Most teams heading into a first ISO 27001 audit have the controls. What they lack is the record proving each one operated. What auditors sample for, and the four questions every record has to answer.
The SoA is the one document every stage of an ISO 27001 audit runs against. What it has to contain, how auditors test it, and why template SoAs fail.
What ISO 27001 certification actually involves for a SaaS company: the stages, the evidence, the timeline, and where teams lose months.