Statement of Applicability Software
Statement of Applicability software. Every control shows the risks it treats.
The Statement of Applicability links every control to the risks it treats, with justifications your auditor can read. Not a spreadsheet you maintain by hand. ISO 27001:2022, $500/mo flat, unlimited users.
14-day trial · no card required · $500/mo after trial
Why spreadsheets drift
The Statement of Applicability documents which ISO 27001 controls you apply and why. Your auditor will ask for it at Stage 1, and they will ask you to defend the decisions at Stage 2.
Most teams maintain the SoA in a spreadsheet or a Word document. That works until the first management review, when the risk register changes and the SoA goes out of sync. By the time the surveillance audit arrives, the two documents tell different stories.
GapLedger keeps the Statement of Applicability and the risk register in the same system. Every control shows the risks it treats, and the justifications are visible in one place. No manual copying, no drift between documents.
Every control shows the risks it treats
ISO 27001 requires the Statement of Applicability to justify each control decision. Most organizations write the justification once and never revisit it. When the risk changes, the justification stays the same, and the auditor notices.
GapLedger links every control to the risks it treats. The SoA shows which controls apply to each risk, and which risks each control addresses. The justifications are visible in the same document, so your auditor can see the connection between the risk assessment and the control selection.
Clauses 4-10 and Annex A
The Statement of Applicability covers all 93 Annex A controls from ISO 27001:2022. GapLedger also includes the 18 management requirements from clauses 4 through 10, so the entire standard is in the same system.
Internal audits (clause 9.2), management reviews (clause 9.3), and nonconformities and corrective actions (clause 10.1) are tracked in the platform. The SoA and the ISMS are not separate documents; they are the same living system.
The full ISO 27001 ISMS
If you want the complete ISO 27001 software platform, read ISO 27001 software. That page covers the whole product: risk register, Statement of Applicability, CAPA log, internal audits, management reviews, and the one-click audit pack.
For more on the documentation approach, read ISO 27001 documentation. That page explains why a living management system stays current when a spreadsheet kit goes stale.
$500/mo flat. Unlimited users.
Or $5,400/yr and save 10%. No per-employee tax, no renewal surprises, cancel anytime.
Frequently asked questions
Can I maintain the SoA in a spreadsheet?
Yes, and many organizations do. The problem is that the SoA and the risk register drift apart over time. When a risk changes or a control is updated, you must remember to update both documents. GapLedger keeps the SoA and the risk register in the same system, so every control shows the risks it treats.
What is the difference between GapLedger and a documentation kit?
A documentation kit is a set of templates and spreadsheets you download, fill in, and save as PDFs. GapLedger is a living management system that stays current as your ISMS changes. The Statement of Applicability and the risk register are in the same system, not maintained as separate documents.
Does GapLedger certify us?
No. GapLedger is compliance management software, not a certification body. Certification decisions rest with your accredited auditor.
What does Core include?
Full ISO 27001:2022 (93 Annex A controls plus 18 clause 4-10 requirements), unlimited users, risk register, Statement of Applicability, CAPA log, internal audits, management reviews, and the one-click audit pack. $500/mo or $5,400/yr.
Does GapLedger include NIST CSF 2.0?
Yes. NIST CSF 2.0 is included with Core at no extra charge.