ISO Clause Mapper
Determined if specific ISO clauses apply to your scope.
Last reviewed by the Radiatus Cloud team
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
Determine which ISO clauses apply
An ISO standard contains many clauses and controls, and not all of them apply to every organisation’s particular scope. This tool helps you determine whether specific ISO clauses apply to your scope, so you can focus your effort on the requirements that are genuinely relevant rather than treating the entire standard as uniformly mandatory.
Why applicability matters
An ISO standard like 27001 defines a broad set of controls, but the standard itself expects you to determine which of them apply to your defined scope and to justify any exclusions in a formal statement of applicability. Treating every single clause as mandatory wastes considerable effort on controls that are irrelevant to your situation, while excluding one without a documented justification becomes an audit finding. Mapping applicability, deciding which clauses your particular scope genuinely requires, is therefore a required and central part of the whole process, and getting it right focuses the entire effort squarely on what actually matters for your organisation.
A tool, not legal advice
It runs entirely in your browser, so nothing you enter is uploaded, which matters when the input describes your security or compliance posture and should stay on your own machine.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
Do all ISO clauses apply to everyone?
No. The standard expects you to determine which controls apply to your defined scope and justify any exclusions, rather than treating all as mandatory.
What is a statement of applicability?
A document recording which controls apply to your scope and why any are excluded, which is a required part of an ISO 27001 implementation.
Why does applicability matter?
Because effort on irrelevant controls is wasted, while excluding one without justification is an audit finding. Mapping it focuses the effort correctly.
How does the tool help?
By helping you reason about whether specific clauses apply to your scope, which is central to the standard’s process.
Is my input uploaded?
No. The tool runs entirely in your browser.
Privacy & Security
Processed locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.