Who can use this feature
Supported on Foundation, Growth, and Scale plans
The Statement of Applicability (SoA) is a cornerstone document when you’re pursuing ISO certifications. This guide will walk you through the process of generating and downloading SoA files effortlessly.
What Is the Statement of Applicability (SoA)?
The Statement of Applicability (SoA) is a critical document that provides a comprehensive overview of how your organization addresses each control within an ISO framework. It serves as a formal declaration that lists all in-scope and out-of-scope controls from an ISO framework, along with the applicability status of each control. Furthermore, it also includes the justifications for why controls are applicable or not applicable to your specific context.

Sample SoA file
You can download the SoA for the following frameworks:
ISO 27001:2022
ISO 27701:2019
ISO 27017:2015
ISO 27018:2019
ISO 42001:2023
Why Is the SoA Important?
It’s a critical component of your ISO journey. It:
Demonstrates Compliance: It provides a clear, auditable trail of how your organization meets the requirements of a specific ISO framework.
Meets Auditing Requirements: For both internal and external audits, the SoA streamlines the process by offering a consolidated view of your scope and implemented controls.
Guides Implementation: It acts as a practical roadmap, ensuring that you cover all relevant aspects of the framework by clearly defining which controls are in scope and how they are addressed.
Facilitates Stakeholder Communication: It demonstrates to partners and other stakeholders your systematic approach to security and compliance.
How To Download the SoA
Sign in to Scrut and go to Compliance → Frameworks using the left navigation panel.
Go to the ISO 27001:2022 or ISO 42001:2023 framework.
Pro Tip: Use the search bar to quickly find and select the framework.

Once you’re on the framework page, click the SoA tab, and click Generate New SoA.

Enter the SoA details, such as:
Enter a Version Name.
Select the frameworks for which you want to download the SoA.
Choose the SoA date.
Enter the names of users who prepared, reviewed, and approved the SoA. You can add multiple names in each section, and separate each name with a semicolon (;).
Include the change description of what’s changing in the current SoA versus the previous one.
Note:
ISO 27701:2019, ISO 27017:2015, ISO 27018:2019, and ISO 42001:2023 are dependent frameworks that rely on ISO 27001 and do not have standalone SoAs.
Click Proceed To Download.

Scrut will export the SoAs for the frameworks you’ve selected and send them to your email.
Click the Download SoA button to download the SoA as an XLSX file.


Sample SoA file
Editing SoA Details
To modify SoA details and generate a new file:
Go to Compliance → Framework, and open your required framework.
Navigate to the SoA tab and click the edit
icon next to the SoA you want to modify. 
Modify any of the details such as version name, selected frameworks, date, preparer, reviewer, approver, and change description.

Scrut will replace the existing file with a new SoA with the modified details.

You’ll receive an email with instructions on how to download the file once it’s ready.
FAQs & Troubleshooting
1: How to view previously downloaded SoAs?
Go to Compliance → Framework, open your required framework, and go to the SoA tab. The All SoAs table has details on all your previously downloaded SoAs.

2: Can I redownload a SoA?
Go to Compliance → Framework, open your required framework, and go to the SoA tab. Click the download icon next to the SoA to redownload it.

3: Can I delete a previously generated SoA?
Go to Compliance → Framework, open your required framework, and go to the SoA tab. Click the delete icon next to the SoA.

Heads Up!
You can only delete the latest SoA.
4: How do I change the logo in the SoA file?
By default, the SoA file includes the logo you’ve uploaded in your Scrut organization. To change this, go to Settings → Organization Info and replace the logo.

5: Can I include more than one reviewer or approver?
Yes. You can enter as many users as required.
