Source
Controls, SoA & measures — found from sitemap — Vanta
Checked for Vanta on 1 Oct 2026
- Page
- https://www.vanta.com/collection/iso-27001/statement-of-applicability-iso-27001
- Checked
- 1 Oct 2026, 15:27 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:2b3a7e874433209f67fe2e4a27010bda95df212069608702d780269f9dee73ea
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Builtin count Report an error
“Connect your infrastructure to Vanta with our 400+ built-in integrations.”
-
Annex a controls Report an error
“Your Statement of Applicability should cover all 93 controls listed in ISO 27001:2022 Annex A — organized across four themes (Organizational, People, Physical, and Technological)”
-
Noncompliance notifications Report an error
“Identify areas of non-compliance with in-platform notifications.”
-
Automated evidence collection Report an error
“Automate evidence collection and centralize all your documents in one place.”
-
Auditor marketplace Report an error
“Find a Vanta-vetted auditor within the platform.”
-
Risk assessment Report an error
“Assess your risk holistically from one unified view.”
-
Action checklist Report an error
“Get a checklist of actions to help you make the needed changes.”
-
Automation claim Report an error
“Looking to automate up to 80% of the work for ISO 27001 compliance?”
-
Certification time claim Report an error
“Complete your ISO 27001 certification in half the time.”
-
API Report an error
“Vanta API”
-
Frameworks supported Report an error
“SOC 2 ISO 27001 GDPR HIPAA HITRUST USDP NIST AI RMF ISO 42001 CMMC CJIS NIS2 DORA CPS 234 EU AI Act Essential Eight Cyber Essentials FedRAMP CRI Custom frameworks Additional frameworks”
-
Soa capabilities Report an error
“Create a table that will become the structure of your Statement of Applicability that includes columns for the Annex A control, inclusion or exclusion of the control, reason for including/excluding the control, how the control was implemented, where the auditor can reference the control in your ISMS.”
-
Trust center Report an error
“Trust Center”
-
Questionnaire automation Report an error
“Questionnaire Automation”
-
Third party risk management Report an error
“Third Party Risk Management”