Organizational
37 controls for policies, roles, suppliers, and incidents
ISO 27001 readiness
AvailableReuse work from SOC 2 while your AI vCISO organizes scope, risk treatment, policies, controls, evidence, and certification preparation.
Clear responsibility
The product prepares and coordinates readiness work while your team and the independent reviewer retain their required roles.
Product workflow
Each stage stays connected to the same controls, policies, evidence, owners, and remediation history.
Readiness depends on
Starting maturity, scope, response time, required remediation, independent-reviewer availability, and any required observation or operating period.
Deliverables are working program records, not an audit opinion or certification.
Related integrations
Available integrations collect supported read-only observations. They do not replace evidence review or independent testing.
ISO 27001 is a widely used international standard for information security management. Where SOC 2 results in an attestation report, ISO 27001 can result in a certificate issued by an accredited certification body after a formal audit. Buyers may request the certificate directly during procurement.
The standard has two parts. Clauses 4 through 10 define the management system itself: context, leadership, planning, support, operation, performance evaluation, and improvement. Annex A is the control catalog. The 2022 revision reorganized it into 93 controls across four themes: organizational, people, physical, and technological.
Certification runs on a three-year cycle. An initial two-stage audit earns the certificate, followed by annual surveillance audits and a recertification at the end of the cycle. The certification body checks both that your management system works and that the Annex A controls you declared applicable are operating.
The 2022 revision, organized the way the standard organizes it.
37 controls for policies, roles, suppliers, and incidents
8 controls for screening, training, and offboarding
14 controls for facilities, equipment, and media
34 controls for access, crypto, logging, and development
Context, leadership, and planning
Resources, awareness, and execution
Monitoring, internal audit, management review
Nonconformity and continual improvement
93
Annex A controls, cross mapped
Relevant implemented controls and reviewed evidence can support both frameworks while each keeps its own scope and independent review.
Quick answers about the product, frameworks, and getting started.
Timing depends on ISMS scope, starting maturity, risk treatment, remediation, internal audit and management review readiness, and certification-body availability. Existing SOC 2 work may reduce duplicated preparation when the relationships are reviewed.
Certification-body fees vary with company size, scope, locations, audit duration, and certification cycle. Platform pricing is published on the pricing page; request a current certification-body proposal for independent audit fees.
Annex A was restructured from 114 controls in 14 domains to 93 controls in 4 themes, with 11 new controls covering areas like cloud services, threat intelligence, and data leakage prevention. We support the 2022 revision natively.
Start with the framework a buyer names when the requirement is explicit. Otherwise, compare whether the immediate need is a SOC 2 report or an ISO 27001 certificate and ISMS, then preserve reusable work for the second framework. The comparison guide walks through that decision.
Did not find what you were looking for? Talk to us.
Start with the roadmap
Start with a saved readiness roadmap, then open the first control your team should complete.