In your template for the SOA you show the column “Control objectives” for which in my understanding S.M.A.R.T objectives shall be listed.
In your ISO 27001 foundation course video about the SOA, this column is missing.
Therefore, I would like to know if it is mandatory or not? Because I struggle to find adequate measurable objectives for all applicable controls.
ISO 27001 doesn't require you to specify objectives in the Statement of Applicability - you can use some other document for this purpose. However, we felt that listing objectives next to each control in SoA is the most practical solution.
Regarding the objectives, to make it easier, you can specify the objectives for groups of controls, very similar to what is written in Annex A of ISO 27001.