{
  "schemaVersion": "artifactExample.v2",
  "artifactId": "SOA",
  "title": "Statement of Applicability (SoA)",
  "definitionRef": {
    "artifactId": "SOA",
    "definitionSchemaVersion": "artifactDefinition.v2",
    "definitionId": "SOA.artifactDefinition.v2",
    "title": "Statement of Applicability (SoA)"
  },
  "organization": "Arcfield",
  "examplePurpose": "Valid curated SoA configuration covering all 93 ISO/IEC 27001:2022 Annex A controls, including documented applicability decisions and justified exclusions.",
  "coverage": {
    "coverageType": "ISO/IEC 27001:2022 Annex A",
    "requiredControlCount": 93,
    "currentControlCount": 93,
    "coverageStatus": "Complete",
    "requiredControlRanges": [
      "A.5.1-A.5.37",
      "A.6.1-A.6.8",
      "A.7.1-A.7.14",
      "A.8.1-A.8.34"
    ],
    "exclusionRule": "Non-applicable controls remain in the SoA with explicit justification; they are never deleted."
  },
  "sections": [
    {
      "id": "title_page",
      "title": "Title Page",
      "values": {
        "Register Title": "Statement of Applicability",
        "Register ID": "SOA-REG-001",
        "Version": "1.1",
        "Status": "Approved",
        "Organization": "Arcfield",
        "Owner": "ISMS Manager",
        "Approver": "Top Management",
        "Classification": "Internal",
        "Effective Date": "2026-09-11",
        "Next Review Date": "2027-09-11"
      },
      "items": [
        "Register Title: Statement of Applicability",
        "Register ID: SOA-REG-001",
        "Version: 1.1",
        "Status: Approved",
        "Organization: Arcfield",
        "Owner: ISMS Manager",
        "Approver: Top Management",
        "Classification: Internal",
        "Effective Date: 2026-09-11",
        "Next Review Date: 2027-09-11"
      ],
      "contentType": "metadata"
    },
    {
      "id": "abstract",
      "title": "Abstract",
      "text": "This example is the complete Arcfield Statement of Applicability, covering all 93 ISO/IEC 27001:2022 Annex A controls with applicability decisions, justification, implementation status, ownership, evidence, risk linkage and treatment linkage. This coverage view belongs to the certified Arcfield Platform SoA in the surveillance cycle after certificate ARC-ISMS-2025-001.",
      "contentType": "narrative"
    },
    {
      "id": "document_control",
      "title": "Document Control",
      "rows": [
        {
          "Property": "Purpose",
          "Value": "Justify Annex A control applicability, implementation status, ownership and evidence for every ISO/IEC 27001:2022 Annex A control."
        },
        {
          "Property": "Used by",
          "Value": "ISMS Manager, Risk Manager, Control Owners, Internal Auditor, External Auditor, Top Management"
        },
        {
          "Property": "Maintained by",
          "Value": "ISMS Manager"
        },
        {
          "Property": "Evidence role",
          "Value": "Mandatory ISO 27001 document"
        },
        {
          "Property": "ISO reference",
          "Value": "ISO/IEC 27001:2022 Clause 6.1 and all Annex A controls A.5.1-A.8.34"
        },
        {
          "Property": "Review cadence",
          "Value": "Annual and after major risk, scope, legal, supplier, or control changes"
        }
      ],
      "contentType": "control_table"
    },
    {
      "id": "instructions",
      "title": "Instructions",
      "items": [
        "Keep one row for every Annex A control from A.5.1 through A.8.34.",
        "Do not delete non-applicable controls. Mark them as not applicable and record the justification.",
        "Base applicability decisions on ISMS scope, risk assessment, legal and contractual requirements, technology context and supplier dependency.",
        "Keep each applicable control linked to owner, implementation status, evidence status and evidence reference.",
        "Link controls to risks and treatment actions where relevant.",
        "Review the SoA before management review, internal audit and certification audit.",
        "Use sheets ending in “Ex” as read-only examples. Enter live data only on the matching “Wk” (Working) sheets.",
        "Every operative list is an Excel Table with frozen headers and filters. Add new rows on the next empty worksheet row beneath the table so Excel expands it — do not leave blank rows inside the table.",
        "Where a column offers a dropdown, choose a value from the list (Status, Owner role, Priority, Severity, Likelihood, Impact, Applicability, Evidence Status, Review Result). Do not invent free-text variants.",
        "Enter dates as YYYY-MM-DD. Date columns are validated and formatted accordingly.",
        "Review the Flag columns (Overdue, Review Due, Missing Owner, Missing Evidence). They calculate automatically and highlight gaps for follow-up.",
        "Keep Cover, Legal, Book, Lists and Metadata unchanged. System sheets are protected on purpose.",
        "Record an applicability decision for every Annex A control and keep Control / Evidence IDs consistent for Traceability."
      ],
      "contentType": "ordered_list"
    },
    {
      "id": "soa_schema",
      "title": "SoA schema",
      "schemaRef": {
        "definitionId": "SOA.artifactDefinition.v2",
        "sectionId": "soa_schema",
        "requiredColumnsRef": "sections.soa_schema.requiredColumns"
      },
      "rows": [
        {
          "Column": "Control ID",
          "Type": "text",
          "Required": "yes",
          "Description": "ISO/IEC 27001:2022 Annex A control identifier.",
          "Example": "A.5.9"
        },
        {
          "Column": "Control name",
          "Type": "text",
          "Required": "yes",
          "Description": "Official or implementation-oriented control name.",
          "Example": "Inventory of information and other associated assets"
        },
        {
          "Column": "Theme",
          "Type": "select",
          "Required": "yes",
          "Description": "Organizational, People, Physical, or Technological.",
          "Example": "Organizational"
        },
        {
          "Column": "Applicability",
          "Type": "select",
          "Required": "yes",
          "Description": "Applicability decision.",
          "Example": "Applicable"
        },
        {
          "Column": "Applicability justification",
          "Type": "text",
          "Required": "yes",
          "Description": "Reason why the control is applicable or excluded.",
          "Example": "Required because in-scope assets support customer, HR, code, identity and evidence processes."
        },
        {
          "Column": "Risk linkage",
          "Type": "text",
          "Required": "conditional",
          "Description": "Related risk, requirement, asset or process.",
          "Example": "RISK-2026-014"
        },
        {
          "Column": "Treatment linkage",
          "Type": "text",
          "Required": "conditional",
          "Description": "Related risk treatment, control implementation or baseline.",
          "Example": "RTP-2026-014"
        },
        {
          "Column": "Implementation status",
          "Type": "select",
          "Required": "yes",
          "Description": "Not started, Planned, In progress, Implemented, or Not applicable.",
          "Example": "Implemented"
        },
        {
          "Column": "Control owner",
          "Type": "text",
          "Required": "yes",
          "Description": "Role accountable for the control.",
          "Example": "Asset Manager"
        },
        {
          "Column": "Evidence status",
          "Type": "select",
          "Required": "yes",
          "Description": "Complete, Partial, Missing, or Not applicable.",
          "Example": "Complete"
        },
        {
          "Column": "Evidence reference",
          "Type": "text",
          "Required": "conditional",
          "Description": "Evidence record, register, policy, procedure or ticket.",
          "Example": "AI-REG-001"
        },
        {
          "Column": "Last review date",
          "Type": "date",
          "Required": "yes",
          "Description": "Last SoA decision review date.",
          "Example": "2026-08-29"
        },
        {
          "Column": "Next review date",
          "Type": "date",
          "Required": "yes",
          "Description": "Next planned review date.",
          "Example": "2026-11-29"
        },
        {
          "Column": "Decision status",
          "Type": "select",
          "Required": "yes",
          "Description": "Approval state of the SoA decision.",
          "Example": "Approved"
        },
        {
          "Column": "Notes",
          "Type": "text",
          "Required": "no",
          "Description": "Additional decision or evidence notes.",
          "Example": "Asset inventory is reference register."
        }
      ],
      "contentType": "schema_table"
    },
    {
      "id": "soa_control_register",
      "title": "SoA control register",
      "schemaRef": {
        "definitionId": "SOA.artifactDefinition.v2",
        "sectionId": "soa_control_register",
        "columnsRef": "sections.soa_control_register.columns"
      },
      "rows": [
        {
          "Control ID": "A.5.1",
          "Control name": "Policies for information security",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for ISMS governance and policy direction.",
          "Risk linkage": "REQT-5.2",
          "Treatment linkage": "SOA baseline",
          "Implementation status": "Implemented",
          "Control owner": "ISMS Manager",
          "Evidence status": "Complete",
          "Evidence reference": "ISP-001",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Policy approved and communicated."
        },
        {
          "Control ID": "A.5.2",
          "Control name": "Information security roles and responsibilities",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for assigning ISMS accountability.",
          "Risk linkage": "REQT-5.3",
          "Treatment linkage": "RACI ownership baseline",
          "Implementation status": "Implemented",
          "Control owner": "ISMS Manager",
          "Evidence status": "Complete",
          "Evidence reference": "RACI-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Role ownership defined."
        },
        {
          "Control ID": "A.5.3",
          "Control name": "Segregation of duties",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to privileged administration and approval workflows.",
          "Risk linkage": "RISK-2026-014",
          "Treatment linkage": "RTP-2026-014",
          "Implementation status": "In progress",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "SOD-CHK-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-29",
          "Decision status": "Approved",
          "Notes": "Q3 SoD review pending."
        },
        {
          "Control ID": "A.5.4",
          "Control name": "Management responsibilities",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for management commitment and oversight.",
          "Risk linkage": "REQT-5.1",
          "Treatment linkage": "Management review baseline",
          "Implementation status": "Implemented",
          "Control owner": "Top Management",
          "Evidence status": "Complete",
          "Evidence reference": "MR-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Reviewed in management review."
        },
        {
          "Control ID": "A.5.5",
          "Control name": "Contact with authorities",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for incident and regulatory escalation.",
          "Risk linkage": "IRP-2026",
          "Treatment linkage": "Communication Plan",
          "Implementation status": "Implemented",
          "Control owner": "Compliance Manager",
          "Evidence status": "Partial",
          "Evidence reference": "COMM-P-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Authority contact list maintained."
        },
        {
          "Control ID": "A.5.6",
          "Control name": "Contact with special interest groups",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant for threat intelligence and software security updates.",
          "Risk linkage": "RISK-2026-027",
          "Treatment linkage": "Threat intelligence process",
          "Implementation status": "Implemented",
          "Control owner": "Security Lead",
          "Evidence status": "Partial",
          "Evidence reference": "TI-SUB-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Security advisories monitored."
        },
        {
          "Control ID": "A.5.7",
          "Control name": "Threat intelligence",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for software and cloud threat awareness.",
          "Risk linkage": "RISK-2026-027",
          "Treatment linkage": "RTP-2026-027",
          "Implementation status": "In progress",
          "Control owner": "Security Lead",
          "Evidence status": "Partial",
          "Evidence reference": "TI-LOG-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-31",
          "Decision status": "Approved",
          "Notes": "Feeds vulnerability triage."
        },
        {
          "Control ID": "A.5.8",
          "Control name": "Information security in project management",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for product and ISMS implementation projects.",
          "Risk linkage": "RISK-2026-027",
          "Treatment linkage": "SSDLC-REL-2026-014",
          "Implementation status": "Implemented",
          "Control owner": "Project Manager",
          "Evidence status": "Partial",
          "Evidence reference": "SSDLC-REL-2026-014",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-27",
          "Decision status": "Approved",
          "Notes": "Security gates used."
        },
        {
          "Control ID": "A.5.9",
          "Control name": "Inventory of information and other associated assets",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required because in-scope assets support customer, HR, code, identity and evidence processes.",
          "Risk linkage": "RISK-2026-014",
          "Treatment linkage": "RTP-2026-014",
          "Implementation status": "Implemented",
          "Control owner": "Asset Manager",
          "Evidence status": "Complete",
          "Evidence reference": "AI-REG-001",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Asset inventory is reference register."
        },
        {
          "Control ID": "A.5.10",
          "Control name": "Acceptable use of information and other associated assets",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for user obligations on company assets and services.",
          "Risk linkage": "RISK-2026-046; HR-ONB-2026-023",
          "Treatment linkage": "Onboarding controls",
          "Implementation status": "Implemented",
          "Control owner": "HR Manager",
          "Evidence status": "Complete",
          "Evidence reference": "AUP-ACK-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Acknowledgement captured."
        },
        {
          "Control ID": "A.5.11",
          "Control name": "Return of assets",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required during offboarding and role changes.",
          "Risk linkage": "RISK-2026-033",
          "Treatment linkage": "OFC-2026-018",
          "Implementation status": "Implemented",
          "Control owner": "HR Manager",
          "Evidence status": "Complete",
          "Evidence reference": "OFC-2026-018",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Linked to offboarding."
        },
        {
          "Control ID": "A.5.12",
          "Control name": "Classification of information",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for handling and protection decisions.",
          "Risk linkage": "RISK-2026-046; RISK-2026-041; AI-REG-001",
          "Treatment linkage": "Classification standard",
          "Implementation status": "Implemented",
          "Control owner": "ISMS Manager",
          "Evidence status": "Complete",
          "Evidence reference": "CLASS-STD-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Classification values used in AI."
        },
        {
          "Control ID": "A.5.13",
          "Control name": "Labelling of information",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required to communicate classification handling.",
          "Risk linkage": "RISK-2026-021",
          "Treatment linkage": "Document control",
          "Implementation status": "Implemented",
          "Control owner": "Document Owner",
          "Evidence status": "Partial",
          "Evidence reference": "DR-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-28",
          "Decision status": "Approved",
          "Notes": "Template labelling under review."
        },
        {
          "Control ID": "A.5.14",
          "Control name": "Information transfer",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for customer, supplier and audit information transfer.",
          "Risk linkage": "RISK-2026-018",
          "Treatment linkage": "Supplier transfer controls",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "ITR-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Supplier transfer evidence pending."
        },
        {
          "Control ID": "A.5.15",
          "Control name": "Access control",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required to protect production, identity, HR and evidence systems.",
          "Risk linkage": "RISK-2026-031; RISK-2026-014",
          "Treatment linkage": "RTP-2026-014",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "ACM-APP-CRM-001",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-29",
          "Decision status": "Approved",
          "Notes": "Q3 access review in progress. Re-sampled after IL-005; less robust than the Stage 2 sample; evidence Partial."
        },
        {
          "Control ID": "A.5.16",
          "Control name": "Identity management",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for lifecycle management of user identities.",
          "Risk linkage": "RISK-2026-014",
          "Treatment linkage": "IAM lifecycle controls",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "IAM-CTRL-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-29",
          "Decision status": "Approved",
          "Notes": "Identity provider tenant is AST-005."
        },
        {
          "Control ID": "A.5.17",
          "Control name": "Authentication information",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for authentication secrets and recovery.",
          "Risk linkage": "RISK-2026-031",
          "Treatment linkage": "RTP-2026-031",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "IAM-CTRL-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-09-30",
          "Decision status": "Approved",
          "Notes": "Break-glass review pending."
        },
        {
          "Control ID": "A.5.18",
          "Control name": "Access rights",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required to grant, review and revoke access rights.",
          "Risk linkage": "RISK-2026-014",
          "Treatment linkage": "RTP-2026-014",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "ARR-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-29",
          "Decision status": "Approved",
          "Notes": "Access review active."
        },
        {
          "Control ID": "A.5.19",
          "Control name": "Information security in supplier relationships",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for cloud and SaaS supplier dependencies.",
          "Risk linkage": "RISK-2026-043; RISK-2026-018",
          "Treatment linkage": "RTP-2026-018",
          "Implementation status": "In progress",
          "Control owner": "Supplier Manager",
          "Evidence status": "Partial",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-15",
          "Decision status": "Approved",
          "Notes": "Supplier contact update pending."
        },
        {
          "Control ID": "A.5.20",
          "Control name": "Addressing information security within supplier agreements",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for supplier security terms.",
          "Risk linkage": "RISK-2026-018",
          "Treatment linkage": "RTP-2026-018",
          "Implementation status": "In progress",
          "Control owner": "Supplier Manager",
          "Evidence status": "Partial",
          "Evidence reference": "CSS-2026-001",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-15",
          "Decision status": "Approved",
          "Notes": "Exit support clause pending."
        },
        {
          "Control ID": "A.5.21",
          "Control name": "Managing information security in the ICT supply chain",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for SaaS, repository, identity and hosting chain.",
          "Risk linkage": "RISK-2026-043; RISK-2026-018",
          "Treatment linkage": "ICT supplier mapping",
          "Implementation status": "Planned",
          "Control owner": "Supplier Manager",
          "Evidence status": "Partial",
          "Evidence reference": "SINV-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Subprocessor chain to be mapped. STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.5.22",
          "Control name": "Monitoring, review and change management of supplier services",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for supplier performance and changes.",
          "Risk linkage": "RISK-2026-018",
          "Treatment linkage": "Supplier review",
          "Implementation status": "In progress",
          "Control owner": "Supplier Manager",
          "Evidence status": "Partial",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Service review evidence pending."
        },
        {
          "Control ID": "A.5.23",
          "Control name": "Information security for use of cloud services",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required because core services are cloud and SaaS based.",
          "Risk linkage": "RISK-2026-043; RISK-2026-018",
          "Treatment linkage": "RTP-2026-018",
          "Implementation status": "In progress",
          "Control owner": "Cloud Service Owner",
          "Evidence status": "Partial",
          "Evidence reference": "CLOUD-CTRL-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-15",
          "Decision status": "Approved",
          "Notes": "Shared responsibility matrix pending."
        },
        {
          "Control ID": "A.5.24",
          "Control name": "Information security incident management planning and preparation",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for incident readiness.",
          "Risk linkage": "IRRT-2026-Q3",
          "Treatment linkage": "IRP-2026",
          "Implementation status": "Implemented",
          "Control owner": "Incident Manager",
          "Evidence status": "Complete",
          "Evidence reference": "IRP-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-25",
          "Decision status": "Approved",
          "Notes": "Runbooks linked."
        },
        {
          "Control ID": "A.5.25",
          "Control name": "Assessment and decision on information security events",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for event triage.",
          "Risk linkage": "IRRT-2026-Q3",
          "Treatment linkage": "Incident triage",
          "Implementation status": "Implemented",
          "Control owner": "Incident Manager",
          "Evidence status": "Partial",
          "Evidence reference": "SIR-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-25",
          "Decision status": "Approved",
          "Notes": "Event decision sample pending."
        },
        {
          "Control ID": "A.5.26",
          "Control name": "Response to information security incidents",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for incident handling.",
          "Risk linkage": "IRRT-2026-Q3",
          "Treatment linkage": "IR-RB-2026",
          "Implementation status": "Implemented",
          "Control owner": "Incident Manager",
          "Evidence status": "Partial",
          "Evidence reference": "IR-RB-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-25",
          "Decision status": "Approved",
          "Notes": "Tabletop evidence pending."
        },
        {
          "Control ID": "A.5.27",
          "Control name": "Learning from information security incidents",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for improvement after incidents.",
          "Risk linkage": "SIR-2026-Q3",
          "Treatment linkage": "CIL-2026-Q3",
          "Implementation status": "Planned",
          "Control owner": "Incident Manager",
          "Evidence status": "Partial",
          "Evidence reference": "CIL-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-25",
          "Decision status": "Approved",
          "Notes": "Lessons learned workflow planned. STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.5.28",
          "Control name": "Collection of evidence",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for audit and incident evidence.",
          "Risk linkage": "RISK-2026-021",
          "Treatment linkage": "ELAI-2026-Q3",
          "Implementation status": "Implemented",
          "Control owner": "ISMS Manager",
          "Evidence status": "Complete",
          "Evidence reference": "ELAI-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-28",
          "Decision status": "Approved",
          "Notes": "Evidence log maintained."
        },
        {
          "Control ID": "A.5.29",
          "Control name": "Information security during disruption",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for continuity of critical services.",
          "Risk linkage": "RISK-2026-045; RISK-2026-018",
          "Treatment linkage": "BCP-CUSTPORTAL-2026",
          "Implementation status": "Implemented",
          "Control owner": "Business Continuity Manager",
          "Evidence status": "Partial",
          "Evidence reference": "BCP-CUSTPORTAL-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Continuity test planned."
        },
        {
          "Control ID": "A.5.30",
          "Control name": "ICT readiness for business continuity",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for ICT continuity readiness.",
          "Risk linkage": "RISK-2026-045; RISK-2026-018",
          "Treatment linkage": "DRP-CUSTPORTAL-001",
          "Implementation status": "In progress",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "DRP-CUSTPORTAL-001",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-31",
          "Decision status": "Approved",
          "Notes": "Restore test pending."
        },
        {
          "Control ID": "A.5.31",
          "Control name": "Legal, statutory, regulatory and contractual requirements",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for legal and contractual obligations.",
          "Risk linkage": "RISK-2026-033",
          "Treatment linkage": "LRR-2026-Q3",
          "Implementation status": "Implemented",
          "Control owner": "Compliance Manager",
          "Evidence status": "Partial",
          "Evidence reference": "LRR-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Legal register maintained."
        },
        {
          "Control ID": "A.5.32",
          "Control name": "Intellectual property rights",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for software, content and third-party licenses.",
          "Risk linkage": "REQT-7.5",
          "Treatment linkage": "IPR review",
          "Implementation status": "Planned",
          "Control owner": "Legal Counsel",
          "Evidence status": "Partial",
          "Evidence reference": "IPR-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-27",
          "Decision status": "Approved",
          "Notes": "Open-source notices pending. STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.5.33",
          "Control name": "Protection of records",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required to protect ISMS and operational records.",
          "Risk linkage": "RISK-2026-041; RISK-2026-021",
          "Treatment linkage": "RRS-2026-Q3",
          "Implementation status": "Implemented",
          "Control owner": "Document Owner",
          "Evidence status": "Complete",
          "Evidence reference": "RRS-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-28",
          "Decision status": "Approved",
          "Notes": "Retention schedule maintained."
        },
        {
          "Control ID": "A.5.34",
          "Control name": "Privacy and protection of PII",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required because HR and customer personal data are processed.",
          "Risk linkage": "RISK-2026-033",
          "Treatment linkage": "DPAR-2026-Q3",
          "Implementation status": "Implemented",
          "Control owner": "Privacy Lead",
          "Evidence status": "Partial",
          "Evidence reference": "DPAR-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "GDPR records linked."
        },
        {
          "Control ID": "A.5.35",
          "Control name": "Independent review of information security",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required to review ISMS effectiveness independently.",
          "Risk linkage": "REQT-9.2",
          "Treatment linkage": "IAP-2026",
          "Implementation status": "Implemented",
          "Control owner": "Internal Auditor",
          "Evidence status": "Complete",
          "Evidence reference": "IAP-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-25",
          "Decision status": "Approved",
          "Notes": "Internal audit programme active."
        },
        {
          "Control ID": "A.5.36",
          "Control name": "Compliance with policies, rules and standards for information security",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required to verify compliance with ISMS requirements.",
          "Risk linkage": "RR-2026-Q3",
          "Treatment linkage": "REQT-2026-Q3",
          "Implementation status": "Implemented",
          "Control owner": "ISMS Manager",
          "Evidence status": "Partial",
          "Evidence reference": "REQT-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Evidence mapping active."
        },
        {
          "Control ID": "A.5.37",
          "Control name": "Documented operating procedures",
          "Theme": "Organizational",
          "Applicability": "Applicable",
          "Applicability justification": "Required for repeatable ISMS and IT operations.",
          "Risk linkage": "REQT-8.1",
          "Treatment linkage": "DOP-2026",
          "Implementation status": "In progress",
          "Control owner": "Process Owner",
          "Evidence status": "Partial",
          "Evidence reference": "DOP-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Procedures being approved. Re-sampled after IL-005; less robust than the Stage 2 sample; evidence Partial."
        },
        {
          "Control ID": "A.6.1",
          "Control name": "Screening",
          "Theme": "People",
          "Applicability": "Applicable",
          "Applicability justification": "Required for relevant roles before employment.",
          "Risk linkage": "ONC-2026",
          "Treatment linkage": "HR onboarding",
          "Implementation status": "Implemented",
          "Control owner": "HR Manager",
          "Evidence status": "Partial",
          "Evidence reference": "HR-ONB-2026-023",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Role-based screening."
        },
        {
          "Control ID": "A.6.2",
          "Control name": "Terms and conditions of employment",
          "Theme": "People",
          "Applicability": "Applicable",
          "Applicability justification": "Required for contractual security obligations.",
          "Risk linkage": "ONC-2026",
          "Treatment linkage": "Employment contract controls",
          "Implementation status": "Implemented",
          "Control owner": "HR Manager",
          "Evidence status": "Complete",
          "Evidence reference": "HR-ONB-2026-023",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Security obligations included."
        },
        {
          "Control ID": "A.6.3",
          "Control name": "Information security awareness, education and training",
          "Theme": "People",
          "Applicability": "Applicable",
          "Applicability justification": "Required for staff and contractors.",
          "Risk linkage": "REQT-7.3",
          "Treatment linkage": "Training plan",
          "Implementation status": "Implemented",
          "Control owner": "HR Manager",
          "Evidence status": "Complete",
          "Evidence reference": "TRAIN-REC-2026-188",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Awareness evidence captured."
        },
        {
          "Control ID": "A.6.4",
          "Control name": "Disciplinary process",
          "Theme": "People",
          "Applicability": "Applicable",
          "Applicability justification": "Required for security policy violations.",
          "Risk linkage": "REQT-7.5",
          "Treatment linkage": "HR policy",
          "Implementation status": "Planned",
          "Control owner": "HR Manager",
          "Evidence status": "Partial",
          "Evidence reference": "HRP-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Escalation path to confirm. STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.6.5",
          "Control name": "Responsibilities after termination or change of employment",
          "Theme": "People",
          "Applicability": "Applicable",
          "Applicability justification": "Required for offboarding and role changes.",
          "Risk linkage": "RISK-2026-033",
          "Treatment linkage": "OFC-2026-018",
          "Implementation status": "Implemented",
          "Control owner": "HR Manager",
          "Evidence status": "Complete",
          "Evidence reference": "OFC-2026-018",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Offboarding linked."
        },
        {
          "Control ID": "A.6.6",
          "Control name": "Confidentiality or non-disclosure agreements",
          "Theme": "People",
          "Applicability": "Applicable",
          "Applicability justification": "Required for personnel, contractors and suppliers.",
          "Risk linkage": "HR-ONB-2026-023",
          "Treatment linkage": "Contract controls",
          "Implementation status": "Implemented",
          "Control owner": "Legal Counsel",
          "Evidence status": "Partial",
          "Evidence reference": "NDA-REG-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Contractor sample pending."
        },
        {
          "Control ID": "A.6.7",
          "Control name": "Remote working",
          "Theme": "People",
          "Applicability": "Applicable",
          "Applicability justification": "Required because staff work remotely.",
          "Risk linkage": "RISK-2026-031",
          "Treatment linkage": "Remote working controls",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "REMOTE-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Endpoint controls apply."
        },
        {
          "Control ID": "A.6.8",
          "Control name": "Information security event reporting",
          "Theme": "People",
          "Applicability": "Applicable",
          "Applicability justification": "Required so personnel report security events.",
          "Risk linkage": "IRRT-2026-Q3",
          "Treatment linkage": "Awareness and incident process",
          "Implementation status": "Implemented",
          "Control owner": "Incident Manager",
          "Evidence status": "Partial",
          "Evidence reference": "IRP-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-25",
          "Decision status": "Approved",
          "Notes": "Reporting drill planned."
        },
        {
          "Control ID": "A.7.1",
          "Control name": "Physical security perimeters",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant for office and equipment storage.",
          "Risk linkage": "AI-AST-006",
          "Treatment linkage": "Physical security baseline",
          "Implementation status": "Implemented",
          "Control owner": "Facilities Manager",
          "Evidence status": "Partial",
          "Evidence reference": "PHY-SEC-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-22",
          "Decision status": "Approved",
          "Notes": "Office context."
        },
        {
          "Control ID": "A.7.2",
          "Control name": "Physical entry",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant for controlled office access.",
          "Risk linkage": "AI-AST-006",
          "Treatment linkage": "Physical access process",
          "Implementation status": "Implemented",
          "Control owner": "Facilities Manager",
          "Evidence status": "Partial",
          "Evidence reference": "PHY-ACCESS-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-22",
          "Decision status": "Approved",
          "Notes": "Visitor logs reviewed."
        },
        {
          "Control ID": "A.7.3",
          "Control name": "Securing offices, rooms and facilities",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant for office workspaces and records.",
          "Risk linkage": "AI-AST-006",
          "Treatment linkage": "Office security process",
          "Implementation status": "Implemented",
          "Control owner": "Facilities Manager",
          "Evidence status": "Partial",
          "Evidence reference": "PHY-OFFICE-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-22",
          "Decision status": "Approved",
          "Notes": "Office controls documented."
        },
        {
          "Control ID": "A.7.4",
          "Control name": "Physical security monitoring",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to office and equipment monitoring.",
          "Risk linkage": "AI-AST-006",
          "Treatment linkage": "Physical monitoring process",
          "Implementation status": "In progress",
          "Control owner": "Facilities Manager",
          "Evidence status": "Partial",
          "Evidence reference": "PHY-MON-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-15",
          "Decision status": "Approved",
          "Notes": "Monitoring coverage under review."
        },
        {
          "Control ID": "A.7.5",
          "Control name": "Protecting against physical and environmental threats",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to equipment and office availability.",
          "Risk linkage": "BCP-2026",
          "Treatment linkage": "Continuity controls",
          "Implementation status": "Planned",
          "Control owner": "Facilities Manager",
          "Evidence status": "Partial",
          "Evidence reference": "BCP-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-22",
          "Decision status": "Approved",
          "Notes": "Cloud services reduce datacenter exposure. STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.7.6",
          "Control name": "Working in secure areas",
          "Theme": "Physical",
          "Applicability": "Not applicable",
          "Applicability justification": "Excluded because the ISMS scope has no dedicated secure area, laboratory, datacenter, or restricted physical processing room operated by Arcfield.",
          "Risk linkage": "Not applicable",
          "Treatment linkage": "No treatment required",
          "Implementation status": "Not applicable",
          "Control owner": "Facilities Manager",
          "Evidence status": "Not applicable",
          "Evidence reference": "SOA-A.7.6",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-22",
          "Decision status": "Approved",
          "Notes": "Reassess if secure areas are introduced. Excluded because the ISMS scope has no dedicated secure area, laboratory, datacenter, or restricted physical processing room operated by Arcfield."
        },
        {
          "Control ID": "A.7.7",
          "Control name": "Clear desk and clear screen",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant for office and remote working.",
          "Risk linkage": "RISK-2026-033",
          "Treatment linkage": "Acceptable use",
          "Implementation status": "Implemented",
          "Control owner": "HR Manager",
          "Evidence status": "Partial",
          "Evidence reference": "AUP-ACK-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Awareness reminder planned."
        },
        {
          "Control ID": "A.7.8",
          "Control name": "Equipment siting and protection",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant for endpoint and office equipment.",
          "Risk linkage": "AI-AST-006",
          "Treatment linkage": "Endpoint controls",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "AI-AST-006",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Endpoint fleet controlled."
        },
        {
          "Control ID": "A.7.9",
          "Control name": "Security of assets off-premises",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Required for laptops and remote work.",
          "Risk linkage": "AI-AST-006",
          "Treatment linkage": "MDM controls",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "MDM-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Remote device controls."
        },
        {
          "Control ID": "A.7.10",
          "Control name": "Storage media",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to endpoint media and backups.",
          "Risk linkage": "AI-AST-006",
          "Treatment linkage": "Endpoint policy",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "MDM-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Removable media restriction to evidence."
        },
        {
          "Control ID": "A.7.11",
          "Control name": "Supporting utilities",
          "Theme": "Physical",
          "Applicability": "Not applicable",
          "Applicability justification": "Excluded because Arcfield does not operate datacenter or server-room utilities in the ISMS scope; production processing relies on cloud-provider facilities covered by supplier assurance.",
          "Risk linkage": "RISK-2026-018",
          "Treatment linkage": "Supplier assurance",
          "Implementation status": "Not applicable",
          "Control owner": "Facilities Manager",
          "Evidence status": "Not applicable",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Supplier responsibility. Excluded because Arcfield does not operate datacenter or server-room utilities in the ISMS scope; production processing relies on cloud-provider facilities covered by supplier assurance."
        },
        {
          "Control ID": "A.7.12",
          "Control name": "Cabling security",
          "Theme": "Physical",
          "Applicability": "Not applicable",
          "Applicability justification": "Excluded because Arcfield does not operate managed cabling infrastructure for in-scope production systems; office network cabling is not used for hosting customer services.",
          "Risk linkage": "Not applicable",
          "Treatment linkage": "No treatment required",
          "Implementation status": "Not applicable",
          "Control owner": "Facilities Manager",
          "Evidence status": "Not applicable",
          "Evidence reference": "SOA-A.7.12",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-22",
          "Decision status": "Approved",
          "Notes": "Reassess if managed infrastructure changes. Excluded because Arcfield does not operate managed cabling infrastructure for in-scope production systems; office network cabling is not used for hosting customer services."
        },
        {
          "Control ID": "A.7.13",
          "Control name": "Equipment maintenance",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to managed endpoint fleet.",
          "Risk linkage": "AI-AST-006",
          "Treatment linkage": "Endpoint lifecycle",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "MDM-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Maintenance record sample pending."
        },
        {
          "Control ID": "A.7.14",
          "Control name": "Secure disposal or re-use of equipment",
          "Theme": "Physical",
          "Applicability": "Applicable",
          "Applicability justification": "Required for endpoint disposal and reuse.",
          "Risk linkage": "RISK-2026-033",
          "Treatment linkage": "OFC-2026-018",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "OFC-2026-018",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Wipe certificate sample pending."
        },
        {
          "Control ID": "A.8.1",
          "Control name": "User endpoint devices",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for managed laptop fleet.",
          "Risk linkage": "AI-AST-006",
          "Treatment linkage": "MDM baseline",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "MDM-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Device compliance export pending."
        },
        {
          "Control ID": "A.8.2",
          "Control name": "Privileged access rights",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for production and identity administration.",
          "Risk linkage": "RISK-2026-044; RISK-2026-031; RISK-2026-014",
          "Treatment linkage": "RTP-2026-014",
          "Implementation status": "In progress",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "ACC-REV-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-09-30",
          "Decision status": "Approved",
          "Notes": "Q3 review in progress."
        },
        {
          "Control ID": "A.8.3",
          "Control name": "Information access restriction",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for restricted repositories and production data.",
          "Risk linkage": "RISK-2026-041; RISK-2026-014",
          "Treatment linkage": "Access matrix",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "ACM-APP-CRM-001",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-29",
          "Decision status": "Approved",
          "Notes": "Access group sample pending."
        },
        {
          "Control ID": "A.8.4",
          "Control name": "Access to source code",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for source repositories.",
          "Risk linkage": "RISK-2026-027",
          "Treatment linkage": "RTP-2026-027",
          "Implementation status": "Implemented",
          "Control owner": "Engineering Lead",
          "Evidence status": "Partial",
          "Evidence reference": "SI-REPO-2026-014",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-27",
          "Decision status": "Approved",
          "Notes": "Repository access evidence pending."
        },
        {
          "Control ID": "A.8.5",
          "Control name": "Secure authentication",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for cloud, SaaS and repository access.",
          "Risk linkage": "RISK-2026-044; RISK-2026-027; RISK-2026-031",
          "Treatment linkage": "IAM controls",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Complete",
          "Evidence reference": "IAM-CTRL-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-09-30",
          "Decision status": "Approved",
          "Notes": "MFA enforced."
        },
        {
          "Control ID": "A.8.6",
          "Control name": "Capacity management",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for service availability.",
          "Risk linkage": "RISK-2026-018",
          "Treatment linkage": "Monitoring process",
          "Implementation status": "Planned",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "MON-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Capacity thresholds pending. STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.8.7",
          "Control name": "Protection against malware",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for endpoints and repositories.",
          "Risk linkage": "AI-AST-006",
          "Treatment linkage": "EDR controls",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "EDR-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Coverage report pending."
        },
        {
          "Control ID": "A.8.8",
          "Control name": "Management of technical vulnerabilities",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for software and cloud services.",
          "Risk linkage": "RISK-2026-027",
          "Treatment linkage": "Vulnerability process",
          "Implementation status": "In progress",
          "Control owner": "Security Lead",
          "Evidence status": "Partial",
          "Evidence reference": "VULN-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-31",
          "Decision status": "Approved",
          "Notes": "High vulnerability SLA sample pending."
        },
        {
          "Control ID": "A.8.9",
          "Control name": "Configuration management",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for identity, cloud, endpoint and application configuration.",
          "Risk linkage": "RISK-2026-031",
          "Treatment linkage": "Configuration baseline",
          "Implementation status": "In progress",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "CFG-BASE-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-09-30",
          "Decision status": "Approved",
          "Notes": "Baseline exception review pending. Re-sampled after IL-005; less robust than the Stage 2 sample; evidence Partial."
        },
        {
          "Control ID": "A.8.10",
          "Control name": "Information deletion",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for retention and offboarding.",
          "Risk linkage": "RISK-2026-033",
          "Treatment linkage": "RRS-HR-001",
          "Implementation status": "In progress",
          "Control owner": "Data Owner",
          "Evidence status": "Partial",
          "Evidence reference": "RRS-HR-001",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "HR deletion rule pending."
        },
        {
          "Control ID": "A.8.11",
          "Control name": "Data masking",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to test data and support access.",
          "Risk linkage": "RISK-2026-033",
          "Treatment linkage": "Data masking plan",
          "Implementation status": "Planned",
          "Control owner": "Engineering Lead",
          "Evidence status": "Missing",
          "Evidence reference": "TBD-DMASK-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-31",
          "Decision status": "Approved",
          "Notes": "Implementation planned. STALL-2026-Q3: still Planned from the 2025 improvement programme. No operating sample on this freeze (evidence Missing)."
        },
        {
          "Control ID": "A.8.12",
          "Control name": "Data leakage prevention",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to customer and HR data transfer.",
          "Risk linkage": "RISK-2026-046; RISK-2026-033",
          "Treatment linkage": "DLP scope decision",
          "Implementation status": "Planned",
          "Control owner": "Security Lead",
          "Evidence status": "Partial",
          "Evidence reference": "DLP-PLAN-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Risk-based scope pending. STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.8.13",
          "Control name": "Information backup",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for availability and evidence integrity.",
          "Risk linkage": "RISK-2026-045; RISK-2026-021",
          "Treatment linkage": "RTP-2026-021",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Complete",
          "Evidence reference": "BKP-CRM-001",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-28",
          "Decision status": "Approved",
          "Notes": "Backup evidence sampled."
        },
        {
          "Control ID": "A.8.14",
          "Control name": "Redundancy of information processing facilities",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required where supplier redundancy is relied on.",
          "Risk linkage": "RISK-2026-018",
          "Treatment linkage": "RTP-2026-018",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-15",
          "Decision status": "Approved",
          "Notes": "Supplier redundancy statement pending."
        },
        {
          "Control ID": "A.8.15",
          "Control name": "Logging",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for security monitoring and investigation.",
          "Risk linkage": "RISK-2026-044; RISK-2026-014",
          "Treatment linkage": "Logging baseline",
          "Implementation status": "Implemented",
          "Control owner": "Security Lead",
          "Evidence status": "Partial",
          "Evidence reference": "LOG-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Log retention evidence pending."
        },
        {
          "Control ID": "A.8.16",
          "Control name": "Monitoring activities",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for detecting security events.",
          "Risk linkage": "IRRT-2026-Q3",
          "Treatment linkage": "Monitoring use cases",
          "Implementation status": "In progress",
          "Control owner": "Security Lead",
          "Evidence status": "Partial",
          "Evidence reference": "MON-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-31",
          "Decision status": "Approved",
          "Notes": "Alert sample pending."
        },
        {
          "Control ID": "A.8.17",
          "Control name": "Clock synchronization",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for reliable logging and investigations.",
          "Risk linkage": "A.8.15",
          "Treatment linkage": "Configuration baseline",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "CFG-BASE-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "NTP baseline evidence pending."
        },
        {
          "Control ID": "A.8.18",
          "Control name": "Use of privileged utility programs",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to administrative tooling.",
          "Risk linkage": "RISK-2026-014",
          "Treatment linkage": "RTP-2026-014",
          "Implementation status": "In progress",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "ACC-REV-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-09-30",
          "Decision status": "Approved",
          "Notes": "Privileged utility access review pending."
        },
        {
          "Control ID": "A.8.19",
          "Control name": "Installation of software on operational systems",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for production and endpoint change control.",
          "Risk linkage": "RISK-2026-027",
          "Treatment linkage": "CMP-2026-Q3",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "CMP-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-27",
          "Decision status": "Approved",
          "Notes": "Deployment approval sample pending."
        },
        {
          "Control ID": "A.8.20",
          "Control name": "Networks security",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for cloud and office connectivity.",
          "Risk linkage": "RISK-2026-018",
          "Treatment linkage": "Network Security Policy",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "NSP-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-29",
          "Decision status": "Approved",
          "Notes": "Network diagram update pending."
        },
        {
          "Control ID": "A.8.21",
          "Control name": "Security of network services",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to supplier and cloud network services.",
          "Risk linkage": "RISK-2026-018",
          "Treatment linkage": "Supplier assurance",
          "Implementation status": "Implemented",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "SINV-CLOUDHOST-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-15",
          "Decision status": "Approved",
          "Notes": "Provider evidence pending."
        },
        {
          "Control ID": "A.8.22",
          "Control name": "Segregation of networks",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for production and management separation.",
          "Risk linkage": "RISK-2026-014",
          "Treatment linkage": "Cloud segmentation",
          "Implementation status": "In progress",
          "Control owner": "IT Operations",
          "Evidence status": "Partial",
          "Evidence reference": "NET-SEG-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-31",
          "Decision status": "Approved",
          "Notes": "Segmentation evidence pending."
        },
        {
          "Control ID": "A.8.23",
          "Control name": "Web filtering",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Relevant to endpoint protection and acceptable use.",
          "Risk linkage": "AUP-ACK-2026-Q3",
          "Treatment linkage": "Endpoint protection plan",
          "Implementation status": "Planned",
          "Control owner": "IT Operations",
          "Evidence status": "Missing",
          "Evidence reference": "TBD-WEBFILTER-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-20",
          "Decision status": "Approved",
          "Notes": "Scope decision pending. STALL-2026-Q3: still Planned from the 2025 improvement programme. No operating sample on this freeze (evidence Missing)."
        },
        {
          "Control ID": "A.8.24",
          "Control name": "Use of cryptography",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for confidentiality and integrity.",
          "Risk linkage": "RISK-2026-033",
          "Treatment linkage": "Cryptography policy",
          "Implementation status": "Implemented",
          "Control owner": "Security Lead",
          "Evidence status": "Complete",
          "Evidence reference": "CKMP-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-27",
          "Decision status": "Approved",
          "Notes": "Cryptography policy maintained."
        },
        {
          "Control ID": "A.8.25",
          "Control name": "Secure development life cycle",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for customer portal software development.",
          "Risk linkage": "RISK-2026-042; RISK-2026-027",
          "Treatment linkage": "SSDLC-REL-2026-014",
          "Implementation status": "Implemented",
          "Control owner": "Engineering Lead",
          "Evidence status": "Partial",
          "Evidence reference": "SSDLC-REL-2026-014",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-27",
          "Decision status": "Approved",
          "Notes": "Release gate evidence pending."
        },
        {
          "Control ID": "A.8.26",
          "Control name": "Application security requirements",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for customer portal requirements.",
          "Risk linkage": "RISK-2026-027",
          "Treatment linkage": "Application security requirements",
          "Implementation status": "In progress",
          "Control owner": "Product Owner",
          "Evidence status": "Partial",
          "Evidence reference": "APPSEC-REQ-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-27",
          "Decision status": "Approved",
          "Notes": "Traceability update pending."
        },
        {
          "Control ID": "A.8.27",
          "Control name": "Secure system architecture and engineering principles",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for architecture of in-scope systems.",
          "Risk linkage": "RISK-2026-027",
          "Treatment linkage": "Architecture security principles",
          "Implementation status": "Planned",
          "Control owner": "Engineering Lead",
          "Evidence status": "Partial",
          "Evidence reference": "ARCH-SEC-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-27",
          "Decision status": "Approved",
          "Notes": "ADR evidence pending. STALL-2026-Q3: still Planned from the 2025 improvement programme."
        },
        {
          "Control ID": "A.8.28",
          "Control name": "Secure coding",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for developed software.",
          "Risk linkage": "RISK-2026-042; RISK-2026-027",
          "Treatment linkage": "RTP-2026-027",
          "Implementation status": "Implemented",
          "Control owner": "Engineering Lead",
          "Evidence status": "Partial",
          "Evidence reference": "SSDLC-REL-2026-014",
          "Last review date": "2026-09-11",
          "Next review date": "2026-09-20",
          "Decision status": "Approved",
          "Notes": "Secret scanning coverage pending."
        },
        {
          "Control ID": "A.8.29",
          "Control name": "Security testing in development and acceptance",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required before software release.",
          "Risk linkage": "RISK-2026-027",
          "Treatment linkage": "Security testing",
          "Implementation status": "In progress",
          "Control owner": "Engineering Lead",
          "Evidence status": "Partial",
          "Evidence reference": "TEST-SEC-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-27",
          "Decision status": "Approved",
          "Notes": "DAST/SAST sample pending."
        },
        {
          "Control ID": "A.8.30",
          "Control name": "Outsourced development",
          "Theme": "Technological",
          "Applicability": "Not applicable",
          "Applicability justification": "Excluded because Arcfield does not outsource software development within the current ISMS scope; all in-scope development is performed by internal engineering staff.",
          "Risk linkage": "Not applicable",
          "Treatment linkage": "No treatment required",
          "Implementation status": "Not applicable",
          "Control owner": "Engineering Lead",
          "Evidence status": "Not applicable",
          "Evidence reference": "SOA-A.8.30",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-27",
          "Decision status": "Approved",
          "Notes": "Reassess if outsourced development starts. Excluded because Arcfield does not outsource software development within the current ISMS scope; all in-scope development is performed by internal engineering staff."
        },
        {
          "Control ID": "A.8.31",
          "Control name": "Separation of development, test and production environments",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for safe software delivery.",
          "Risk linkage": "RISK-2026-027",
          "Treatment linkage": "Environment separation",
          "Implementation status": "Implemented",
          "Control owner": "Engineering Lead",
          "Evidence status": "Partial",
          "Evidence reference": "ENV-SEP-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-27",
          "Decision status": "Approved",
          "Notes": "Access export pending."
        },
        {
          "Control ID": "A.8.32",
          "Control name": "Change management",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required for changes to systems and services.",
          "Risk linkage": "RISK-2026-042; RISK-2026-027",
          "Treatment linkage": "CMP-2026-Q3",
          "Implementation status": "Implemented",
          "Control owner": "Change Manager",
          "Evidence status": "Partial",
          "Evidence reference": "CMP-2026-Q3",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-27",
          "Decision status": "Approved",
          "Notes": "Emergency change sample pending. Re-sampled after IL-005; less robust than the Stage 2 sample; evidence Partial."
        },
        {
          "Control ID": "A.8.33",
          "Control name": "Test information",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required to protect production data in testing.",
          "Risk linkage": "RISK-2026-033",
          "Treatment linkage": "Test data controls",
          "Implementation status": "Planned",
          "Control owner": "Engineering Lead",
          "Evidence status": "Missing",
          "Evidence reference": "TBD-TESTDATA-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-10-31",
          "Decision status": "Approved",
          "Notes": "Anonymization rule pending. STALL-2026-Q3: still Planned from the 2025 improvement programme. No operating sample on this freeze (evidence Missing)."
        },
        {
          "Control ID": "A.8.34",
          "Control name": "Protection of information systems during audit testing",
          "Theme": "Technological",
          "Applicability": "Applicable",
          "Applicability justification": "Required to protect systems during internal and external audit testing.",
          "Risk linkage": "REQT-9.2",
          "Treatment linkage": "Internal audit plan",
          "Implementation status": "Implemented",
          "Control owner": "Internal Auditor",
          "Evidence status": "Partial",
          "Evidence reference": "IAP-2026",
          "Last review date": "2026-09-11",
          "Next review date": "2026-11-25",
          "Decision status": "Approved",
          "Notes": "Audit test authorization sample pending."
        }
      ],
      "text": "The following register renders the complete SoA configuration from the JSON Example. It contains all 93 Annex A controls. Exclusions are retained as rows with explicit justification.",
      "contentType": "register_table"
    },
    {
      "id": "coverage_decision",
      "title": "Coverage decision",
      "values": {
        "Coverage result": "Complete with justified exclusions",
        "Required controls": 93,
        "Current controls": 93,
        "Missing controls": 0,
        "Excluded controls": "A.7.6, A.7.11, A.7.12, A.8.30",
        "Reviewed by": "ISMS Manager",
        "Decision date": "2026-09-11",
        "Evidence reference": "SOA-COMPLETE-2026-Q3"
      },
      "rows": [
        {
          "Field": "Coverage result",
          "Value": "Complete with justified exclusions",
          "Evidence reference": "SOA-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Required controls",
          "Value": "93",
          "Evidence reference": "SOA-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Current controls",
          "Value": "93",
          "Evidence reference": "SOA-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Missing controls",
          "Value": "0",
          "Evidence reference": "SOA-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Excluded controls",
          "Value": "A.7.6, A.7.11, A.7.12, A.8.30",
          "Evidence reference": "SOA-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Reviewed by",
          "Value": "ISMS Manager",
          "Evidence reference": "SOA-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Decision date",
          "Value": "2026-09-11",
          "Evidence reference": "SOA-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        },
        {
          "Field": "Evidence reference",
          "Value": "SOA-COMPLETE-2026-Q3",
          "Evidence reference": "SOA-COMPLETE-2026-Q3",
          "Evidence status": "Complete"
        }
      ],
      "contentType": "decision_table"
    },
    {
      "id": "evidence_and_records",
      "title": "Evidence and records",
      "groups": [
        {
          "text": "Related records live in the companion documents named below. This file cites them by their approved version. It does not copy their content. The Owner named on the cover is accountable for those live records."
        },
        {
          "items": [
            "[Risk Register](RR_Risk_Register.xlsx) — Live Risk IDs in Risk linkage.",
            "[Risk Treatment Plan](RTP_Risk_Treatment_Plan.xlsx) — Treatment linkage for applicable controls.",
            "[Mandatory Documents and Records Register](MDR_Mandatory_Documents_and_Records_Register.xlsx) — Documented information that holds the operating sample."
          ],
          "ordered": true,
          "relationView": "evidence"
        }
      ],
      "contentType": "evidence_table"
    },
    {
      "id": "external_references",
      "title": "References",
      "groups": [
        {
          "text": "Cite these sources from workshops and audits. This list names ISO clauses, book chapters and companion artifacts used by this file."
        },
        {
          "rows": [
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "ISO",
              "Reference": "ISO/IEC 27001:2022 6.1",
              "How this document uses it": "Normative source this artifact implements or cites.",
              "href": "https://www.iso.org/standard/82875.html"
            },
            {
              "Kind": "Book",
              "Reference": "Building the ISMS, Annex A Controls",
              "How this document uses it": "Primary operating chapter for this companion artifact.",
              "href": "https://www.amazon.com/dp/9789908983448"
            },
            {
              "Kind": "Artifact",
              "Reference": "RTP Risk Treatment Plan (Implementation & Certification, Risk Assessment & Risk Treatment Process)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "AI Asset Inventory (Implementation & Certification, Asset Management & Information Classification)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/s?k=ISO+27001+for+Software+Companies+Implementation+and+Certification"
            },
            {
              "Kind": "Artifact",
              "Reference": "REQT ISO 27001 Clauses 4-10 Requirements Tracker (Dual Compliance, ISO 27001 & NIS2)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983479"
            },
            {
              "Kind": "Artifact",
              "Reference": "ISO Information Security Objectives (Building the ISMS, Information Security Policies & Risk Management)",
              "How this document uses it": "Interface record. Cite this Document Control version; do not copy this file into that record.",
              "href": "https://www.amazon.com/dp/9789908983448"
            }
          ]
        }
      ],
      "contentType": "reference_table"
    }
  ],
  "enrichment": {
    "source": "Example.json",
    "method": "curated-json",
    "note": "Completes Example JSON with renderer-native sections and generalized groups; no mdSource helper fields."
  },
  "snapshotRef": {
    "snapshotId": "arcfield.platform.surv.2026-09-11",
    "schemaVersion": "evidenceSnapshot.v1"
  },
  "scenarioRef": {
    "githubIssue": 64,
    "crId": "CR-TYPE-ARCFIELD-001",
    "family": "Coverage",
    "role": "Control coverage of the certified SoA"
  }
}
