Skip to content
complianceofficer

ISO 27001 compliance software that keeps the ISMS alive between audits

ISO 27001 compliance software helps you build, run and certify an Information Security Management System: it holds the Statement of Applicability, maps the 93 Annex A controls to your evidence, drives the risk treatment plan, and schedules the internal audits and management reviews a certification body will sample. Complianceofficer treats the ISMS as something that has to stay alive between audits, not a binder assembled the month before Stage 2, and it watches the standards and guidance that keep redefining what your auditor expects to see.

Scan your ISO 27001 obligations now

Pick your industry and ISO 27001 below. The scan returns the obligation register with the last 12 months of movement, sources linked. No signup, nothing stored.

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation

The ISO 27001 register: the management system, not just the controls

The mistake most teams make is treating ISO 27001 as Annex A and nothing else. Annex A is the control catalogue. The certificate is awarded against clauses 4 to 10, the management system itself, and that is where audits are failed.

  • § 01 Scope and context of the ISMS Clause 4
  • § 02 Leadership, policy, roles Clause 5
  • § 03 Risk assessment and treatment plan Clause 6
  • § 04 Statement of Applicability Clause 6.1.3
  • § 05 Competence, awareness, documented information Clause 7
  • § 06 Internal audit programme Clause 9.2
  • § 07 Management review Clause 9.3
  • § 08 Nonconformity and corrective action Clause 10
  • § 09 Annex A applicability 93 controls, 4 themes
  • § 10 Surveillance audit evidence Years 1 and 2

Each line maps to the documents and records you already keep. The lines that flag are the ones auditors raise nonconformities against most often, because they are the ones that go stale quietly: a risk treatment plan nobody revisited, an internal audit that never happened, a management review with no minutes. The loop that keeps them current is on how it works.

§ 11 Annex A, 2022 revision

93 controls in four themes

ISO/IEC 27001:2022 restructured Annex A from the 114 controls and 14 domains of the 2013 version into 93 controls across four themes. The transition period for existing certificates closed on 31 October 2025, so any certificate issued or maintained today is against the 2022 revision. If a vendor's material still counts 114 controls, it has not been updated in three years.

Theme Controls What it covers
Organizational 37 Policies, roles, supplier relationships, incident management, continuity
People 8 Screening, terms of employment, awareness training, disciplinary process
Physical 14 Secure areas, equipment, clear desk, media handling, facilities
Technological 34 Access control, cryptography, logging, secure development, threat intelligence

You are not required to implement all 93. You are required to justify, in the Statement of Applicability, why each control is included or excluded, and to back the included ones with evidence. That justification is the document an auditor opens first.

§ 12 Questions buyers ask

ISO 27001 compliance software questions, answered

Is ISO 27001 certification mandatory?

No. ISO 27001 is a voluntary international standard, not a law, and no regulator will fine you for lacking it. It becomes mandatory commercially rather than legally: enterprise buyers, and most buyers outside the US, put it in the contract. Companies certify because deals stall without it.

How long does ISO 27001 certification take?

Usually 6 to 10 months from starting preparation to holding the certificate. The gate is not paperwork, it is elapsed time: the ISMS has to run long enough to generate real records, including a completed risk assessment, at least one internal audit and one management review, before a certification body will take you through Stage 1 and Stage 2.

What is a Statement of Applicability?

The Statement of Applicability, required by clause 6.1.3, lists every Annex A control, records whether you apply it, and justifies the decision either way. It ties the control set back to your risk assessment. It is the single most scrutinized document in the audit, and the fastest way to fail Stage 1 is to have one that does not match what you actually do.

Should I get ISO 27001 or SOC 2?

If your customers are mostly US companies, start with SOC 2, because that is the report a US procurement team knows how to read. If you sell into Europe, the UK, or enterprise accounts globally, ISO 27001 is the credential that travels. The control sets overlap heavily, so the second one costs far less than the first. We work through the decision in ISO 27001 vs SOC 2, and our SOC 2 compliance software page covers the other side.

Does ISO 27001 cover my suppliers?

Yes, and it is a common source of nonconformities. Annex A's organizational theme requires you to manage information security in supplier relationships and in the ICT supply chain, which means a maintained supplier register, security requirements in contracts, and evidence you monitor them. That is the job of vendor risk management software.

Last updated July 2026. General regulatory information, not legal advice.

Run the compliance scan

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.