If your startup is going for ISO 27001, the document the auditor opens first is the Statement of Applicability (SoA). Most engineering teams build it backwards and pay for it at the audit. Here's the mental model that actually holds up.

What the SoA actually is

The SoA is one document that lists every control in Annex A of ISO/IEC 27001:2022 and states, for each: does it apply to you, why, and what's its status. It's not optional — clause 6.1.3 d) names it by name as documented information you must produce. It's one of the very few documents the standard requires explicitly.

If your ISMS were a map, the SoA is the legend. It ties your assessed risks to the specific controls you've decided to operate.

Annex A:2022 has 93 controls in four themes: Organizational (A.5, 37 controls), People (A.6, 8), Physical (A.7, 14), and Technological (A.8, 34). The SoA walks all 93 — including the ones you exclude. The completeness is the point: an auditor should see you considered the whole set and made a deliberate call on each, not cherry-picked.