Statement of Applicability Template Excel
A statement of applicability template (excel) is the core document that shows an auditor which of the 93 ISO 27001:2022 Annex A controls apply to your business and why. This ready-to-use Excel template lists every control, organised by theme, with columns for applicability and justification, so you build your SoA quickly instead of starting from a blank workbook.
It is delivered by secure instant download for a one-time ZAR price - no subscription. You tailor the sheet to your scope and you are done.
What a statement of applicability template is
The Statement of Applicability (SoA) is the document required by ISO 27001 that records your selection of controls and the justification for including or excluding each one. It is the link between your risk assessment and the controls you implement.
This Excel template pre-lists all 93 Annex A controls from the 2022 revision, grouped into the four themes - Organisational, People, Physical, and Technological - so you work through a complete, standard-aligned list rather than trusting your memory to remember every control.
Who needs it
Anyone preparing for ISO 27001:2022 certification or being asked by a client for evidence of their control selection. The SoA is a mandatory part of the ISMS documentation set, so you cannot reach certification without one.
It also doubles as a practical accountability tool: once you record which controls apply and who owns them, you have a clear map of what the business has to implement and maintain.
What's included
The template includes all 93 Annex A controls, the four ISO 27001:2022 themes, applicability and justification columns, implementation status tracking, and fields for the control owner and evidence reference - mirroring the structure expected in the standard.
Because it is pre-listed as an Excel workbook, you can filter by theme, flag controls as applicable or not, and keep the whole register in one maintainable file.
Common mistakes people make without one
The most frequent mistake is marking every control as applicable. That inflates your scope, creates a huge implementation burden, and is a red flag to auditors. A proper SoA lets you justify exclusions for controls that genuinely do not apply to a small business.
Equally common is skipping the justification column altogether. The standard requires a reasoned basis for each inclusion and exclusion. Without it, the SoA is not auditable.
How it maps to ISO 27001:2022 Annex A
Annex A of ISO 27001:2022 defines the 93 controls across four themes. Clause 6.1.3 requires you to determine which controls are necessary to implement the risk treatment options you selected, and to prepare that as your Statement of Applicability.
This template is structured so each theme is a clear section of the workbook and each control carries the fields the standard expects, making the mapping between your risk treatment and your controls straightforward to follow.
Get the Statement of Applicability Template Excel
Ready-to-use, pre-structured with placeholder fields for your company details. Instant download after payment - one-time ZAR pricing, no subscription.
Related template
Complete your ISO 27001 documentation set with the ISO 27001 vendor assessment template. The two documents work together, so linking them up saves you time and makes your documentation more coherent.
Statement of Applicability Template Excel FAQ
Is this a statement of applicability template in excel?
Yes. It is an Excel (.xlsx) workbook with all 93 ISO 27001:2022 Annex A controls pre-listed, organised by theme, delivered by secure instant download after a one-time ZAR payment.
Do I need all 93 Annex A controls?
No. The Statement of Applicability lets you justify which controls apply to your ISMS scope. Many controls will not apply to a small business, and that is expected.
Are the controls already filled in?
All 93 controls are pre-listed with their theme. You fill in the applicability, justification, owner, and evidence columns based on your scope and risk assessment.
What else do I need alongside the SoA?
A risk assessment register (clauses 6.1 and 6.2) works hand-in-hand with the SoA, since your risk treatment drives which controls you select and justify. See our ISO 27001 risk assessment template and vendor assessment template for the complementary documents.
Questions?
If you have questions about which kit is right for your business, or need a custom document set for a specific framework or industry, contact us at [email protected].