ISO 27001
ISO 27001:2022 is the international standard for an information security management system. Certification tells customers, regulators and procurement teams that your security is a governed system rather than a set of good intentions. Complyanz gives you the whole system: the controls, the risk register, the Statement of Applicability and the documents.
The full ISO 27001 library, pre-loaded
How an ISO 27001 program runs
Context and scope
Define the organization, the interested parties and the boundary of the ISMS.
Assets and risk
Inventory the assets in scope with their CIA values, then build and treat the risk register.
Controls and SoA
Decide applicability across all 93 Annex A controls, record justifications and generate the Statement of Applicability.
Audit and review
Run the internal audit and management review, close nonconformities, and go into the certification audit with the records assembled.
ISO 27001 is the foundation the others build on
Once the ISMS exists, privacy and AI management extend it rather than duplicating it. Adding ISO 27701 moves your library from 36 to 38 integrated documents; adding ISO 42001 takes it to 40; both together, 42. The overlapping requirements stay in one place.
ISO 27001 FAQ
What is the Statement of Applicability?
The SoA records, for all 93 Annex A controls, whether each one applies to your organization and why. It is typically the first document a certification auditor opens. Complyanz walks you through every control and generates it.
Do you cover the 2022 version?
Yes. The control set is ISO 27001:2022 — the 93 Annex A controls in their four themes, plus the 23 main-body clauses.
Do we need an external auditor?
Yes. Certification is issued by an accredited certification body after a Stage 1 and Stage 2 audit. Complyanz prepares the management system and the evidence; it does not and cannot issue the certificate.
Can we import a risk register we already have?
You can build the register from the 266 pre-written scenarios, add your own, or both. Risks link to the assets they affect and the controls that treat them.
Build your ISO 27001 ISMS
Create an organization and the controls, risk library and documents are ready to work with.