation.
  • Justification for inclusion or exclusion - the reason. Every inclusion ties to a risk you are treating; every exclusion needs a defensible reason.
  • Implementation status - Implemented, Partially implemented, Planned, or Not applicable.
  • Evidence or reference - the policy, configuration, ticket or screenshot that proves it.
  • Owner - who is accountable for the control.
One evidence library mapped across ISO 27001 and other frameworks
Each control links to evidence - the reference column of your SoA in practice.

ISO 27001:2022 has 93 Annex A controls in four themes

Make sure you are working against the current version. ISO/IEC 27001:2022 restructured Annex A into 93 controls across four themes: 37 Organizational, 8 People, 14 Physical and 34 Technological. The retired 2013 edition had 114 controls in 14 domains. If a template still shows 114 controls in 14 domains, it is out of date, and certifying against the wrong control set is exactly the kind of error an auditor catches immediately. This template is built to the 2022 Annex A.

Mapping one ISO 27001 control across other frameworks
The 2022 Annex A controls, and how each maps across the frameworks it also satisfies.

How to fill in your Statement of Applicability

  1. Run a risk assessment first. Your SoA decisions should follow from the risks you identified, not the other way around.
  2. Go control by control. For each of the 93, mark it applicable or not, and write the justification.
  3. Set the implementation status honestly. Partially implemented is fine mid-project; a fabricated Implemented is not.
  4. Link the evidence. This is what turns a claim into something an auditor can verify.
  5. Review it at least annually and whenever your risk assessment changes.

Keep the Statement of Applicability current automatically

A spreadsheet SoA is correct the day you finish it and drifts from then on. In Venvera the Statement of Applicability is generated from live control data, so it reflects your actual implementation status and evidence rather than a snapshot, and the same evidence reuses across SOC 2, GDPR and NIS2 through a crosswalk. Plans start from EUR 399 per month. If you want to understand the controls first, our guide to the ISO 27001 Annex A controls walks through all four themes.

A live ISO 27001 posture that keeps the Statement of Applicability current
A live posture keeps your SoA current instead of freezing it in a spreadsheet.

Frequently Asked Questions

Is the Statement of Applicability mandatory for ISO 27001?

Yes. Clause 6.1.3 d of ISO/IEC 27001 requires a Statement of Applicability that lists the necessary controls, justifies their inclusion, states whether they are implemented, and justifies the exclusion of any Annex A controls. It is one of the mandatory documents for certification.

How many controls are in the 2022 Statement of Applicability?

ISO/IEC 27001:2022 Annex A has 93 controls across four themes: 37 Organizational, 8 People, 14 Physical and 34 Technological. The template includes all 93.

What is the difference between the SoA and a risk treatment plan?

The risk treatment plan says how you will treat each identified risk; the Statement of Applicability records which Annex A controls you apply as a result, with justification and status. They are related but separate mandatory outputs.

Can I exclude Annex A controls?

Yes, but every exclusion needs a documented justification in the SoA. Excluding a control because it genuinely does not apply to your context is expected; excluding one to avoid work is what auditors look for.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

RELATED POSTS