Statement of Applicability Explained Without Compliance Jargon
The SoA records which Annex A controls are applicable, why, and how the organisation addresses them.
What the SoA is for
The Statement of Applicability connects the organisation's risk treatment decisions to the selected control set. It is not a generic spreadsheet copied from another company.
Applicability needs a reason
The organisation should be able to explain why a control is applicable or not applicable based on its risks, context, legal and contractual requirements and chosen treatment.
Implementation status needs evidence
Writing "implemented" in a spreadsheet is not evidence. The organisation should be able to point to the process, system configuration, ownership and operating records that support the statement.
Keep it synchronised
Changes to systems, suppliers, scope and risk treatment can change applicability or implementation. The SoA should remain aligned with the live risk process.
Avoid copying control wording casually
Use the organisation's licensed copy of the applicable standard when building the formal SoA. A consulting template should not substitute for the standard itself.
Use the Readiness Review to define scope and the first assessment.