Free Website Tool

ISO 27001 Statement of Applicability Builder

Build and review a clear Statement of Applicability across all 93 Annex A controls. Record each decision, its justification, implementation status and evidence.

Tool summary

Framework
Annex A · 93 controls
Purpose
Statement of Applicability
Privacy
Browser only
Persistence
Local autosave

Related records

Statement of Applicability

Explains which controls are applicable, why, and their implementation position.

Risk Register

Records identified risks and their assessment.

Risk Treatment Plan

Records actions selected to address risks.

Local working document

Build a practical SoA

Choose a control, record the applicability decision and justification, then add implementation status and evidence.

Your SoA is stored in this browser and is not uploaded to AuditPrepared.

Ready to save locally

SoA summary

Controls
93
Reviewed
0
Applicable
0
Implemented
0
Needs attention
0

Annex A controls

Showing 93 controls

ControlTitleApplicabilityImplementationReview

Quality review

Useful checks

Concise prompts for incomplete decisions; not a compliance score.

    Practical guidance

    Build an SoA that supports real decisions

    A Statement of Applicability records which information-security controls are necessary, why they are included or excluded, and their implementation position. It connects risk treatment to the controls your organization operates.

    What should an SoA contain?

    A useful minimum is the control identifier and title, applicability decision, justification, implementation status and evidence reference. Optional ownership and notes can support maintenance without turning the record into a full GRC workflow.

    What makes a good justification?

    Use specific organizational context. Explain the risk, obligation, service, technology or scope decision behind inclusion or exclusion. Avoid generic wording such as “required by ISO”.

    How an auditor may review it

    1. Confirm all 93 controls were considered.
    2. Review applicability decisions and sample justifications.
    3. Compare implementation status with current evidence.
    4. Trace relevant controls to risk treatment and operational practice.