WHAT IS THIS STATEMENT OF APPLICABILITY (SOA) TEMPLATE FOR? It is an Excel‑based template designed to help organisations document their compliance with ISO 27001:2022 by providing pre‑written justifications for all 93 Annex A controls – both applicable and non‑applicable.
Stop writing your SoA from scratch. This Statement of Applicability (SoA) covers all 93 Annex A controls of ISO/IEC 27001:2022 – with pre‑written justifications for both applicable and non‑applicable controls.
Created by an ISO 27001 Certified Lead Auditor with 15+ years of experience in critical infrastructure security, this editable Excel template gives you a head start on one of the most important documents for certification.
AT A GLANCE (KEY SPECIFICATIONS)
• Framework Standard: ISO/IEC 27001:2022 (All 93 Annex A controls)
• Target Audience: CISOs, Compliance Officers, Internal Auditors, Consultants, SMEs preparing for certification
• File Format: Editable .XLSX (macro‑free, tested on Office 2010+)
• Key Features: Pre‑written justifications for Yes/No controls, Dual‑row design (keep what fits, delete the rest), Evidence items & responsible owners, Implementation status & review frequency, Document control & revision history
WHY CHOOSE THIS SOA?
• Auditor‑Grade Expertise: Built by a Certified Lead Auditor who has reviewed dozens of real SoAs during certification audits – the justifications are practical, not theoretical.
• Dual‑Row Design: For controls that may not apply to every organisation (e.g., A.5.23 Information security for use of cloud services, physical security, outsourced development), the SoA provides both a "Yes" row and a "No" row – keep what fits and delete the rest.
• Complete Coverage: All 93 Annex A controls organised into four themes – Organisational (37), People (8), Physical (14), and Technological (34).
• Zero Risk: Macro‑free, clean Excel file tested on Excel 2010+. No subscriptions, no recurring fees.
WHAT YOU GET (macro‑free, clean Excel file, tested on Excel 2010+):
• Full control coverage – Every Annex A control from A.5.1 (Policies) and A.5.23 (Information security for use of cloud services) to A.8.34 (Technical compliance), organised into four themes: Organisational (37 controls), People (8), Physical (14), and Technological (34).
• Dual‑row applicability – For controls that may not apply to every organisation (e.g., physical security, cloud services, outsourced development), the SoA provides both a "Yes" row and a "No" row. Keep the one that fits your organisation and delete the other. No more manual reformatting.
• Pre-written justifications – Each control includes a ready‑to‑use justification. For "Yes" rows, the justification explains why the control applies. For "No" rows, expertly drafted exclusion justifications are provided (e.g., "organisation has no physical premises" or "no outsourced development performed"). You can edit these to match your exact context.
• Evidence items & responsible owners – For every control, the tool lists example evidence items (e.g., "Information Security Policy signed by CEO") and suggested responsible roles (e.g., CISO, IT Security Manager, HR Manager).
• Implementation status & review frequency – Columns for marking whether the control is implemented (Yes/No) and how often evidence is reviewed (e.g., daily, quarterly, annually).
• Document control & revision history – A dedicated Document Control sheet tracks version, author, approval status, and distribution. The Read Me sheet provides step‑by‑step instructions.
WHY THIS SOA IS DIFFERENT?
Most SoA templates are simple checklists. This one is built by a Certified Lead Auditor who has reviewed dozens of real SoAs during certification audits. The justifications are practical, not theoretical. The dual‑row design saves hours of reformatting.
WHO IS THIS FOR?
• Small and medium enterprises finalising their ISO 27001 documentation
• Consultants who need a professional SoA for multiple clients
• Security practitioners preparing for Stage 2 audits
• Already‑certified organisations updating their SoA for surveillance audits or as part of ongoing ISMS maintenance
WHO THIS IS NOT FOR?
• Large enterprises looking for automated, integrated GRC platforms – this is a focused Excel template, not a SaaS solution
• Users seeking a complete ISMS documentation suite – this is the Statement of Applicability only, not the full policy/procedure suite
• Organisations tied to the old standard: Users looking specifically for the outdated ISO 27001:2013 framework – this template is strictly mapped to the updated ISO 27001:2022 structure and its 93 controls
What this tool does not include – This listing is for the Statement of Applicability only. It does not include the Self‑Assessment Tool, ISMS Manual, or full policy/procedure suite.
Immediate download – You receive an editable Excel file. No macros, no scripts. Own it forever – no subscription fees.
Got a question about the product? Email us at support@flevy.com or ask the author directly by using the "Ask the Author a Question" form. If you cannot view the preview above this document description, go here to view the large preview instead.
Source: Best Practices in ISO 27001 Excel: ISO 27001:2022 Statement of Applicability (SoA) Excel (XLSX) Spreadsheet, Brahim Yahyaoui Consulting
This document is available as part of the following discounted bundle(s):
Save %!
ISO 27001:2022 ISMS Implementation Toolkit
This bundle contains 5 total documents. See all the documents to the right.
|
Download our FREE Digital Transformation Templates
Download our free compilation of 50+ Digital Transformation slides and templates. DX concepts covered include Digital Leadership, Digital Maturity, Digital Value Chain, Customer Experience, Customer Journey, RPA, etc. |