Skip to content

ISO 27001

ISO 27001 software: build, operate and certify your ISMS

Run Annex A, risks, owners and evidence in the same working state as BCMS, DSMS and AIMS. The ISMS becomes a defensible foundation for further obligations.

ISO 27001:2022 Annex A controls pre-loaded
93
ISMS controls also feed BCMS, DSMS, AIMS evidence
4 systems
Statement of Applicability generated, not assembled
1 SoA

One control, several standards

From ISO 27001 to NIS2 and DORA without duplicate work

KaitoSec keeps approved controls and evidence in one ISMS software workspace and maps them to NIS2, DORA and other frameworks only where their substance overlaps. Framework-specific wording and decisions remain visible.

One control, entered once, satisfies a requirement in each of the standards listed below.

One control

Supplier & third-party due diligence

  • ISO 27001Requirement satisfied
  • NIS2Requirement satisfied
  • DORARequirement satisfied
  • BSI IT-GrundschutzRequirement satisfied
  • TISAXRequirement satisfied

From control to policy

What ISO 27001:2022 requires

ISO 27001:2022 requires a managed ISMS: scope, risk-based decisions, objectives, controlled information, reviews and continual improvement. Annex A supports treatment; it does not replace the management system.

One control feeds the four management systems, which in turn carry it into the policies and procedures listed below.

One control

Supplier & third-party due diligence

Management systems

  • BCMSBusiness continuity
  • ISMSInformation security
  • DSMSData protection
  • AIMSAI governance

Policies and procedures

  • Information security policy
  • Supplier policy
  • Continuity plan

Maintain the SoA and Annex A automatically

Applicability, justification, implementation status and evidence stay together for all 93 Annex A controls. Changes update the working SoA instead of starting another spreadsheet round. Our guide to ISO 27001 certification costs breaks down what a project like this typically costs.

01

Gap analysis with existing context

Map the asset inventory, policies and existing controls to your ISO 27001:2022 scope. KaitoSec prepares open items with owner and priority for professional review.

02

Living Statement of Applicability

Your Statement of Applicability brings applicability, justification, implementation and evidence together. Changes are versioned and your certification body can receive controlled read access to the approved state when required.

03

ISMS policy templates

Start with a structured policy template, adapt it to your organisation and connect the approved version to controls, versions and acknowledgements.

Risk assessment under ISO 27005

Assess risk in context, document treatment and residual risk, assign accountability and set the next review. The ISO 27005 view remains connected to the controls selected for treatment.

01

Control Implementation Tracker

Every Annex A control has a dedicated workspace where you assign owners, attach evidence, and track implementation status. Overall progress toward certification readiness is visible to the whole team.

02

Risk Treatment Workflows

Link risks directly to controls and define the treatment: accept, mitigate, transfer, or avoid. KaitoSec requires documented decisions and reminds owners when risk reviews are overdue.

03

Auditor Access Portal

Give your certification body scoped read access to an approved state of your ISMS evidence. Context, version and accountability stay with the evidence.

Frequently asked questions about ISO 27001 certification

What software do I need for ISO 27001?

For ISO 27001, you need a tool that keeps context, risk assessment, the Statement of Applicability, Annex A controls and evidence together. KaitoSec provides exactly that as ISMS software, without a parallel Excel environment. Our ISO 27001 checklist breaks the whole certification path into concrete steps.

What is the Statement of Applicability (SoA), and how do you maintain it?

The Statement of Applicability (SoA) lists all 93 controls in ISO 27001:2022 Annex A and explains whether and how each is implemented. In KaitoSec, it is generated automatically from risk management and control status, so it stays current and audit-ready.

How long does ISO 27001 certification take?

ISO 27001 certification typically takes 6 to 12 months, depending on maturity and scope. KaitoSec measurably shortens the ISMS build; the timetable to the audit still depends on the certification body. For SMEs without a security team, see ISMS for SMEs.

Can the same ISMS fulfil ISO 27001 and NIS2?

ISO 27001 and NIS2 can share the same ISMS. The measures in Section 30 BSIG overlap substantially with Annex A. Through compliance mapping, one implementation counts for NIS2, DORA and ISO 27001 at the same time; in our data, existing controls cover around 78% of ISO requirements.

ISO 27001 or BSI IT-Grundschutz: which fits us?

ISO 27001 is internationally recognised and risk-based; IT-Grundschutz is more detailed and is often required in public authorities and critical infrastructure. The two can also be combined as ISO 27001 based on IT-Grundschutz. Compare the approaches under BSI IT-Grundschutz.

What is ISO 27001, and what does ISO/IEC 27001:2022 mean?

ISO/IEC 27001 is the international standard for an information security management system (ISMS). It defines how an organisation identifies, treats and evidences risks to the confidentiality, integrity and availability of its information. The 2022 edition replaces the 2013 one: Annex A was condensed to 93 controls in four themes, and eleven controls such as threat intelligence and cloud security were added. Our article ISO 27001:2022 explained simply covers the basics.

How does ISO 27001 certification work?

An accredited certification body audits in two stages: stage 1 checks documentation and readiness, stage 2 checks that the ISMS works in day-to-day operation. The certificate is valid for three years, with annual surveillance audits and a recertification audit at the end of the cycle. Before the first audit the standard expects an internal audit and a management review to have taken place.

Audit evidence without spreadsheets

Versioned policies, approved evidence and a scoped auditor view keep the audit trail on the record. Reporting, mapping and risk work use the same current state.

Connect ISO 27001 with other standards

Extend the same ISMS working state to the standards and obligations that apply to your organisation.