ISO 27001 compliance software that keeps the ISMS alive between audits
ISO 27001 compliance software helps you build, run and certify an Information Security Management System: it holds the Statement of Applicability, maps the 93 Annex A controls to your evidence, drives the risk treatment plan, and schedules the internal audits and management reviews a certification body will sample. Complianceofficer treats the ISMS as something that has to stay alive between audits, not a binder assembled the month before Stage 2, and it watches the standards and guidance that keep redefining what your auditor expects to see.
Scan your ISO 27001 obligations now
Pick your industry and ISO 27001 below. The scan returns the obligation register with the last 12 months of movement, sources linked. No signup, nothing stored.
§ Live · Compliance scan
No signup. Nothing you pick is stored.
Sample register · fintech, US · what a scan returns
- § 01 Written AML program with a named officer
- § 02 KYC and customer due diligence
- § 03 Sanctions screening lists Changed
- § 04 PCI DSS v4.0 validation
The ISO 27001 register: the management system, not just the controls
The mistake most teams make is treating ISO 27001 as Annex A and nothing else. Annex A is the control catalogue. The certificate is awarded against clauses 4 to 10, the management system itself, and that is where audits are failed.
- § 01 Scope and context of the ISMS Clause 4
- § 02 Leadership, policy, roles Clause 5
- § 03 Risk assessment and treatment plan Clause 6
- § 04 Statement of Applicability Clause 6.1.3
- § 05 Competence, awareness, documented information Clause 7
- § 06 Internal audit programme Clause 9.2
- § 07 Management review Clause 9.3
- § 08 Nonconformity and corrective action Clause 10
- § 09 Annex A applicability 93 controls, 4 themes
- § 10 Surveillance audit evidence Years 1 and 2
Each line maps to the documents and records you already keep. The lines that flag are the ones auditors raise nonconformities against most often, because they are the ones that go stale quietly: a risk treatment plan nobody revisited, an internal audit that never happened, a management review with no minutes. The loop that keeps them current is on how it works.
93 controls in four themes
ISO/IEC 27001:2022 restructured Annex A from the 114 controls and 14 domains of the 2013 version into 93 controls across four themes. The transition period for existing certificates closed on 31 October 2025, so any certificate issued or maintained today is against the 2022 revision. If a vendor's material still counts 114 controls, it has not been updated in three years.
| Theme | Controls | What it covers |
|---|---|---|
| Organizational | 37 | Policies, roles, supplier relationships, incident management, continuity |
| People | 8 | Screening, terms of employment, awareness training, disciplinary process |
| Physical | 14 | Secure areas, equipment, clear desk, media handling, facilities |
| Technological | 34 | Access control, cryptography, logging, secure development, threat intelligence |
You are not required to implement all 93. You are required to justify, in the Statement of Applicability, why each control is included or excluded, and to back the included ones with evidence. That justification is the document an auditor opens first.
ISO 27001 compliance software questions, answered
Is ISO 27001 certification mandatory?
No. ISO 27001 is a voluntary international standard, not a law, and no regulator will fine you for lacking it. It becomes mandatory commercially rather than legally: enterprise buyers, and most buyers outside the US, put it in the contract. Companies certify because deals stall without it.
How long does ISO 27001 certification take?
Usually 6 to 10 months from starting preparation to holding the certificate. The gate is not paperwork, it is elapsed time: the ISMS has to run long enough to generate real records, including a completed risk assessment, at least one internal audit and one management review, before a certification body will take you through Stage 1 and Stage 2.
What is a Statement of Applicability?
The Statement of Applicability, required by clause 6.1.3, lists every Annex A control, records whether you apply it, and justifies the decision either way. It ties the control set back to your risk assessment. It is the single most scrutinized document in the audit, and the fastest way to fail Stage 1 is to have one that does not match what you actually do.
Should I get ISO 27001 or SOC 2?
If your customers are mostly US companies, start with SOC 2, because that is the report a US procurement team knows how to read. If you sell into Europe, the UK, or enterprise accounts globally, ISO 27001 is the credential that travels. The control sets overlap heavily, so the second one costs far less than the first. We work through the decision in ISO 27001 vs SOC 2, and our SOC 2 compliance software page covers the other side.
Does ISO 27001 cover my suppliers?
Yes, and it is a common source of nonconformities. Annex A's organizational theme requires you to manage information security in supplier relationships and in the ICT supply chain, which means a maintained supplier register, security requirements in contracts, and evidence you monitor them. That is the job of vendor risk management software.
Last updated July 2026. General regulatory information, not legal advice.
Run the compliance scanRelated registers
- Continuous Compliance Monitoring
- Compliance Monitoring Software
- Compliance Software Pricing
- Enterprise Compliance Software for CCOs and CISOs
- GRC Software Without the Six-Figure Suite
- GDPR Compliance Software That Tracks the Regulators
- Compliance Automation Software, AI-First
- AML Transaction Monitoring Plus Regulatory Watch
- SOC 2 Compliance Software Beyond Audit Readiness
- Policy Management Software Tied to the Regulation
- Regulatory Change Management Software, Continuous
- HIPAA Compliance Software with Security Risk Analysis
- Vendor Risk Management Software for Third Party Risk
- PCI Compliance Software Tied to PCI DSS 4.0.1
- Audit Management Software for Continuous Readiness
- SOX Compliance Software for SOX 404 Controls
- Best Compliance Software in 2026, Compared
- Vanta Alternative for Regulatory Change Monitoring
- Drata Alternative Focused on Regulatory Change
- Secureframe Alternative for Regulatory Change
- Sprinto Alternative for Regulatory Change
§ 99 · Final entry
Get on the early-access list
Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.