
ISO 27001 Statement of Applicability Template

Fully written, pre filled, ready to go ISO 27001:2022 Statement of Applicability Template to fast track your implementation.

Save valuable time and ensure compliance by leveraging this essential SOA.

Crafted by Stuart Barker, the ISO 27001 Ninja and 30+ year practitioner.

Original price was: $ 129.97.Current price is: $ 69.97.


This Template is included in:

The Ultimate ISO 27001 Toolkit

Do It Yourself ISO 27001

ISO 27001 Toolkit Business Edition


The ISO 27001 Statement of Applicability document is a fundamental part of your ISO 27001 implementation and certification. It is a list of the controls that you are required to implement and is a statement of if and why particular required controls apply to you.

The ISO 27001:2022 update introduced many new controls.

It is an ISO 27001 Mandatory document and required for ISO 27001 Certification.

The ISO 27001 Statement of Applicability Template:

This is the definitive Statement of Applicability ISO 27001 template xls.

ISO 27001 Statement of Applicability

The ISO 27001 statement of applicability is the list of information security controls that your business has implemented. It includes a list of the controls that you have considered but have deem not applicable. It is a fundamental document of ISO 27001 certification and of the information security management system.

The ISO 27001 Statement of Applicability Template is an Excel spreadsheet that has been created to fully meet the requirements of ISO 27001 for your ISO 27001 certification. Fully populated and ready to go it is designed to save you time and fast track your implementation.

You need the ISO 27001 Statement of Applicability as part of your ISO 27001 certification as it is a mandatory document. It may also be requested by your clients and your customers. Without the ISO 27001 Statement of Applicability you will not be able to evidence the controls that you have implemented and you will not certify to ISO 27001

The purpose of the ISO 27001 Statement of Applicability Template is to clearly communicate what information security controls you have implemented to employees, clients, auditors and interested parties. It is fully populated to fast track your implementation.


Who should use the Statement of Applicability Template?

Anyone that wants to save time and money and have a pre populated ISO 27001 Statement of Applicability that fully meets the requirements of the ISO 27001 standard, contains all the updated and required controls, and is ready to go. The benefits of using the ISO 27001 Statement of Applicability Template are:

Save time: the template is already fully populated with all the up to date, required controls and ready to go
Meet the requirements of the standard: the template is mapped directly to the requirements of the ISO 27001:2022 standard
Save money: you will not have to pay consultants to research and write the SOA for you

What format is the Statement of Applicability Template in?

The ISO 27001 Statement of Applicability Template is in Microsoft Excel format.

What version of the ISO 27001 standard does the ISO 27001 Statement of Applicability Template support?

The Statement of Applicability fully supports ISO/IEC 27001:2022 and ISO/IEC 27001:2013.

How complete is the ISO 27001 Statement of Applicability Template?

It is 100% complete. It just requires a fast rebrand, checking and some minor additions that are clearly sign posted and marked

Where can I get a free example ISO 27001 Statement of Applicability Template PDF?

You can download the ISO 27001 Statement of Applicability Template PDF

How long will it take me to implement the Statement of Applicability Template?

We estimate that on average about 15 minutes.

What is the cost of the ISO 27001 Statement of Applicability Template?

The cost of the ISO 27001 Statement of Applicability Template is £49.97. The price can vary depending on currency exchange rates and the running of promotions and offers.

What does the ISO 27001 Statement of Applicability Template cover?

The ISO 27001 Statement of Applicability Template covers:
– The complete list of ISO 27001:2022 Annex A Controls
– Justification for inclusion
– Justification for inclusion
– Applicability
– Review Date

Where can I learn more about the ISO 27001 Statement of Applicability?

The ISO 27001 Statement of Applicability: The Ultimate Guide is the complete guide to the ISO 27001 Statement Of Applicability and includes everything you need to know.

How quickly will I get the Statement of Applicability Template? What is the turnaround?

You get the Statement of Applicability immediately on successful payment.

What support do you offer?

We offer a free 30 minutes, 1 to 1 consultation as well as a free weekly ISO 27001 Q and A call and the unique ability to purchase consulting by the hour.

Will the Template work in America / Australia / Europe / UK …. other?

Yes. The ISO 27001 Statement of Applicability Template supports the International Standard for Information Security. It is being used successfully right now across the globe.

Why are there 2 versions of the ISO 27001 Statement of Applicability?

The ISO 27001 statement of applicability is the list of information security controls contained within ISO 27002. ISO 27002 is an annex to ISO 27001 and a requirement of ISO 27001. That list of controls changed in 2022. Certification bodies should be checked before going for certification to agree which version of the controls you will be assessed against. You have both versions in the template to cover both scenarios and to allow for future planning.

Will I need to hire consultants to use the ISO 27001 Statement of Applicability Template?

No. The ISO 27001 Statement of Applicability Template is designed to be easy to implement and easy to configure. It comes with an easy to follow step by step guide.

You are provided with a free hour of training if you need it.

Is the ISO 27001 Statement of Applicability Template the only ISO 27001 template I need?

It depends what you are trying to achieve. We have made it available as a single document as some people just require the SOA but for ISO 27001 certification you will require the complete Information Security Management System (ISMS) and the Ultimate ISO 27001 Toolkit.

What is the best ISO 27001 Statement of Applicability Template?

The best ISO 27001 Statement of Applicability Template will depend on your needs and requirements but we would recommend the High Table ISO 27001 Statement of Applicability Template. Review the templates for what they offer, view the samples and choose based on your need and budget.

I built this ISO 27001 Statement of Applicability Template so people could save time copying out all the ISO 27001 controls and clauses and then putting in the required columns and formatting. It is a lot of cut and pasting to do from scratch. And when the 2022 update changed everything I updated it so people had the latest clauses and controls without having to work out what changed.

I include it as part of the Ultimate ISO 27001 Toolkit but people asked me for it as a standalone tool.

The Ultimate ISO 27001 Statement of Applicability (SOA) Template

  • Fully ISO 27001:2022 Compliant
  • Prewritten and Ready to Go
  • Complete list of ISO 27001:2022 Annex A Controls
  • All new ISO 27001:2022 Annex A Controls
  • Fast to implement
  • Simple to configure
  • Step-by-step guide and video walkthrough
  • Format: Microsoft Excel XLS

To see what you are getting take a look at the Example ISO 27001 Statement of Applicability Template PDF


  1. Stuart Barker

    I was sceptical about downloading templates but am glad I did. This was recommended to me by a fellow security manager and allowed me to start to plan our certification. ISM | SaaS Platform

  2. Stuart Barker

    My company is considering ISO 27001 certification and I need to know what controls we would need to implement. This is a very practical straight forward template and well worth the money. Information Security Manager | Software Development Company

Add a review

Your email address will not be published. Required fields are marked *