Certification

ISO 27001

ISO 27001:2022 is the international standard for an information security management system. Certification tells customers, regulators and procurement teams that your security is a governed system rather than a set of good intentions. Complyanz gives you the whole system: the controls, the risk register, the Statement of Applicability and the documents.

What you get

The full ISO 27001 library, pre-loaded

93Annex A controls, each with guidance and applicability
23main-body clauses covering the mandatory requirements
266pre-written risk scenarios ready to apply to your assets
36audit-ready documents for a standalone ISMS
In the platform

How an ISO 27001 program runs

Step 1

Context and scope

Define the organization, the interested parties and the boundary of the ISMS.

Step 2

Assets and risk

Inventory the assets in scope with their CIA values, then build and treat the risk register.

Step 3

Controls and SoA

Decide applicability across all 93 Annex A controls, record justifications and generate the Statement of Applicability.

Step 4

Audit and review

Run the internal audit and management review, close nonconformities, and go into the certification audit with the records assembled.

Going further

ISO 27001 is the foundation the others build on

Once the ISMS exists, privacy and AI management extend it rather than duplicating it. Adding ISO 27701 moves your library from 36 to 38 integrated documents; adding ISO 42001 takes it to 40; both together, 42. The overlapping requirements stay in one place.

Questions

ISO 27001 FAQ

What is the Statement of Applicability?

The SoA records, for all 93 Annex A controls, whether each one applies to your organization and why. It is typically the first document a certification auditor opens. Complyanz walks you through every control and generates it.

Do you cover the 2022 version?

Yes. The control set is ISO 27001:2022 — the 93 Annex A controls in their four themes, plus the 23 main-body clauses.

Do we need an external auditor?

Yes. Certification is issued by an accredited certification body after a Stage 1 and Stage 2 audit. Complyanz prepares the management system and the evidence; it does not and cannot issue the certificate.

Can we import a risk register we already have?

You can build the register from the 266 pre-written scenarios, add your own, or both. Risks link to the assets they affect and the controls that treat them.

Build your ISO 27001 ISMS

Create an organization and the controls, risk library and documents are ready to work with.