Information Security

Statement of Applicability Template

A statement of applicability template defining the ISO 27001 Statement of Applicability recording every Annex A control, its applicability, justification and implementation status, aligned to ISO 27001, SOC 2.

14-20 pages|Updated 2026-09-12|2 frameworks
Aligned to:
ISO 27001
SOC 2

What's Included

1. Purpose & Scope

What the Statement of Applicability is for.

PurposeScope ReferenceVersion and Approval

2. Control Register

Every Annex A control listed.

Control ReferenceControl TitleApplicable Yes or No

3. Justification

Why each control is included or excluded.

Inclusion JustificationExclusion JustificationRisk Assessment LinkageLegal or Contractual Driver

4. Implementation Status

Where each control actually stands.

ImplementedPartially ImplementedPlanned with DateEvidence Reference

5. Linkage

Connects the SoA to the rest of the system.

Risk Treatment Plan ReferencePolicy ReferenceOwner

6. Maintenance

Keeping it current.

Change TriggersReview CadenceApproval of Changes

Frequently Asked Questions

What should a statement of applicability template include?

A comprehensive statement of applicability template should include purpose & scope, control register, justification, implementation status, and more. This template covers 6 key sections aligned to ISO 27001, SOC 2 requirements.

Which frameworks require a information security policy?

Major frameworks requiring information security policies include ISO 27001, SOC 2. This template maps directly to their control requirements, making it easier to demonstrate compliance across multiple standards.

How often should a statement of applicability template be reviewed?

Best practice is to review your statement of applicability template at least annually, or whenever significant changes occur in your organisation, technology environment, or regulatory landscape. Most frameworks including ISO 27001 and NIST CSF require documented policy review cycles.

Build Your Compliance Programme

Pair this policy template with our compliance platform to map controls across 686+ frameworks, run self-assessments, and get AI-powered compliance advisory.

Get Started Free →

Free forever — no credit card required