ISO 27001 compliance software that runs your ISMS day to day
ISO 27001:2022 is an ISMS plus 93 Annex A controls. Complies tracks both as obligations with owners, and if you did SOC 2 first, you start roughly 60% pre-filled.
ISO 27001 compliance software operates the information security management system the standard requires: Complies tracks the Clause 4 to 10 management obligations, maps your controls to all 93 Annex A controls in ISO 27001:2022, and collects the evidence your certification auditor will sample. The standard demands a running ISMS, not a binder: defined scope, a documented risk assessment and treatment plan, a Statement of Applicability covering every Annex A control, internal audits, and management reviews on a cadence. Complies turns each requirement into an obligation with an owner and a due date, drafts policy starting points your team edits and approves, and pulls technical evidence from AWS, GitHub, Azure, and Okta automatically. Certification audits typically cost $10,000 to $30,000 in auditor fees, so arriving organized is worth real money. If you completed SOC 2 first, that work pre-fills roughly 60% of ISO 27001 in Complies, because access control, change management, risk assessment, and incident response map across both frameworks, and the same controls reach into GDPR Art. 32 and PCI DSS. One control library serves every framework, at $199 a month on Growth instead of a quote-only annual contract.
Complies handles it with control mapping across frameworks and policy management software, with every control cross-mapped to the other frameworks you run.
What ISO 27001 asks of you, in plain language
| Code | What it demands | How Complies helps |
|---|---|---|
| Clause 6.1.2 | Run and document an information security risk assessment | The risk register ties each risk to assets, owners, and treatment decisions, and generates the risk assessment record your certification auditor asks for first. |
| A.5.1 | Maintain approved, communicated information security policies | AI-drafted policy starting points mapped to A.5.1; your team edits and approves, and Complies tracks versions, review dates, and staff acknowledgments. |
| A.5.15 | Grant access to information based on business need only | Maps SSO, IAM, and repository permissions to A.5.15, schedules access reviews, and flags leavers whose accounts outlived their employment. |
| A.8.8 | Manage technical vulnerabilities in the systems you operate | Collects scanner output and patch cadence evidence from AWS and GitHub, ties it to A.8.8, and flags when the cadence slips. |
| Clause 9.2 | Audit your own ISMS at planned intervals | The compliance calendar schedules internal audits, assigns them owners, and stores findings as evidence, so the certification auditor sees a system that inspects itself. |
Collect once, comply many times
ISO 27001 overlaps heavily with everything else you will be asked for: A.5.15 access control is SOC 2 CC6.1, GDPR Art. 32, HIPAA 164.312(a), and PCI DSS Req. 7 in different numbering, and the risk, incident, and vendor clauses map the same way. Complies keeps one control library and marks each control satisfied across every framework it serves, so SOC 2 work done first pre-fills roughly 60% of your Statement of Applicability, and evidence is reused wherever the second auditor accepts it. Cross-mapping ships on Growth and up.
| Control area | ISO 27001 | Also satisfies |
|---|---|---|
| Access control | A.5.15 | SOC 2 CC6.1 · GDPR Art. 32 · HIPAA 164.312(a) · PCI Req. 7 |
| Security policies | A.5.1 | SOC 2 CC5.3 · HIPAA 164.316 · PCI Req. 12.1 |
| Vulnerability management | A.8.8 | SOC 2 CC7.1 · PCI Req. 11.3 |
| Incident management | A.5.24 | SOC 2 CC7.4 · GDPR Art. 33 · HIPAA 164.308(a)(6) |
See the full crosswalk on the control mapping software page.
Getting ISO 27001 ready with Complies
Scope the ISMS and connect your stack
Define what the ISMS covers, connect AWS, GitHub, Azure, and Okta, and let Complies build your obligation tracker from the Clause 4 to 10 requirements and all 93 Annex A controls.
Assess risks and build the Statement of Applicability
Work the risk register, decide treatment per risk, and mark each Annex A control applicable or justified out. Complies drafts policies and keeps the SoA current as controls change.
Run the ISMS, then bring the certification body
Internal audit and management review land on the calendar with owners. When the readiness score holds, export the evidence pack and schedule stage 1 and stage 2 audits.
Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.
ISO 27001 questions, answered
No. Certification is issued by an accredited certification body after stage 1 and stage 2 audits, and no software can grant it. Complies assists with compliance workflows: it is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready, with the ISMS documented, the Statement of Applicability current, and evidence organized for sampling.
Less than half, usually. Access control, change management, monitoring, incident response, and vendor management map directly, so your ISO readiness score starts pre-filled, typically around 60%. What SOC 2 does not give you is the ISMS machinery: scope, Statement of Applicability, internal audit, and management review. Complies tracks those as obligations so the remaining work is visible and staffable.
Certification body fees typically run $10,000 to $30,000 depending on company size and scope, and surveillance audits follow annually. Complies covers the readiness side at $199 a month on Growth, $2,388 a year, where incumbents like Vanta or Drata typically quote $7,500 to $25,000 or more per year with a sales call required to see a number.
New certifications are issued against ISO 27001:2022, and existing 2013 certificates had to transition by October 2025. Complies maps to the 2022 control set: 93 Annex A controls across organizational, people, physical, and technological themes. If your policies still reference the 2013 numbering, the control map shows exactly which items moved or merged.
ISO 27001 Checklist: 13 Steps From Scope to Certification
CROSS-FRAMEWORKSOC 2 vs ISO 27001: Which One Do You Need? (Or Both)
Start your ISO 27001 readiness today
Growth includes every framework, cross-mapped, at $199 a month.