ClearPenTest

Audit and compliance

Statement of Applicability

Also called: SoA, ISO 27001 SoA

The Statement of Applicability is the ISO 27001 document listing every Annex A control, whether it applies to the organization, the justification for including or excluding it, and its implementation status. It is the central artifact a certification auditor works from.

Testing, with the report an auditor can actually use

A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.