ISO 27001 compliance software
that evidences the 2022 controls.
What ISO/IEC 27001:2022 certification asks for, the order the work has to happen in, which parts software can carry and which it cannot, and how one control set answers ISO 27001, SOC 2 and DPDP at once.
What does ISO 27001 certification require?
ISO 27001 certification requires an information security management system meeting clauses 4 to 10 of ISO/IEC 27001:2022, a risk assessment that selects controls from the 93 in Annex A, a Statement of Applicability, and evidence the system has run, including an internal audit and management review , before an accredited certification body audits it.
The standard is ISO/IEC 27001:2022, amended in 2024 to add climate change to the context questions in clauses 4.1 and 4.2. It has two parts that teams routinely weigh the wrong way round. The clauses are the management system: short, abstract, and the thing certification is actually of. Annex A is the control catalogue: long, concrete, and the part everybody starts with.
| Part | What it covers | What it asks you to produce |
|---|---|---|
| Clause 4 Context | Interested parties, their requirements, the scope of the ISMS | A scope statement naming the entity, locations, systems and interfaces |
| Clause 5 Leadership | Top management commitment, the policy, roles | An information security policy and named responsibilities |
| Clause 6 Planning | Risk assessment, risk treatment, objectives | A risk methodology, the register, the treatment plan and the Statement of Applicability |
| Clause 7 Support | Resources, competence, awareness, documented information | Training records and controlled documents |
| Clause 8 Operation | Running the risk process and the treatment plan | Evidence the controls operate |
| Clause 9 Performance evaluation | Monitoring, internal audit (9.2), management review (9.3) | Audit reports and review minutes, with decisions |
| Clause 10 Improvement | Nonconformity, corrective action, continual improvement | A corrective action log that closes |
| Annex A | 93 controls: 37 organisational (5.x), 8 people (6.x), 14 physical (7.x), 34 technological (8.x) | Implemented controls, or a justified exclusion for each |
The 2013 edition had 114 Annex A controls in fourteen domains. The 2022 edition merged many and added eleven, including threat intelligence (5.7), cloud services (5.23), data masking (8.11) and secure coding (8.28).
Did the 2013 to 2022 transition deadline pass?
Yes. The IAF gave certified organisations 36 months from the October 2022 publication to transition, and every accredited ISO/IEC 27001:2013 certificate expired or was withdrawn on 31 October 2025. Any current accredited certificate is against the 2022 edition, and new programmes should build to it directly.
The rule comes from the International Accreditation Forum's mandatory document IAF MD 26. Two practical consequences. When you review a supplier's certificate, check the edition and the date: a 2013 certificate is no longer evidence of anything current. And if you are reusing an old control mapping, check it cites 2022 numbering: A.5.18 for access rights, not A.9.2.5.
What order do you build an ISMS in?
Build an ISMS in this order: scope, risk assessment, Statement of Applicability, controls, a period of operation, internal audit, management review, then the stage 1 and stage 2 audits. Each step consumes the one before it, so starting at the controls produces evidence for a scope and risks nobody has yet defined.
| Step | What it produces | Who owns it |
|---|---|---|
| 1. Scope | Which entity, locations, products and systems the ISMS covers, and its boundaries | Leadership, with security |
| 2. Risk assessment | A methodology with acceptance criteria, and a register of risks with owners | Security; risk owners in each function |
| 3. Statement of Applicability | All 93 Annex A controls, each included or excluded, with justification and status | Security, approved by leadership |
| 4. Controls | Policies, technical controls and processes the treatment plan calls for | Engineering, IT, HR, facilities: whoever runs the thing |
| 5. Operation | Weeks to months of the controls actually running, with records | Everyone, which is the point |
| 6. Internal audit | An objective audit of the ISMS against the standard, with findings | Someone independent of the work audited, often an external consultant at a startup |
| 7. Management review | Top management reviews performance, risks and audit results, and decides | Leadership |
| 8. Stage 1 and stage 2 | Stage 1 reviews documentation and readiness; stage 2 tests that the system operates | The accredited certification body |
After certification comes a three-year cycle with surveillance audits in the intervening years, so step 5 never really ends.
Where does ISO 27001 automation help, and where can it not?
ISO 27001 automation helps most with the technological controls and with evidence: testing controls continuously, keeping dated records, deriving risk from control state. It cannot set scope, accept risk, run your management review or make an internal audit independent. Those are decisions people must make and be seen to make.
| Area | What software can carry | What it cannot |
|---|---|---|
| Scope (4.3) | Hold the system and asset inventory the scope is drawn from | Decide the boundary, or defend it to the auditor |
| Risk assessment (6.1.2) | Hold the register; derive residual risk from whether treating controls pass | Set acceptance criteria, or accept a residual risk on behalf of its owner |
| Statement of Applicability | Keep implementation status current from control results | Write the justification for excluding a control |
| Technological controls (8.x) | Test continuously: pipeline scans for 8.25–8.29 and 8.8, device posture for 8.1, logging, access | Choose the controls the risk assessment did not ask for |
| Organisational and people (5.x, 6.x) | Versioned policies with attestations; supplier and access review records | Make training effective, or a policy appropriate to your business |
| Physical (7.x) | Store the records and due dates | Check that the door is locked |
| Internal audit (9.2) | Give the auditor dated evidence to sample without a walkthrough | Be the auditor, or make one independent |
| Management review (9.3) | Assemble the inputs the clause lists | Hold the review or take the decisions |
A tool that claims to do the right-hand column is describing a document template, not a management system.
How does one control set answer ISO 27001, SOC 2 and DPDP?
One control set answers ISO 27001, SOC 2 and DPDP because the three ask for largely the same practices in different words. An access review is ISO 27001 A.5.18, SOC 2 CC6.2 and part of the reasonable security safeguards under DPDP Section 8(5). One control, tested once, produces evidence all three can read.
The overlap is large and lopsided. A company with SOC 2 in place usually finds most of Annex A already evidenced and the management system missing: scope, risk methodology, Statement of Applicability, internal audit and management review. DPDP overlaps on security and breach handling and barely at all on notice and consent, which live in the product rather than the infrastructure. The mechanics, including how partial coverage is recorded, are on the cross-framework mapping page; the DPDP side is in the DPDP programme.
Where this runs in the platform
ISO 27001:2022 is one of the frameworks on the coverage list, enabled explicitly and per legal entity, because a certificate is issued to an entity rather than an account. It starts empty: a requirement with no control mapped reads as not modelled, and readiness is computed from control results rather than entered by hand. What that looks like against the build order:
- Risk assessment. The risk register scores inherent risk on likelihood and impact and derives residual risk from whether the treating controls are passing, so it moves when a control fails rather than at the next review
- Technological controls. The SDK and CI gate run SAST, SCA, IaC, DAST and secret scanning in your own pipeline; device posture syncs Intune, Jamf or Google Workspace for endpoint checks. How the pipeline side maps to Annex A 8.25–8.29 is in the compliance as code guide
- Policies. The compliance programme generator produces policies with versioned attestations, so a policy is shown to have been read rather than filed
- Evidence and audit. Results land in the hash-chained evidence ledger, failures included, and a scoped auditor workspace exports one entity and framework for the internal auditor or the certification body
- The next framework. The delta view shows which SOC 2 or DPDP requirements your ISO controls already satisfy before you enable them
The judgement steps in the table above stay with you. So does the certificate: the platform does not certify anyone, and our own certification is in progress rather than complete, as the trust page says.
The things people ask us
What does ISO 27001 certification actually require?
An information security management system that meets clauses 4 to 10 of ISO/IEC 27001:2022, a risk assessment and treatment that decide which Annex A controls apply, a Statement of Applicability, and evidence that the system has operated: at least one internal audit and one management review before an accredited certification body runs the stage 1 and stage 2 audits.
Are ISO 27001:2013 certificates still valid?
No. Under the IAF's transition requirements, organisations had 36 months from the October 2022 publication to move to the 2022 edition, and every accredited certificate issued against the 2013 edition expired or was withdrawn on 31 October 2025. A 2013 certificate shown to you today is not a current accredited certificate.
How many controls are in ISO 27001:2022 Annex A?
Ninety-three, in four themes: 37 organisational, 8 people, 14 physical and 34 technological. The 2013 edition had 114 in fourteen domains. Not all 93 have to be implemented: the risk assessment decides, and the Statement of Applicability records each control as included or excluded with a justification.
Can software make us ISO 27001 compliant?
No. Software can hold the risk register, test technological controls continuously, keep dated evidence and show what is failing. It cannot set your scope, accept a risk, conduct your management review or make your internal audit independent. Certification is granted by an accredited certification body after its own audit, not by any tool.
If we already have SOC 2, how much of ISO 27001 is done?
Usually most of the Annex A technological and organisational controls, because they test the same practices: access review, change management, logging, incident response, vendor management. What SOC 2 does not give you is the management system itself: defined scope, a documented risk methodology, the Statement of Applicability, internal audit and management review.
Is TryTrustable ISO 27001 certified?
Not yet. Our own certification is in progress and we say so on the trust page rather than implying otherwise. Nothing in the platform certifies anyone either: it helps you run and evidence the management system, and an accredited certification body decides whether it conforms.
See Annex A evidenced from live state.
We enable ISO 27001 for one entity, connect a repository and a cloud account, and show which controls have evidence behind them and which read as not modelled. Thirty minutes.