Statement of Applicability — ISO 27001:2022
Pre-mapped SoA covering all 93 Annex A controls with justification language, owner fields and evidence pointers ready for Stage 1.
Pre-mapped SoA covering all 93 Annex A controls with justification language, owner fields and evidence pointers ready for Stage 1.
Written by Sara Vanhoof and pressure-tested on live cybersecurity engagements before publication, this template is designed to move a programme forward the same week you open it.
Every section is annotated with the decision it should unblock, the owner it should sit with, and the evidence it should leave behind — so the artefact still holds up under audit twelve months later.
- Field-tested against real Stage 1 and Stage 2 audit findings
- Mapped to the controls and cadences the Cybersecurity faculty deploy in cohort work
- Editable, credit-line optional — use it inside your organisation without attribution
- Includes evidence pointers, owner fields and a first-90-days cadence
- Heads of GRC, CISOs, DPOs and internal audit leads
- Lead Implementers and Lead Auditors preparing for cert cycles
- Consulting teams standing up client programmes
Turn this template into a certification.
The faculty behind this resource teach the full programme in cohort. Enrol in ISO/IEC 27001 Lead Implementer and build the operating model end-to-end with expert review.
How a regional bank rebuilt its ISMS in two cohorts
From a failed surveillance audit to a clean recertification in 11 months — what the security team changed in governance, evidence and training.
SOC 2 Type II readiness — 120-day sprint
Control-by-control checklist for CC-series criteria with owner, evidence type and the common ways auditors reject weak artefacts.
