The Statement of Applicability, usually shortened to SoA, records which of the Annex A information security controls apply to your ISMS, whether each is implemented, and the justification for including or excluding it.
It is mandatory under ISO 27001 and has no equivalent in ISO 9001. Auditors typically ask for it first, because it defines what the rest of the audit will examine.
What it must contain
For every Annex A control: whether it is applicable, the justification for that decision, whether it is currently implemented, and a reference to how — a policy, a procedure, a technical measure.
Exclusions are permitted and normal. Not every organisation has software development, physical data centres, or teleworkers. What is not permitted is excluding a control because implementing it is inconvenient.
Why it cannot be bought
The SoA is the output of your risk assessment. It only makes sense in relation to your assets, your threats and your risk treatment decisions. A template SoA describes a fictional organisation, and an experienced auditor identifies one quickly — usually by asking why a particular control was excluded and finding that nobody knows.
This is also why compliance automation platforms, which are genuinely good at collecting evidence, cannot produce it for you. Evidence collection is a different activity from deciding which controls your organisation needs and why.
Keeping it current
The SoA changes when the organisation changes. New systems, new suppliers, new locations and new services all affect applicability. An SoA that has not been touched since certification is a reliable sign the ISMS has stopped being maintained.