The Executive Guide to ISO/IEC 27001:2022 Statement of Applicability (SoA)
ISO/IEC 27001:2022 is the globally recognized international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). For high-growth startups, corporate enterprise entities, and defense suppliers, achieving an ISO 27001 certificate is the most comprehensive way to prove operational security controls to prospective partners and international auditors.
Under the core requirements of ISO 27001:2022 (specifically Clause 6.1.3), an organization must produce aStatement of Applicability (SoA). The SoA is the most critical document reviewed during a Stage 1 certification audit. It lists all information security controls identified during your risk assessment, notes whether each control is applicable or excluded, defines the implementation status, and crucially documents the legal or operational justifications for those decisions.
1. Understanding the 2022 Framework Restructuring
The publication of ISO 27001:2022 introduced a massive simplification of the Annex A control set. The previous 2013 version mapped 114 controls across 14 separate structural domains. The 2022 standard consolidated these into **93 controls** categorized into **4 simple themes**:
- Theme A.5: Organizational Controls (37 controls): Encompasses information security policies, roles, threat intelligence management, asset classification, and security in project and supplier relations.
- Theme A.6: People Controls (8 controls): Addresses human resource vulnerabilities, employment vetting, onboarding, continuous security training, and post-employment revocation.
- Theme A.7: Physical Controls (14 controls): Governs physical barriers, reception screening, server cabinets, room monitoring, and secure hardware disposal.
- Theme A.8: Technological Controls (34 controls): Focuses on network protection, endpoint security, cryptography keys, automated logs, secure coding, and cloud backup.
2. How to Defend Exclusions to Stage 1 ISO Auditors
Organizations often mistakenly assume they must implement all 93 controls to receive ISO certification. In reality, ISO 27001 explicitly permits the exclusion of controls, provided there is a logical, risk-based rationale. For example:
- Physical Controls Exclusion: If your startup is a 100% remote company, utilizes cloud hosting (AWS/GCP), and maintains no local storage or office rooms, you can legitimately exclude physical perimeters (7.1) and cabling security (7.11). The justification is that no corporate physical assets exist within the ISMS boundary.
- Software Coding Exclusion: If your business manages consulting or operational services and does not develop or release custom software products, you can exclude Theme A.8's secure software development standards (8.25-8.32).
3. Best Practices for Developing Your Audit-Ready SoA Memo
To survive Stage 1 audit inspection and prevent corrective action requests, keep the following rules in mind:
- Never leave justifications blank: Every single control—whether included or excluded—must have an explicit written rationale.
- Track continuous state changes: Security implementation is a moving target. Clearly document "In-Progress" controls alongside completed ones to demonstrate active management.
- Establish Executive Sign-off: Ensure both the CISO and Executive Team formally sign and version-control the Statement of Applicability document.