The international security standard, run from the same control set as your SOC 2. Your AI vCISO handles the ISMS documentation, the Annex A controls, and the evidence.
ISO 27001 is the leading international standard for information security management. Where SOC 2 results in an attestation report, ISO 27001 results in a certificate issued by an accredited certification body after a formal audit. Outside North America, and increasingly inside it, this certificate is what enterprise buyers ask for.
The standard has two parts. Clauses 4 through 10 define the management system itself: context, leadership, planning, support, operation, performance evaluation, and improvement. Annex A is the control catalog. The 2022 revision reorganized it into 93 controls across four themes: organizational, people, physical, and technological.
Certification runs on a three year cycle. An initial two stage audit earns the certificate, followed by annual surveillance audits and a recertification at the end of the cycle. The certification body checks both that your management system works and that the Annex A controls you declared applicable are operating.
European and global enterprises ask for the certificate by name. It is often a hard requirement in procurement, not a nice to have.
Most of the control work overlaps. With cross mapping, the marginal effort to add ISO 27001 drops dramatically.
Finance, healthcare, and government adjacent buyers treat the certificate as the baseline for vendor trust.
ISMS documentation, Annex A controls, and evidence, all from one program.
Define what the management system covers. Your onboarding answers seed the context, scope, and risk picture the standard requires.
Work through risks and decide which Annex A controls apply. The platform tracks applicability and justification per control.
Policies, tasks, and evidence flow through the same control set as SOC 2, so work you did there counts here automatically.
Walk into the stage 1 and stage 2 audits organized, then keep the program alive for surveillance audits without a scramble.
The 2022 revision, organized the way the standard organizes it.
37 controls for policies, roles, suppliers, and incidents
8 controls for screening, training, and offboarding
14 controls for facilities, equipment, and media
34 controls for access, crypto, logging, and development
Context, leadership, and planning
Resources, awareness, and execution
Monitoring, internal audit, management review
Nonconformity and continual improvement
Annex A controls, cross mapped
Implement once, satisfy both. The controls behind your ISO 27001 certificate are the same ones behind your SOC 2 report.
Quick answers about the product, frameworks, and getting started.
Did not find what you were looking for? Talk to us.
Run the gap analysis, get your roadmap, and know your real timeline before you spend a dollar.