Skip to content

Statement of Applicability

Statement of Applicability in Keel

The Statement of Applicability (SoA) is the mandatory ISO/IEC 27001 deliverable required by Clause 6.1.3 d): for every Annex A control, it records whether the control applies, why, and how it’s implemented. Keel generates it from your controls so it stays in sync as your program moves, and exports the grid your auditor asks for. Open it from Statement of Applicability in the sidebar.

Keel builds one row per Annex A control, in the standard’s order, grouped by the four Annex A themes (A.5 Organizational, A.6 People, A.7 Physical, A.8 Technological). Each row carries:

  • ApplicabilityApplicable or Excluded.
  • Related controls — the Keel controls mapped to that Annex A reference, so applicability and implementation status are grounded in real controls rather than a self-assessment.
  • Implementation statusImplemented, In progress, Gap, Not started, or No control mapped, derived from the state of the mapped controls.
  • Justification — the reason the control is included (often traced to your risk assessment or a legal/contractual requirement) or the reason it’s excluded.

The summary tiles across the top count total Annex A controls, how many are applicable vs. excluded, how many are implemented, and how many carry a justification.

Excluding a control on the SoA (or from Scope) removes it from your readiness score and marks it excluded here, with the exclusion reason recorded against it. Use Manage scope to work applicability in bulk. Record a justification for each control either way — an auditor expects a reason for every inclusion and every exclusion.

Owners and admins can set the SoA’s document-control block: a version, the approver’s name and role, an approval date, and an ISMS scope statement. These print on the exported document so it reads as a controlled, approved record.

  • Download SoA (PDF) — a branded, print-ready document.
  • Download SoA (Excel) — the spreadsheet grid, one row per Annex A control, with separate Justification for inclusion and Reason for exclusion columns (the ISO SoA convention) and a header block of organization, framework, scope, and approval metadata.