Back to the library
Template
Cybersecurity

Statement of Applicability — ISO 27001:2022

Pre-mapped SoA covering all 93 Annex A controls with justification language, owner fields and evidence pointers ready for Stage 1.

May 2026 Template · DOCX + XLSX By Sara Vanhoof
Overview

Pre-mapped SoA covering all 93 Annex A controls with justification language, owner fields and evidence pointers ready for Stage 1.

Written by Sara Vanhoof and pressure-tested on live cybersecurity engagements before publication, this template is designed to move a programme forward the same week you open it.

Every section is annotated with the decision it should unblock, the owner it should sit with, and the evidence it should leave behind — so the artefact still holds up under audit twelve months later.

What you'll take away
  • Field-tested against real Stage 1 and Stage 2 audit findings
  • Mapped to the controls and cadences the Cybersecurity faculty deploy in cohort work
  • Editable, credit-line optional — use it inside your organisation without attribution
  • Includes evidence pointers, owner fields and a first-90-days cadence
Who this is for
  • Heads of GRC, CISOs, DPOs and internal audit leads
  • Lead Implementers and Lead Auditors preparing for cert cycles
  • Consulting teams standing up client programmes
Go deeper

Turn this template into a certification.

The faculty behind this resource teach the full programme in cohort. Enrol in ISO/IEC 27001 Lead Implementer and build the operating model end-to-end with expert review.