Skip to main content

ISO 27001 CLAUSE 6.1.3 D

The Statement of Applicability

Clause 6.1.3 d) of ISO 27001:2022 requires a Statement of Applicability. It is the document an auditor opens first, and it is the one artefact a compliance platform cannot generate for you, because it records decisions only your organisation can take.

Book the Free DiagnosticSame-week availability

Loading the calendar

Open the booking page

Calendar not loading? Open Calendly directly

What it has to contain

PHASE 01

The necessary controls

Which controls you have determined are necessary, drawn from your risk treatment and not only from Annex A.

PHASE 02

Justification for inclusion

Why each necessary control is necessary, traceable back to a risk, a legal requirement or a contractual obligation.

PHASE 03

Implementation status

Whether each necessary control is implemented, stated honestly. A control that is planned is recorded as planned.

PHASE 04

Justification for exclusion

Why each Annex A control you have not applied is not applicable. Silence is not an exclusion and an auditor will treat it as an omission.

What auditors raise most often

  • Annex A treated as a checklist, with controls marked applicable because they are in the standard rather than because a risk requires them.

  • Exclusions with no justification, or a justification that restates the exclusion.

  • An implementation status that does not match what the evidence shows.

  • A Statement of Applicability that has not been reviewed since the risk assessment changed.

The Statement of Applicability is sampled again during the ISO 27001 clause 9.2 internal audit, where every control marked implemented has to be supported by evidence.

Why the platform cannot write it

Vanta, Drata, Sprinto and Thoropass collect evidence and monitor controls continuously, and they do that well. The Statement of Applicability is not an evidence problem. It records which controls your organisation decided were necessary and why, which is a judgement about your risk, your obligations and your scope. A platform can tell you a control is passing. It cannot tell an auditor why you decided that control was necessary in the first place.

If you already own a platform and the audit is not getting closer, the platform rescue review of scope, configuration and evidence gaps covers the same ground.

Annex A in ISO 27001:2022

The 2022 edition reorganised Annex A into 93 controls across four themes: organisational, people, physical and technological. The 2013 edition had 114 controls across 14 clauses. A Statement of Applicability written against the 2013 structure is a finding in itself.

Get the Statement of Applicability reviewed

A free 45 minute diagnostic with the practitioner who would do the work. Bring your current SoA, or the risk assessment it should be built from.

45 minutes, video, with the practitioner who would do the work. No sales pitch.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.