[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:the-iso-27001-statement-of-applicability-for-a-software-company-the-93-controls-the-four-columns-of-clause-6-1-3-d-the-exclusions-an-auditor-accepts-and-a-page-that-writes-it":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","the-iso-27001-statement-of-applicability-for-a-software-company-the-93-controls-the-four-columns-of-clause-6-1-3-d-the-exclusions-an-auditor-accepts-and-a-page-that-writes-it","The ISO 27001 Statement of Applicability for a software company: the 93 controls, the four columns of Clause 6.1.3(d), the exclusions an auditor accepts, and a page that writes it","The Statement of Applicability is the one ISO 27001 document an auditor reads before anything else, and Clause 6.1.3(d) makes it four questions per control: is it necessary, why is it included, is it implemented, and why is any Annex A control left out. For a software company with no offices of its own and a hosted stack, the 93 controls of the 2022 edition sort into the ones that apply in full, the handful that are honestly excluded, and the partly implemented ones that decide the audit's findings. What each column means, the exclusions an auditor accepts and the ones they never do, how the Statement follows the risk treatment plan, and a free page that writes it in six languages with the statuses in the address.","2026-09-12",{"who":10,"when":11,"do":12},"A software company building or running an ISO 27001 information security management system, at the point where the risk assessment is done and the controls have to be declared, and the same company a year later when the surveillance audit asks what changed.","Before the certification audit, as the output of the risk treatment of Clause 6.1.3, and again whenever a control's status or a scope changes; the 2022 edition's 93 controls are the ones every new certificate and every certificate transitioned by 31 October 2025 is audited against.","Start from all 93 controls applicable and planned; mark a control implemented only when its evidence exists; exclude a control only with a written reason tied to the scope; write the Statement as a table with the four columns and date it; the free page writes it from the statuses and carries them in the address.","\nEvery ISO 27001 audit opens the same way: the auditor asks for the scope and the Statement of Applicability, and reads the second against the first before looking at a single policy. The reason is in Clause 6.1.3 of ISO\u002FIEC 27001:2022, the risk treatment clause: after the risks are assessed, the organisation chooses the controls it needs, compares them against Annex A to check nothing necessary has been left out, and then produces a Statement of Applicability that says, for every control, whether it is necessary, why it is included, whether it is implemented, and why any Annex A control has been excluded. This article reads that document for a software company, against the 93 controls the package holds as data and the [free page](\u002Fiso-27001\u002Fstatement-of-applicability) that writes it.\n\n## What the four columns mean\n\nThe first column is the control itself: the Annex A reference, A.5.1 to A.8.34, which is the identifier the auditor and the company must both mean the same thing by, and a title. The titles on the page and in the document are StandardOS's own plain-language descriptions of what each control is about, because the standard's wording is ISO's copyrighted text and a Statement does not need it; the reference is what makes the row auditable. The second column is applicability: whether the control is necessary for the scope, which for a control from Annex A means the answer to \"is there a risk in the scope this control treats\". The third is implementation: whether the control is in place, in full, in part, or not yet, which the auditor will test against evidence rather than against the word in the column. The fourth is the justification: for an included control, the risk treatment that needs it; for an excluded one, the reason it does not apply to the scope. The Statement is not a checklist of good intentions; it is the map between the risk treatment plan and the evidence, and every row that says \"implemented\" is a promise the audit will collect on.\n\n## The exclusions an auditor accepts, and the ones they never do\n\nA software company with no premises of its own, a hosted stack and a remote team has a real case for excluding some of the 14 physical controls of A.7, because the physical perimeter, the entry controls and the equipment siting are the hosting provider's, assessed under the supplier controls A.5.19 to A.5.22 rather than operated by the company. That exclusion is accepted when the Statement says so in those words: no physical premises within the scope, the provider certified and its certificate on file, the supplier controls applicable and implemented. The exclusions an auditor never accepts are the ones that remove a control because it is inconvenient: excluding secure development (A.8.25 to A.8.31) because \"we are a small team\", excluding logging (A.8.15) because the logs are in the cloud provider's console, excluding supplier controls because the suppliers are large. A control is excluded because no risk in the scope needs it, never because implementing it is work, and the justification has to survive the question \"what if that risk materialises\". Where a control applies to part of the scope, the honest status is partly implemented with the part named, not excluded and not implemented.\n\n## Where the statuses come from\n\nThe Statement follows the risk treatment plan, not the other way around: a control is necessary because a risk in the register is treated by it, and the plan names the control, the owner and the date. A company that writes the Statement first and the risk register afterwards produces two documents that disagree, and an auditor finds the disagreement in the first hour. The order is the scope (Clause 4.3), the risk assessment (6.1.2), the treatment plan (6.1.3(e)), then the Statement (6.1.3(d)), with each row's justification pointing back at the risk. Implementation is then a matter of evidence: the policy approved and published for A.5.1, the access review record for A.5.18, the backup test for A.8.13, the log retention setting for A.8.15. The page starts every control as applicable and planned, which is the honest state of a system being built, and moves a control to implemented only when the company says the evidence exists.\n\n## The Statement over time\n\nThe Statement is dated, and it changes: a new product feature adds a risk and turns a planned control into a necessary one; a move from an office to a fully remote team turns three physical controls into exclusions; a surveillance audit's finding turns an \"implemented\" into a \"partly\" until the corrective action closes. Clause 9.3 has management review the changes, and Clause 10.2 has the nonconformities corrected, so each version of the Statement is kept with its date, and the auditor at the surveillance audit asks for the diff. The free page keeps the statuses in the address, one character per control in Annex A order, so a version is a link that can be sent, kept, and compared.\n\n## What to do with it\n\nTake the risk register and, for each risk, name the controls that treat it; every control named is applicable. For every Annex A control not named, write why it does not apply to the scope, in one sentence that names the scope element that is absent, or make it applicable and planned. Mark a control implemented only when the evidence can be shown today. Write the four columns as a table, date it, and put the scope on top. The [free page](\u002Fiso-27001\u002Fstatement-of-applicability) does that for the 93 controls, with the [controls guide](\u002Fiso-27001\u002Fcontrols) beside it for what each control asks, the [scope statement](\u002Farticles\u002Fthe-iso-27001-scope-statement-why-a-certificate-that-says-head-office-does-not-cover-your-saas-what-clause-4-3-asks-for-what-a-buyer-under-dora-checks-and-three-that-pass) as the first line, and the [cost page](\u002Fiso-27001\u002Fcost) for how many auditor days the scope buys.\n",1789383984874]