Statement of Applicability
The Statement of Applicability (SoA) is the mandatory ISO/IEC 27001 deliverable required by Clause 6.1.3 d): for every Annex A control, it records whether the control applies, why, and how it’s implemented. Keel generates it from your controls so it stays in sync as your program moves, and exports the grid your auditor asks for. Open it from Statement of Applicability in the sidebar.
What Keel generates
Section titled “What Keel generates”Keel builds one row per Annex A control, in the standard’s order, grouped by the four Annex A themes (A.5 Organizational, A.6 People, A.7 Physical, A.8 Technological). Each row carries:
- Applicability — Applicable or Excluded.
- Related controls — the Keel controls mapped to that Annex A reference, so applicability and implementation status are grounded in real controls rather than a self-assessment.
- Implementation status — Implemented, In progress, Gap, Not started, or No control mapped, derived from the state of the mapped controls.
- Justification — the reason the control is included (often traced to your risk assessment or a legal/contractual requirement) or the reason it’s excluded.
The summary tiles across the top count total Annex A controls, how many are applicable vs. excluded, how many are implemented, and how many carry a justification.
Applicability comes from your scope
Section titled “Applicability comes from your scope”Excluding a control on the SoA (or from Scope) removes it from your readiness score and marks it excluded here, with the exclusion reason recorded against it. Use Manage scope to work applicability in bulk. Record a justification for each control either way — an auditor expects a reason for every inclusion and every exclusion.
Document control
Section titled “Document control”Owners and admins can set the SoA’s document-control block: a version, the approver’s name and role, an approval date, and an ISMS scope statement. These print on the exported document so it reads as a controlled, approved record.
Export for your auditor
Section titled “Export for your auditor”- Download SoA (PDF) — a branded, print-ready document.
- Download SoA (Excel) — the spreadsheet grid, one row per Annex A control, with separate Justification for inclusion and Reason for exclusion columns (the ISO SoA convention) and a header block of organization, framework, scope, and approval metadata.
Next steps
Section titled “Next steps”- Frameworks & crosswalks: how one Keel control maps to many Annex A references.
- Get certified: where the SoA sits on the path to ISO 27001.