Statement of Applicability
An honest self-assessment of all 93 ISO/IEC 27001:2022 Annex A controls, recording for each whether it is implemented, partial, not implemented, inherited from a cloud provider, or not applicable — with evidence pointers into the repository.
What this policy commits us to
- Where a control is not built, the document says 'not implemented' and gives the real reason, rather than claiming a control that does not exist.
- Every evidence pointer names a real file or mechanism, or a numbered risk in the procurement-shared register.
- Physical controls are recorded as inherited from cloud subprocessors holding their own attestations.
- Explicitly a self-assessed statement: the certification audit and a signed-off SoA remain open items.
Need the detail behind this page?
Request access and we can share the full policy set, assessment reports, and completed questionnaires under NDA — or answer your security questionnaire directly.