- Documentation
- Run your ISMS
The Statement of Applicability
The first document your auditor reads: recording which Annex A controls apply to you, why, and how Certaria keeps the decision trail.
Audience: ISMS Admin.
Where: the Certaria app, under Audit Readiness.
Why this matters: the Statement of Applicability is where you state, control by control, whether an ISO 27001 Annex A control applies to your organisation and what you have done about it. It is the document an auditor opens first, and the decisions in it are yours. Certaria gathers the evidence and does the arithmetic; it cannot decide applicability on your behalf, and any tool that offered to would be selling you a problem.
What you record against each control
Section titled “What you record against each control”- Whether it applies. If it does not, you must say why.
- Its implementation status, if it does apply.
- Your justification. For an excluded control this is not optional: an auditor will read it.
Evidence from your readiness scans attaches itself to controls automatically. That tells you what your tenant already supports. It does not tell you whether the control is in scope, which is the part only you know.
The decision trail
Section titled “The decision trail”Producing the document
Section titled “Producing the document”Export it as a PDF. Certaria produces the Statement of Applicability listing every Annex A control grouped by theme, with your applicability decision and justification against each. The finished document is kept against your organisation settings, so you can download or email it again later without producing it afresh.
Email it. You can send the most recent copy to recipients you choose, as a branded PDF attachment. It sends the copy that was last produced rather than making a new one, so if you have changed decisions since, export again first.
Working through it the first time
Section titled “Working through it the first time”There are 93 Annex A controls and doing all of them in one sitting is unrealistic. A workable order:
- Start with what the scan already evidences. Those controls have a factual basis in front of you and are quick to confirm.
- Then the controls you know do not apply. Exclusions need a justification, and writing it while the reason is fresh is much easier than reconstructing it later.
- Then the gaps. These are the real work, and each one usually becomes a task or a policy rather than a decision you can close today.
Your scope statement, set during onboarding, governs all of this. If you find yourself arguing about whether a control applies, the argument is usually about scope rather than the control.
Cyber Essentials overlap
Section titled “Cyber Essentials overlap”If you recorded Cyber Essentials during onboarding, Certaria tags the controls it already covers, so you are not asked to prove the same thing twice. The tag is a starting point rather than a conclusion: the two schemes overlap, they do not match.
Common failure modes
Section titled “Common failure modes”| Symptom | Cause | Fix |
|---|---|---|
| The emailed PDF is out of date | Email sends the last export, not the current state | Export again, then email |
| A control shows no evidence but you have implemented it | The control is implemented outside Microsoft 365, or the scan cannot see it | Record the status and justification by hand. Absence of automatic evidence is not absence of the control |
| Decision date looks wrong | It stamps once, at the first decision, and does not follow later edits | It records when you decided, not when you last typed |
| An excluded control has no justification | It was excluded without one | Add it. This is the first thing an auditor challenges |
- Evidence and scans, which feeds the decisions here
- Publish a policy, which is usually the next step for a control with a gap
- The compliance summary and audit pack