Not applicable explained
When is a security requirement not applicable?
Use Not applicable only when a requirement or question genuinely does not apply, and record a reason. It is not a way to postpone unfinished work.
Explain the boundary
State why it does not apply, which systems or activities you considered, and what supports that conclusion. An assessor must be able to understand the decision without guessing.
Distinguish a gap
If something applies but is not implemented, record the gap. Use In progress when work has started and record an estimated completion date. A missing purchase, policy or evidence record is not by itself a reason for exclusion.
Revisit when circumstances change
A new contract, information type or provider can change applicability. Review excluded focus areas after updating Profile or Scope.