Statement of Applicability (SoA) Generator
Identify the Secure by Design controls and associated risks that apply to your project, based on the data you handle, the people you serve and the technologies you use.
Project details
Capture the metadata that will appear on the front page of your Statement of Applicability.
How to use this tool
- 1. Enter project details.
- 2. Select the data types your service handles.
- 3. Identify your stakeholders.
- 4. Identify the technologies in scope.
- 5. Review the recommended controls, set priority and capture risks.
- 6. Export to Word, PDF or CSV.
All data is held in your browser. Nothing is sent to a server.
Data types in scope
Tick every data category your service will create, process, store or share. Each selection drives the list of applicable controls and the legislation that applies.
Stakeholders
Tick every group that will interact with the service or whose data is processed by it.
Technologies and architecture
Tick every technology component or pattern that is part of the design.
Applicable controls and risk register
Each control below has been identified as applicable to your selected data, stakeholders and technologies. Open a control to see its mapping to Secure by Design, NCSC CAF v4.0 and the NIST SP 800-53, and capture inherent and residual risk.
0 controls match
Review and export
Statement of Applicability ready
Export options
Generate a printable Statement of Applicability or a data file that can be imported into a project risk register.
Document preview
Configuration map
A traceability matrix of how scope becomes controls. Read across a row to see what a selection brings in; read down a column to see what put a control there. Generated live from the same gate, tier and weighting tables the tool uses to set defaults.
Secure by Design
What this tool maps to, what it does not cover, and where it fits in Secure by Design delivery.