ISO 27001 Statement of Applicability Generator
Work through all 93 ISO/IEC 27001:2022 Annex A controls, mark each as applicable, excluded or partial with your justification, and export a structured starter SoA — a draft to refine with your auditor, not a finished artefact.
This produces a STARTER DRAFT only. It does not reproduce ISO/IEC 27001:2022 control titles or normative text — refer to the standard from your national standards body. A real Statement of Applicability must reflect your risk assessment and risk treatment decisions and be reviewed internally before being assessed by a competent auditor or certification body.
0 of 93 controls decided · Applicable: 0 · Excluded: 0 · Partially applicable: 0
Before you export
Fill in the ISMS scope fields above (organization, scope statement, version, date) — a Statement of Applicability is incomplete without them.
- A.5.1 — No decision recorded yet
- A.5.2 — No decision recorded yet
- A.5.3 — No decision recorded yet
- A.5.4 — No decision recorded yet
- A.5.5 — No decision recorded yet
- A.5.6 — No decision recorded yet
- A.5.7 — No decision recorded yet
- A.5.8 — No decision recorded yet
- A.5.9 — No decision recorded yet
- A.5.10 — No decision recorded yet
- +83…
2. Annex A control decisions
Important
This tool generates a starter Statement of Applicability draft from your inputs. It is not legal advice, not an audit, does not certify your organization, and is not a statement of conformity. It does not by itself document all evidence, implementation status or inclusion rationale needed for a final SoA. Your SoA must be derived from your risk assessment and risk treatment, and confirmed with a competent auditor; some requirements are not captured here.
FAQ
- Is this a finished Statement of Applicability?
- No — it is a structured starter draft. A real SoA must be traceable to your risk assessment and risk treatment decisions and reviewed with your auditor. This tool helps you not miss a control and keep the justifications organised.
- Are these the official ISO control titles?
- No. We deliberately do not reproduce ISO/IEC 27001:2022 control titles or normative text. Each control shows its number and our own plain-English summary. Use the standard from your national standards body for official wording.
- Why must exclusions be justified?
- Excluding an Annex A control without a documented, defensible justification is a common audit issue. The tool flags any exclusion or partial status that has no justification so you can fix it before export.
- Do you store my answers?
- No. Everything runs in your browser. There is no form gate; the CSV/JSON export and printable view are generated locally.
By ISMS Copilot. Structured around ISO/IEC 27001:2022 Annex A. Control summaries are original editorial content; refer to the standard from your national standards body for official titles and normative requirements.
Ready to streamline your compliance work?
Built for speed, accuracy, and audit-ready output.
