Skip to content
complianceofficer

ISO 27001 software that keeps the ISMS, the Annex A controls and the audit evidence alive between audits

ISO 27001 compliance software helps you build, run and certify an Information Security Management System: it holds the Statement of Applicability, maps the 93 Annex A controls to your evidence, drives the risk treatment plan, and schedules the internal audits and management reviews a certification body will sample. Complianceofficer treats the ISMS as something that has to stay alive between audits, not a binder assembled the month before Stage 2, and it watches the standards and guidance that keep redefining what your auditor expects to see.

Scan your ISO 27001 obligations now

Pick your industry and ISO 27001 below. The scan returns the obligation register with the last 12 months of movement, sources linked. No signup, nothing stored.

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation

The ISO 27001 register: the management system, not just the controls

The mistake most teams make is treating ISO 27001 as Annex A and nothing else. Annex A is the control catalogue. The certificate is awarded against clauses 4 to 10, the management system itself, and that is where audits are failed.

  • § 01 Scope and context of the ISMS Clause 4
  • § 02 Leadership, policy, roles Clause 5
  • § 03 Risk assessment and treatment plan Clause 6
  • § 04 Statement of Applicability Clause 6.1.3
  • § 05 Competence, awareness, documented information Clause 7
  • § 06 Internal audit programme Clause 9.2
  • § 07 Management review Clause 9.3
  • § 08 Nonconformity and corrective action Clause 10
  • § 09 Annex A applicability 93 controls, 4 themes
  • § 10 Surveillance audit evidence Years 1 and 2

Each line maps to the documents and records you already keep. The lines that flag are the ones auditors raise nonconformities against most often, because they are the ones that go stale quietly: a risk treatment plan nobody revisited, an internal audit that never happened, a management review with no minutes. The loop that keeps them current is on how it works.

§ 11 Annex A, 2022 revision

93 controls in four themes

ISO/IEC 27001:2022 restructured Annex A from the 114 controls and 14 domains of the 2013 version into 93 controls across four themes. The transition period for existing certificates closed on 31 October 2025, so any certificate issued or maintained today is against the 2022 revision. If a vendor's material still counts 114 controls, it has not been updated in three years.

Theme Controls What it covers
Organizational 37 Policies, roles, supplier relationships, incident management, continuity
People 8 Screening, terms of employment, awareness training, disciplinary process
Physical 14 Secure areas, equipment, clear desk, media handling, facilities
Technological 34 Access control, cryptography, logging, secure development, threat intelligence

You are not required to implement all 93. You are required to justify, in the Statement of Applicability, why each control is included or excluded, and to back the included ones with evidence. That justification is the document an auditor opens first.

§ 123 The certification cycle

How ISO 27001 certification actually runs, over three years

ISO 27001 is not a one-off audit. Certification runs on a three-year cycle, and the cost and effort are spread across it unevenly. Budgeting for Stage 2 alone is how a program gets caught out in year two, when a surveillance auditor arrives expecting a year of records that nobody kept.

Stage When What the auditor is doing What has to exist
Stage 1 Month 0 Reviewing documentation and readiness, not testing controls Scope, ISMS policy, risk assessment method, Statement of Applicability
Stage 2 Typically 1 to 3 months later Testing that the ISMS is implemented and operating Completed risk treatment plan, at least one internal audit and one management review, control evidence
Surveillance 1 Year 1 Sampling a subset of controls plus the ISMS management processes Another internal audit cycle, another management review, closed nonconformities
Surveillance 2 Year 2 Same again, usually on a different control sample Evidence of continual improvement, not just of steady state
Recertification Year 3 Full audit of the whole ISMS again Three years of records, including the ones from the quiet year

There is no valid 2013 certificate left

ISO/IEC 27001:2022 was published on 25 October 2022. Under IAF MD 26, certified organizations had 36 months from the end of that publication month to transition, so every certificate still issued against ISO/IEC 27001:2013 expired or was withdrawn on 31 October 2025. If a supplier sends you a 2013 certificate today, it is not current, whatever date is printed on it.

That matters for vendor due diligence more than for your own program. Certificates circulate in sales packets for years after they lapse, and the version line is the fastest way to check one. Our vendor risk management software page covers how to keep supplier evidence current rather than collected once.

§ 124 ISO 27001 vs SOC 2

ISO 27001 vs SOC 2, as a buying decision

These two get compared constantly and they are not the same kind of object. ISO 27001 is a certifiable management-system standard: an accredited body audits you and issues a certificate. SOC 2 is an attestation: a licensed CPA firm reports an opinion on controls you selected against the AICPA trust services criteria. There is no such thing as SOC 2 certification, and a vendor claiming one is telling you something about their program.

ISO/IEC 27001:2022 SOC 2
What you get A certificate from an accredited certification body A report with an opinion from a CPA firm
Who asks for it Enterprise and non-US buyers, public tenders, EU procurement US buyers, especially SaaS procurement and security review
What is assessed The management system first, the 93 Annex A controls second The controls you selected against the trust services criteria
Who defines scope You, in the Statement of Applicability, with justification You, by choosing criteria and system boundary
Renewal rhythm Three-year cycle with annual surveillance Annual report covering a stated period

If your pipeline is mostly US, start with SOC 2 and add ISO 27001 when a non-US or enterprise deal demands it. If you sell into Europe or into regulated procurement, invert that order. Most companies that do both eventually run one control set mapped to both frameworks, which is where the evidence overlap pays off. Our SOC 2 compliance software page covers the attestation side, and the ISO 27001 vs SOC 2 comparison works through the decision in more detail.

§ 12 Questions buyers ask

ISO 27001 compliance software questions, answered

Is ISO 27001 certification mandatory?

No. ISO 27001 is a voluntary international standard, not a law, and no regulator will fine you for lacking it. It becomes mandatory commercially rather than legally: enterprise buyers, and most buyers outside the US, put it in the contract. Companies certify because deals stall without it.

How long does ISO 27001 certification take?

Usually 6 to 10 months from starting preparation to holding the certificate. The gate is not paperwork, it is elapsed time: the ISMS has to run long enough to generate real records, including a completed risk assessment, at least one internal audit and one management review, before a certification body will take you through Stage 1 and Stage 2.

What is a Statement of Applicability?

The Statement of Applicability, required by clause 6.1.3, lists every Annex A control, records whether you apply it, and justifies the decision either way. It ties the control set back to your risk assessment. It is the single most scrutinized document in the audit, and the fastest way to fail Stage 1 is to have one that does not match what you actually do.

Should I get ISO 27001 or SOC 2?

If your customers are mostly US companies, start with SOC 2, because that is the report a US procurement team knows how to read. If you sell into Europe, the UK, or enterprise accounts globally, ISO 27001 is the credential that travels. The control sets overlap heavily, so the second one costs far less than the first. We work through the decision in ISO 27001 vs SOC 2, and our SOC 2 compliance software page covers the other side.

Does ISO 27001 cover my suppliers?

Yes, and it is a common source of nonconformities. Annex A's organizational theme requires you to manage information security in supplier relationships and in the ICT supply chain, which means a maintained supplier register, security requirements in contracts, and evidence you monitor them. That is the job of vendor risk management software.

How long is an ISO 27001 certificate valid?

Three years, provided you pass the surveillance audits in years one and two. Miss or fail one and the certificate can be suspended or withdrawn before its printed expiry date, so that date is a ceiling rather than a guarantee. Year three is a full recertification audit of the whole ISMS, not a lighter check, and it is the point where programs that stopped running internal audits get found out.

Is ISO 27001:2013 still valid?

No. ISO/IEC 27001:2022 was published on 25 October 2022, and under IAF MD 26 certified organizations had 36 months from the end of that month to transition. Every certificate issued against ISO/IEC 27001:2013 expired or was withdrawn on 31 October 2025. A 2013 certificate in a supplier's sales packet today is not a current certification, whatever expiry date is printed on it.

Do I need ISO 27001 compliance software to get certified?

No, and plenty of first-time certifications are done on documents and a spreadsheet. Software earns its place at the second audit rather than the first, because a certificate commits you to three years of internal audits, management reviews and control evidence. What breaks manually is not the initial push, it is the quiet year in between, when nobody is watching and the records stop being made.

Last updated August 2026. General regulatory information, not legal advice.

Run the compliance scan
§ 90

Related registers

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.