All 93 Annex A controls, ready to complete: applicability, justification, implementation status and evidence, with a live progress counter.
All 93 Annex A controls pre-loaded, with live progress counter · Excel (.xlsx) · Free, no email required
Every control from ISO/IEC 27001:2022 Annex A, pre-loaded and grouped by theme, with columns for applicability, justification, implementation status and evidence. A counter at the top tracks how many controls you have marked applicable, mirroring the “87 of 93” view auditors like to see at a glance.
| Theme | Controls |
|---|---|
| Organizational (5.1–5.37) | 37 controls: policies, roles, suppliers, cloud, incidents, continuity, legal |
| People (6.1–6.8) | 8 controls: screening, terms, training, discipline, remote working |
| Physical (7.1–7.14) | 14 controls: perimeters, entry, clear desk, equipment, media, disposal |
| Technological (8.1–8.34) | 34 controls: endpoints, access, malware, backup, logging, development |
The SoA is the mandatory ISO 27001 document listing all 93 Annex A controls and stating, for each, whether it applies to your ISMS, why, and whether it is implemented. It is required by clause 6.1.3 d) of ISO/IEC 27001:2022.
Yes, but every exclusion needs a documented justification, and auditors expect exclusions to be rare. A typical example is excluding development controls at a company that develops no software.
Yes, all 93 controls from ISO/IEC 27001:2022 Annex A are pre-loaded and grouped into the four themes.
ISOvault pre-seeds the 93 controls, links them to your risks and evidence, and exports a formatted Statement of Applicability as a Word document whenever your auditor asks. 14 days free, no card required.