.ai

ISO 27001 readiness

Available

Build your ISO 27001 ISMS without running a second compliance program.

Reuse work from SOC 2 while your AI vCISO organizes scope, risk treatment, policies, controls, evidence, and certification preparation.

Open the program view

Clear responsibility

Your AI vCISO prepares the work. Independent judgment stays independent.

The product prepares and coordinates readiness work while your team and the independent reviewer retain their required roles.

Your AI vCISO prepares

  • Organize scope, risk treatment, and the Statement of Applicability
  • Prepare policy drafts and evidence requirements
  • Show where SOC 2 work can be reused

Your team approves or performs

  • Approve scope, risk treatment, and policies
  • Operate controls and review evidence
  • Complete internal audit and management review

Independent reviewer

  • Perform the independent certification audit
  • Evaluate ISMS and control operation
  • Make the certification decision

Product workflow

Move from scope to reviewable proof.

Each stage stays connected to the same controls, policies, evidence, owners, and remediation history.

Readiness depends on

Starting maturity, scope, response time, required remediation, independent-reviewer availability, and any required observation or operating period.

  1. Define ISMS scope
  2. Assess and treat risk
  3. Prepare the Statement of Applicability
  4. Operate and review
  5. Prepare internal audit and management review
  6. Engage the certification body

What the program prepares

Deliverables are working program records, not an audit opinion or certification.

  • ISMS scope
  • Risk assessment and treatment plan
  • Statement of Applicability
  • Policy and evidence set
  • Certification preparation package

Related integrations

Available integrations collect supported read-only observations. They do not replace evidence review or independent testing.

  • Amazon Web Services
  • Google Cloud
  • Microsoft Azure
  • GitHub
  • GitLab
  • Okta
  • Microsoft Entra ID
  • Google Workspace

What is ISO 27001?

ISO 27001 is a widely used international standard for information security management. Where SOC 2 results in an attestation report, ISO 27001 can result in a certificate issued by an accredited certification body after a formal audit. Buyers may request the certificate directly during procurement.

The standard has two parts. Clauses 4 through 10 define the management system itself: context, leadership, planning, support, operation, performance evaluation, and improvement. Annex A is the control catalog. The 2022 revision reorganized it into 93 controls across four themes: organizational, people, physical, and technological.

Certification runs on a three-year cycle. An initial two-stage audit earns the certificate, followed by annual surveillance audits and a recertification at the end of the cycle. The certification body checks both that your management system works and that the Annex A controls you declared applicable are operating.

All 93 Annex A controls represented

The 2022 revision, organized the way the standard organizes it.

A.5

Organizational

37 controls for policies, roles, suppliers, and incidents

A.6

People

8 controls for screening, training, and offboarding

A.7

Physical

14 controls for facilities, equipment, and media

A.8

Technological

34 controls for access, crypto, logging, and development

Cl. 4 to 6

ISMS foundation

Context, leadership, and planning

Cl. 7 to 8

Support and operation

Resources, awareness, and execution

Cl. 9

Evaluation

Monitoring, internal audit, management review

Cl. 10

Improvement

Nonconformity and continual improvement

93

Annex A controls, cross mapped

Relevant implemented controls and reviewed evidence can support both frameworks while each keeps its own scope and independent review.

Frequently asked questions

Quick answers about the product, frameworks, and getting started.

ISO 27001 basics

How long does ISO 27001 certification take?

Timing depends on ISMS scope, starting maturity, risk treatment, remediation, internal audit and management review readiness, and certification-body availability. Existing SOC 2 work may reduce duplicated preparation when the relationships are reviewed.

What does certification cost?

Certification-body fees vary with company size, scope, locations, audit duration, and certification cycle. Platform pricing is published on the pricing page; request a current certification-body proposal for independent audit fees.

What changed in the 2022 revision?

Annex A was restructured from 114 controls in 14 domains to 93 controls in 4 themes, with 11 new controls covering areas like cloud services, threat intelligence, and data leakage prevention. We support the 2022 revision natively.

SOC 2 or ISO 27001 first?

Start with the framework a buyer names when the requirement is explicit. Otherwise, compare whether the immediate need is a SOC 2 report or an ISO 27001 certificate and ISMS, then preserve reusable work for the second framework. The comparison guide walks through that decision.

Did not find what you were looking for? Talk to us.

Start with the roadmap

Build ISO 27001 readiness inside a real security program.

Start with a saved readiness roadmap, then open the first control your team should complete.