Security Assurance · GRC · Secure AutomationRemote delivery for growing technology businesses
Security Assurance Insight

Statement of Applicability Explained Without Compliance Jargon

The SoA records which Annex A controls are applicable, why, and how the organisation addresses them.

Published 2026-09-03 · Tech Turn Technology

What the SoA is for

The Statement of Applicability connects the organisation's risk treatment decisions to the selected control set. It is not a generic spreadsheet copied from another company.

Applicability needs a reason

The organisation should be able to explain why a control is applicable or not applicable based on its risks, context, legal and contractual requirements and chosen treatment.

Implementation status needs evidence

Writing "implemented" in a spreadsheet is not evidence. The organisation should be able to point to the process, system configuration, ownership and operating records that support the statement.

Keep it synchronised

Changes to systems, suppliers, scope and risk treatment can change applicability or implementation. The SoA should remain aligned with the live risk process.

Avoid copying control wording casually

Use the organisation's licensed copy of the applicable standard when building the formal SoA. A consulting template should not substitute for the standard itself.

Need an evidence-based view of your own environment?
Use the Readiness Review to define scope and the first assessment.