Skip to content

The Statement of Applicability

The first document your auditor reads: recording which Annex A controls apply to you, why, and how Certaria keeps the decision trail.

Audience: ISMS Admin.

Where: the Certaria app, under Audit Readiness.

Why this matters: the Statement of Applicability is where you state, control by control, whether an ISO 27001 Annex A control applies to your organisation and what you have done about it. It is the document an auditor opens first, and the decisions in it are yours. Certaria gathers the evidence and does the arithmetic; it cannot decide applicability on your behalf, and any tool that offered to would be selling you a problem.

  • Whether it applies. If it does not, you must say why.
  • Its implementation status, if it does apply.
  • Your justification. For an excluded control this is not optional: an auditor will read it.

Evidence from your readiness scans attaches itself to controls automatically. That tells you what your tenant already supports. It does not tell you whether the control is in scope, which is the part only you know.

Export it as a PDF. Certaria produces the Statement of Applicability listing every Annex A control grouped by theme, with your applicability decision and justification against each. The finished document is kept against your organisation settings, so you can download or email it again later without producing it afresh.

Email it. You can send the most recent copy to recipients you choose, as a branded PDF attachment. It sends the copy that was last produced rather than making a new one, so if you have changed decisions since, export again first.

There are 93 Annex A controls and doing all of them in one sitting is unrealistic. A workable order:

  1. Start with what the scan already evidences. Those controls have a factual basis in front of you and are quick to confirm.
  2. Then the controls you know do not apply. Exclusions need a justification, and writing it while the reason is fresh is much easier than reconstructing it later.
  3. Then the gaps. These are the real work, and each one usually becomes a task or a policy rather than a decision you can close today.

Your scope statement, set during onboarding, governs all of this. If you find yourself arguing about whether a control applies, the argument is usually about scope rather than the control.

If you recorded Cyber Essentials during onboarding, Certaria tags the controls it already covers, so you are not asked to prove the same thing twice. The tag is a starting point rather than a conclusion: the two schemes overlap, they do not match.

SymptomCauseFix
The emailed PDF is out of dateEmail sends the last export, not the current stateExport again, then email
A control shows no evidence but you have implemented itThe control is implemented outside Microsoft 365, or the scan cannot see itRecord the status and justification by hand. Absence of automatic evidence is not absence of the control
Decision date looks wrongIt stamps once, at the first decision, and does not follow later editsIt records when you decided, not when you last typed
An excluded control has no justificationIt was excluded without oneAdd it. This is the first thing an auditor challenges