ALVOR
Platform
Advisory
PricingBlog
Get Demo
ALVOR
Platform
Advisory
PricingBlog
Get Demo

Free resource

Statement of Applicability builder

A Statement of Applicability is the document ISO 27001 requires you to maintain listing every Annex A control, whether it applies to you, and why. This builder gives you all 93 controls from the 2022 revision, somewhere to record the decision and the justification for each, and a CSV you can hand to an auditor.

It runs entirely in your browser. Nothing you type is sent anywhere, and your draft is saved locally so you can close the tab and come back to it.

Clause

6.1.3 d)

Controls

93

Themes

Four

Revision

ISO/IEC 27001:2022

What ISO 27001 asks the document to contain

  • Every Annex A control, listed, so the reader can see nothing was quietly skipped.
  • Whether each control is applicable to your ISMS.
  • The justification for including it, or for leaving it out.
  • Whether it is currently implemented.

The justifications have to be yours. An auditor is reading them to understand your reasoning about your scope, and generic wording is the fastest way to earn follow-up questions.

Statement of Applicability

ISO/IEC 27001:2022 Annex A · 93 controls

Prepared 0 of 93 controls decided

Organisation and ISMS scope: ________________________________________

Progress

0 of 93 controls decided

A.5Organizational controls

0/37

A.5.1

Policies for information security

Not decided

A.5.2

Information security roles and responsibilities

Not decided

A.5.3

Segregation of duties

Not decided

A.5.4

Management responsibilities

Not decided

A.5.5

Contact with authorities

Not decided

A.5.6

Contact with special interest groups

Not decided

A.5.7

Threat intelligence

Not decided

A.5.8

Information security in project management

Not decided

A.5.9

Inventory of information and other associated assets

Not decided

A.5.10

Acceptable use of information and other associated assets

Not decided

A.5.11

Return of assets

Not decided

A.5.12

Classification of information

Not decided

A.5.13

Labelling of information

Not decided

A.5.14

Information transfer

Not decided

A.5.15

Access control

Not decided

A.5.16

Identity management

Not decided

A.5.17

Authentication information

Not decided

A.5.18

Access rights

Not decided

A.5.19

Information security in supplier relationships

Not decided

A.5.20

Addressing information security within supplier agreements

Not decided

A.5.21

Managing information security in the ICT supply chain

Not decided

A.5.22

Monitoring, review and change management of supplier services

Not decided

A.5.23

Information security for use of cloud services

Not decided

A.5.24

Information security incident management planning and preparation

Not decided

A.5.25

Assessment and decision on information security events

Not decided

A.5.26

Response to information security incidents

Not decided

A.5.27

Learning from information security incidents

Not decided

A.5.28

Collection of evidence

Not decided

A.5.29

Information security during disruption

Not decided

A.5.30

ICT readiness for business continuity

Not decided

A.5.31

Legal, statutory, regulatory and contractual requirements

Not decided

A.5.32

Intellectual property rights

Not decided

A.5.33

Protection of records

Not decided

A.5.34

Privacy and protection of PII

Not decided

A.5.35

Independent review of information security

Not decided

A.5.36

Compliance with policies, rules and standards for information security

Not decided

A.5.37

Documented operating procedures

Not decided

A.6People controls

0/8

A.6.1

Screening

Not decided

A.6.2

Terms and conditions of employment

Not decided

A.6.3

Information security awareness, education and training

Not decided

A.6.4

Disciplinary process

Not decided

A.6.5

Responsibilities after termination or change of employment

Not decided

A.6.6

Confidentiality or non-disclosure agreements

Not decided

A.6.7

Remote working

Not decided

A.6.8

Information security event reporting

Not decided

A.7Physical controls

0/14

A.7.1

Physical security perimeters

Not decided

A.7.2

Physical entry

Not decided

A.7.3

Securing offices, rooms and facilities

Not decided

A.7.4

Physical security monitoring

Not decided

A.7.5

Protecting against physical and environmental threats

Not decided

A.7.6

Working in secure areas

Not decided

A.7.7

Clear desk and clear screen

Not decided

A.7.8

Equipment siting and protection

Not decided

A.7.9

Security of assets off-premises

Not decided

A.7.10

Storage media

Not decided

A.7.11

Supporting utilities

Not decided

A.7.12

Cabling security

Not decided

A.7.13

Equipment maintenance

Not decided

A.7.14

Secure disposal or re-use of equipment

Not decided

A.8Technological controls

0/34

A.8.1

User end point devices

Not decided

A.8.2

Privileged access rights

Not decided

A.8.3

Information access restriction

Not decided

A.8.4

Access to source code

Not decided

A.8.5

Secure authentication

Not decided

A.8.6

Capacity management

Not decided

A.8.7

Protection against malware

Not decided

A.8.8

Management of technical vulnerabilities

Not decided

A.8.9

Configuration management

Not decided

A.8.10

Information deletion

Not decided

A.8.11

Data masking

Not decided

A.8.12

Data leakage prevention

Not decided

A.8.13

Information backup

Not decided

A.8.14

Redundancy of information processing facilities

Not decided

A.8.15

Logging

Not decided

A.8.16

Monitoring activities

Not decided

A.8.17

Clock synchronization

Not decided

A.8.18

Use of privileged utility programs

Not decided

A.8.19

Installation of software on operational systems

Not decided

A.8.20

Networks security

Not decided

A.8.21

Security of network services

Not decided

A.8.22

Segregation of networks

Not decided

A.8.23

Web filtering

Not decided

A.8.24

Use of cryptography

Not decided

A.8.25

Secure development life cycle

Not decided

A.8.26

Application security requirements

Not decided

A.8.27

Secure system architecture and engineering principles

Not decided

A.8.28

Secure coding

Not decided

A.8.29

Security testing in development and acceptance

Not decided

A.8.30

Outsourced development

Not decided

A.8.31

Separation of development, test and production environments

Not decided

A.8.32

Change management

Not decided

A.8.33

Test information

Not decided

A.8.34

Protection of information systems during audit testing

Not decided

Control titles are the Annex A titles from ISO/IEC 27001:2022. The standard's own text is not reproduced here; if you need the normative wording, buy the standard from ISO.

Being clear

A Statement of Applicability is a document, not a certification

Filling this in does not make anyone ISO 27001 certified. Certification comes from an accredited body auditing a working ISMS, and the SoA is one of the documents they will ask to see. It is a genuinely important one: it is where an auditor learns how you reasoned about scope.

The other thing worth saying plainly is that an SoA goes stale. The moment a system changes, a control gets implemented, or scope moves, the document drifts from reality, and the version in the audit folder stops matching the thing being audited. A spreadsheet cannot tell you when that has happened.

Where Alvor comes in

Alvor keeps the record an SoA is produced from, rather than the document itself: control applicability and implementation status maintained per control, evidence with freshness states, and named sign-offs. The Statement of Applicability is then generated from that record, on screen and as CSV, so it reflects the current state rather than the day someone last opened the spreadsheet.

Compliance moduleAnnex A coverage mapISO 27001 compliance

Free tool

The security architecture review checklist

45 verifiable statements across seven sections, with a sign-off strip that expects named individuals. Free, printable, no email gate.

Open the checklist

Get started

See how Alvor works for your role

Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.

Request DemoView Pricing
ALVOR

Security architecture management and compliance: connected into one source of truth.

Security,
Simplified.

Platform

  • Overview
  • AI Assistant
  • Secure by Design
  • Asset Management
  • Risk Management
  • Compliance
  • Policy
  • Security Management
  • Third-Party Risk Management
  • Business Continuity

Capabilities

  • Security Architecture
  • Security Design Review
  • Threat Modeling
  • Dependency Mapping
  • Data Governance
  • Components & SBOM
  • System Security Plan
  • Deployment models

Solutions

  • All solutions
  • CISO
  • Security architect
  • GRC lead
  • Engineering leader
  • Startups
  • Mid-Market
  • Enterprise
  • Regulated & Sovereign

Frameworks

  • ISO 27001
  • SOC 2
  • NIST CSF
  • HIPAA
  • GDPR
  • Essential Eight
  • SABSA
  • PCI DSS
  • CMMC
  • FedRAMP
  • Control alignment

Advisory

  • Advisory overview
  • Assess
  • Architect
  • Build
  • Operate
  • All engagements

Company

  • About
  • Blog
  • Security
  • Pricing
  • Compare Alvor

© 2026 Alvor Pty Ltd · ABN 40 700 022 546 · All rights reserved.

PrivacyTermsCookie PolicyDisclosure