ISO Statement of Applicability Generator

The free ISO SoA generator builds a Statement of Applicability for ISO 27001, ISO 42001 or ISO 27701. Pick a standard, record your applicability decisions, and export a finished SoA to Excel or PDF.

Nothing you type is sent anywhere. The whole tool runs in your browser and your work is saved only on this device.

1 Choose a standard

Loading the generator — supports ISO/IEC 27001:2022 (93 controls), ISO/IEC 42001:2023 (38 controls) and ISO/IEC 27701:2025 (78 controls), plus an ISO/IEC 27017:2026 cloud extension.

How the ISO SoA generator works

The Statement of Applicability is the document a certification body asks for first. It lists every control in the standard’s Annex A, says whether each one applies to you, and gives the reason. Building it by hand means copying a control list into a spreadsheet and formatting it — work that takes an afternoon and adds nothing.

This ISO SoA generator does that part for you. Pick a standard and it loads the full control set with the official reference and title for each control, plus a plain-English explanation of what the control actually asks for. You record the decisions; it produces the document.

ISO SoA generator workflow: choose a standard, add organisation details, decide each control, export the Statement of Applicability

Your work is saved in the browser as you go, so a 93-control SoA does not have to be finished in one sitting. You can also download a small progress file and hand it to a colleague to continue, which is useful when the control owners are spread across several teams.

Nothing you type is uploaded

The whole tool runs on your device. Control decisions, justifications and organisation details never reach our server, because there is no server involved — the Excel and PDF files are built in your browser. That matters if you are a consultant drafting an SoA with a client’s real scope and risk references in it.

What a Statement of Applicability must contain

ISO/IEC 27001:2022 clause 6.1.3 d) is specific. The SoA has to contain the necessary controls, the justification for including each one, whether it is implemented, and the justification for excluding any Annex A control you have left out. Miss any of those four and the document is incomplete, however good it looks.

The generator enforces this. Every control needs both a decision and a justification before the export is marked complete, and the progress bar tells you how many are still outstanding. You can export an unfinished SoA — sometimes you need a draft for a management review — but it will say plainly what is missing.

Beyond the mandatory four, the exported workbook carries the fields auditors normally expect: implementation status, the document or evidence that implements the control, and the control owner. The cover sheet records the organisation, the scope statement, the document reference and version, and the prepared, reviewed and approved sign-off.

Which ISO standards need an SoA

Not every management system standard has one. A Statement of Applicability belongs to standards built around a reference set of controls, which is why this tool covers four and not forty:

  • ISO/IEC 27001:2022 — 93 Annex A controls across organisational, people, physical and technological themes.
  • ISO/IEC 42001:2023 — 38 controls for AI management systems. Note that section A.6 uses three-level references such as A.6.2.4, unlike every other section.
  • ISO/IEC 27701:2025 — 78 controls. The 2025 edition is a standalone standard, so a privacy information management system can now be certified without an ISO 27001 certificate underneath it.
  • ISO/IEC 27017:2026 — four cloud controls that extend the ISO 27001 SoA rather than forming their own. The generator appends them to the same document, because a certification body audits one SoA, not two.

ISO 9001, ISO 14001, ISO 45001 and ISO 22301 have no Annex A control set and therefore no Statement of Applicability. If a template promises you an ISO 9001 SoA, treat the rest of it with suspicion.

The 2026 edition changes worth knowing

ISO/IEC 27017:2026 dropped the old CLD.x.x.x numbering used by the withdrawn 2015 edition. Its cloud controls now continue the ISO 27002 sequence as 5.38, 5.39, 8.35 and 8.36. If your existing cloud SoA still lists CLD references, it is written against a superseded edition.

Writing justifications an auditor will accept

Most SoAs fail on the justification column rather than the decisions. A justification has to connect the control to something outside the SoA — a risk, a legal obligation or a contract. “Best practice” and “industry standard” connect to nothing and will be challenged.

Useful justifications for inclusion look like “Required to treat risk R-014; also a contractual requirement of the Acme master services agreement.” Useful justifications for exclusion are equally concrete: “The organisation carries out no in-house software development and holds no source code.”

Work from your risk treatment plan first and compare it against Annex A afterwards. Opening the annex and ticking boxes produces a document that collapses under one follow-up question, which is exactly what a Stage 2 audit is designed to ask.

Five mistakes that fail an audit

  1. Excluding a control with no justification. Exclusions need a reason in writing just as much as inclusions do — clause 6.1.3 d) says so explicitly.
  2. Claiming everything is implemented. A wall of “Implemented” invites sampling. “Partial” with a target date is more credible and easier to defend.
  3. Maintaining two competing SoAs. Cloud or privacy extension controls belong in the main document, not a second one.
  4. Letting it go stale. The SoA must be updated whenever the risk treatment plan changes, and reviewed at least annually.
  5. Using a superseded control list. Editions move. Check your control references against the current standard before an audit, not during one.

Frequently asked questions

Is the ISO SoA generator really free?

Yes, with no sign-up and no email required. We sell documentation toolkits, and this tool exists because the people who need an SoA are usually the people who need the rest of the documentation too.

Does the control text come from the standard?

No. The generator uses each control’s official reference and short title, and pairs them with a plain-English explanation written by us. The normative control text is ISO copyright — you should buy the standard from ISO or your national standards body, and this tool is not a substitute for it.

Can I use the exported SoA with a client?

Yes. The export carries your organisation’s details, not ours, with a single credit line in the footer. Consultants are welcome to use it in client work.

What format are the exports?

A styled .xlsx workbook with a cover sheet, the control table and a summary by theme, or a print-ready PDF produced through your browser’s print dialog — choose “Save as PDF” as the destination.

Will it tell me which controls apply to my organisation?

No, and be wary of anything that claims it will. Applicability follows from your own risk assessment and legal obligations. The generator structures and formats your decisions; the decisions are yours.

What if I need the supporting documents too?

An SoA names the controls; an auditor then asks to see the policies, procedures and records behind them. Our ISO 27001 toolkit, ISO 42001 toolkit and ISO 27701 toolkit cover that layer, and there are free sample templates if you want to see the house style first.

This tool helps you record and format your own applicability decisions. It is not a substitute for the standard itself, and it does not tell you which controls apply to your organisation — that judgement is yours and must follow your risk assessment.