Statement of Applicability
Explains which controls are applicable, why, and their implementation position.
Free Website Tool
Build and review a clear Statement of Applicability across all 93 Annex A controls. Record each decision, its justification, implementation status and evidence.
Explains which controls are applicable, why, and their implementation position.
Records identified risks and their assessment.
Records actions selected to address risks.
Local working document
Choose a control, record the applicability decision and justification, then add implementation status and evidence.
Your SoA is stored in this browser and is not uploaded to AuditPrepared.
Showing 93 controls
| Control | Title | Applicability | Implementation | Review |
|---|
Quality review
Concise prompts for incomplete decisions; not a compliance score.
Practical guidance
A Statement of Applicability records which information-security controls are necessary, why they are included or excluded, and their implementation position. It connects risk treatment to the controls your organization operates.
A useful minimum is the control identifier and title, applicability decision, justification, implementation status and evidence reference. Optional ownership and notes can support maintenance without turning the record into a full GRC workflow.
Use specific organizational context. Explain the risk, obligation, service, technology or scope decision behind inclusion or exclusion. Avoid generic wording such as “required by ISO”.