Complies
ISO 27001 · A.5.15

ISO 27001 compliance software that runs your ISMS day to day

ISO 27001:2022 is an ISMS plus 93 Annex A controls. Complies tracks both as obligations with owners, and if you did SOC 2 first, you start roughly 60% pre-filled.

See pricing

ISO 27001 compliance software operates the information security management system the standard requires: Complies tracks the Clause 4 to 10 management obligations, maps your controls to all 93 Annex A controls in ISO 27001:2022, and collects the evidence your certification auditor will sample. The standard demands a running ISMS, not a binder: defined scope, a documented risk assessment and treatment plan, a Statement of Applicability covering every Annex A control, internal audits, and management reviews on a cadence. Complies turns each requirement into an obligation with an owner and a due date, drafts policy starting points your team edits and approves, and pulls technical evidence from AWS, GitHub, Azure, and Okta automatically. Certification audits typically cost $10,000 to $30,000 in auditor fees, so arriving organized is worth real money. If you completed SOC 2 first, that work pre-fills roughly 60% of ISO 27001 in Complies, because access control, change management, risk assessment, and incident response map across both frameworks, and the same controls reach into GDPR Art. 32 and PCI DSS. One control library serves every framework, at $199 a month on Growth instead of a quote-only annual contract.

Complies handles it with control mapping across frameworks and policy management software, with every control cross-mapped to the other frameworks you run.

ISO 27001 DEMANDS

What ISO 27001 asks of you, in plain language

CodeWhat it demandsHow Complies helps
Clause 6.1.2 Run and document an information security risk assessment The risk register ties each risk to assets, owners, and treatment decisions, and generates the risk assessment record your certification auditor asks for first.
A.5.1 Maintain approved, communicated information security policies AI-drafted policy starting points mapped to A.5.1; your team edits and approves, and Complies tracks versions, review dates, and staff acknowledgments.
A.5.15 Grant access to information based on business need only Maps SSO, IAM, and repository permissions to A.5.15, schedules access reviews, and flags leavers whose accounts outlived their employment.
A.8.8 Manage technical vulnerabilities in the systems you operate Collects scanner output and patch cadence evidence from AWS and GitHub, ties it to A.8.8, and flags when the cadence slips.
Clause 9.2 Audit your own ISMS at planned intervals The compliance calendar schedules internal audits, assigns them owners, and stores findings as evidence, so the certification auditor sees a system that inspects itself.
CROSS-MAP

Collect once, comply many times

ISO 27001 overlaps heavily with everything else you will be asked for: A.5.15 access control is SOC 2 CC6.1, GDPR Art. 32, HIPAA 164.312(a), and PCI DSS Req. 7 in different numbering, and the risk, incident, and vendor clauses map the same way. Complies keeps one control library and marks each control satisfied across every framework it serves, so SOC 2 work done first pre-fills roughly 60% of your Statement of Applicability, and evidence is reused wherever the second auditor accepts it. Cross-mapping ships on Growth and up.

Control areaISO 27001Also satisfies
Access control A.5.15 SOC 2 CC6.1 · GDPR Art. 32 · HIPAA 164.312(a) · PCI Req. 7
Security policies A.5.1 SOC 2 CC5.3 · HIPAA 164.316 · PCI Req. 12.1
Vulnerability management A.8.8 SOC 2 CC7.1 · PCI Req. 11.3
Incident management A.5.24 SOC 2 CC7.4 · GDPR Art. 33 · HIPAA 164.308(a)(6)

See the full crosswalk on the control mapping software page.

THE PATH

Getting ISO 27001 ready with Complies

01

Scope the ISMS and connect your stack

Define what the ISMS covers, connect AWS, GitHub, Azure, and Okta, and let Complies build your obligation tracker from the Clause 4 to 10 requirements and all 93 Annex A controls.

02

Assess risks and build the Statement of Applicability

Work the risk register, decide treatment per risk, and mark each Annex A control applicable or justified out. Complies drafts policies and keeps the SoA current as controls change.

03

Run the ISMS, then bring the certification body

Internal audit and management review land on the calendar with owners. When the readiness score holds, export the evidence pack and schedule stage 1 and stage 2 audits.

Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.

QUESTIONS

ISO 27001 questions, answered

No. Certification is issued by an accredited certification body after stage 1 and stage 2 audits, and no software can grant it. Complies assists with compliance workflows: it is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready, with the ISMS documented, the Statement of Applicability current, and evidence organized for sampling.

Less than half, usually. Access control, change management, monitoring, incident response, and vendor management map directly, so your ISO readiness score starts pre-filled, typically around 60%. What SOC 2 does not give you is the ISMS machinery: scope, Statement of Applicability, internal audit, and management review. Complies tracks those as obligations so the remaining work is visible and staffable.

Certification body fees typically run $10,000 to $30,000 depending on company size and scope, and surveillance audits follow annually. Complies covers the readiness side at $199 a month on Growth, $2,388 a year, where incumbents like Vanta or Drata typically quote $7,500 to $25,000 or more per year with a sales call required to see a number.

New certifications are issued against ISO 27001:2022, and existing 2013 certificates had to transition by October 2025. Complies maps to the 2022 control set: 93 Annex A controls across organizational, people, physical, and technological themes. If your policies still reference the 2013 numbering, the control map shows exactly which items moved or merged.

Start your ISO 27001 readiness today

Growth includes every framework, cross-mapped, at $199 a month.