01
Gap analysis with existing context
Map the asset inventory, policies and existing controls to your ISO 27001:2022 scope. KaitoSec prepares open items with owner and priority for professional review.
ISO 27001
Run Annex A, risks, owners and evidence in the same working state as BCMS, DSMS and AIMS. The ISMS becomes a defensible foundation for further obligations.
One control, several standards
KaitoSec keeps approved controls and evidence in one ISMS software workspace and maps them to NIS2, DORA and other frameworks only where their substance overlaps. Framework-specific wording and decisions remain visible.
One control
Supplier & third-party due diligence
From control to policy
ISO 27001:2022 requires a managed ISMS: scope, risk-based decisions, objectives, controlled information, reviews and continual improvement. Annex A supports treatment; it does not replace the management system.
One control
Supplier & third-party due diligence
Management systems
Policies and procedures
Applicability, justification, implementation status and evidence stay together for all 93 Annex A controls. Changes update the working SoA instead of starting another spreadsheet round. Our guide to ISO 27001 certification costs breaks down what a project like this typically costs.
01
Map the asset inventory, policies and existing controls to your ISO 27001:2022 scope. KaitoSec prepares open items with owner and priority for professional review.
02
Your Statement of Applicability brings applicability, justification, implementation and evidence together. Changes are versioned and your certification body can receive controlled read access to the approved state when required.
03
Start with a structured policy template, adapt it to your organisation and connect the approved version to controls, versions and acknowledgements.
Assess risk in context, document treatment and residual risk, assign accountability and set the next review. The ISO 27005 view remains connected to the controls selected for treatment.
01
Every Annex A control has a dedicated workspace where you assign owners, attach evidence, and track implementation status. Overall progress toward certification readiness is visible to the whole team.
02
Link risks directly to controls and define the treatment: accept, mitigate, transfer, or avoid. KaitoSec requires documented decisions and reminds owners when risk reviews are overdue.
03
Give your certification body scoped read access to an approved state of your ISMS evidence. Context, version and accountability stay with the evidence.
For ISO 27001, you need a tool that keeps context, risk assessment, the Statement of Applicability, Annex A controls and evidence together. KaitoSec provides exactly that as ISMS software, without a parallel Excel environment. Our ISO 27001 checklist breaks the whole certification path into concrete steps.
The Statement of Applicability (SoA) lists all 93 controls in ISO 27001:2022 Annex A and explains whether and how each is implemented. In KaitoSec, it is generated automatically from risk management and control status, so it stays current and audit-ready.
ISO 27001 certification typically takes 6 to 12 months, depending on maturity and scope. KaitoSec measurably shortens the ISMS build; the timetable to the audit still depends on the certification body. For SMEs without a security team, see ISMS for SMEs.
ISO 27001 and NIS2 can share the same ISMS. The measures in Section 30 BSIG overlap substantially with Annex A. Through compliance mapping, one implementation counts for NIS2, DORA and ISO 27001 at the same time; in our data, existing controls cover around 78% of ISO requirements.
ISO 27001 is internationally recognised and risk-based; IT-Grundschutz is more detailed and is often required in public authorities and critical infrastructure. The two can also be combined as ISO 27001 based on IT-Grundschutz. Compare the approaches under BSI IT-Grundschutz.
ISO/IEC 27001 is the international standard for an information security management system (ISMS). It defines how an organisation identifies, treats and evidences risks to the confidentiality, integrity and availability of its information. The 2022 edition replaces the 2013 one: Annex A was condensed to 93 controls in four themes, and eleven controls such as threat intelligence and cloud security were added. Our article ISO 27001:2022 explained simply covers the basics.
An accredited certification body audits in two stages: stage 1 checks documentation and readiness, stage 2 checks that the ISMS works in day-to-day operation. The certificate is valid for three years, with annual surveillance audits and a recertification audit at the end of the cycle. Before the first audit the standard expects an internal audit and a management review to have taken place.
Versioned policies, approved evidence and a scoped auditor view keep the audit trail on the record. Reporting, mapping and risk work use the same current state.