Complies

CLAUSE 6.1.2 · CLAUSE 6.1.3 · CLAUSE 8.2

ISO 27001 risk management software: a risk assessment tool, ISMS risk register and Statement of Applicability for ISO 27001:2022

The risk assessment is the one part of ISO 27001 an auditor reads line by line, and the one part most teams still run in a spreadsheet that nobody has opened since the last audit.

See pricing

From $79/mo · Prices published · No sales call · Monthly billing

SOC 2 · TRUST SERVICES CRITERIA

Audit readiness

0 %

Your auditor makes the final call

Built for teams of 5 to 200

AWS GitHub Google Workspace Slack Jira Azure Okta
RISK

What ISO 27001 risk management software does, and what clauses 6.1.2 to 8.3 actually ask for

ISO 27001 risk management software runs the risk assessment and risk treatment process that clauses 6.1.2 and 6.1.3 of ISO/IEC 27001:2022 require, then keeps it current under clause 8.2, which says the assessment must be repeated at planned intervals and whenever significant change is proposed or occurs. In practice that means one place where each risk has an owner, a likelihood, a consequence, a resulting level compared against your written acceptance criteria, a treatment decision, and a link to the Annex A controls that treat it, with the Statement of Applicability produced from those decisions rather than typed separately. The standard is less prescriptive than most templates suggest. Since the 2013 revision it has not required you to list assets, threats and vulnerabilities; the 2022 text asks for a process that produces consistent, valid and comparable results, identifies risks to confidentiality, integrity and availability within the ISMS scope, names a risk owner for each, analyzes consequence and likelihood, and evaluates the result against criteria you set in advance. ISO/IEC 27005:2022 is the guidance standard and describes both the asset-based approach most teams still use and an event-based one. Clause 6.1.3 then requires you to choose treatment options, determine the controls those options need, compare that list against the 93 controls in Annex A to check nothing necessary was left out, write the Statement of Applicability with a justification for every inclusion and exclusion, and get each risk owner to approve the treatment plan and accept the residual risk. The reason software exists for this is not the arithmetic. It is that the assessment, the SoA, the treatment plan and the evidence that treatments are working are four documents that drift apart the moment they live in different files, and the auditor tests exactly that drift. Complies holds them as one record for teams of 5 to 200: a risk register seeded for your stack where each risk carries an owner and a likelihood-times-impact score, controls linked to the risks they treat with the SoA marked applicable or justified out from the same library, evidence pulled on a schedule from AWS, Okta, GitHub and Google Workspace, and review cadences enforced by the compliance calendar. The register, cross-mapping and evidence collection are in the Growth plan at $199 a month billed yearly ($239 monthly), which is published on the pricing page rather than disclosed after a demo. It does not scan your network, it does not run penetration tests, and it does not audit you, and the tables below say where those lines fall.

Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.

ASSESS · TREAT · REPEAT

The three clauses an ISO 27001 auditor walks through, and where each one breaks in a spreadsheet

6.1.2

Assess: criteria first, then risks with owners

Clause 6.1.2 starts with something most teams skip: written risk acceptance criteria and criteria for how assessments are performed, so that two assessments a year apart are comparable. Then every risk gets an owner, a consequence, a likelihood and a level. A spreadsheet holds the rows fine. What it cannot show an auditor is that the same criteria were applied both times, or who owned a risk on the day it was rated.

risk register software
6.1.3

Treat: controls, the Statement of Applicability, and residual acceptance

Treatment is where the assessment turns into the control set. You pick options, determine the controls, check them against Annex A, and write the SoA with a justification per control. The failure is a SoA written once as a standalone document, so when a risk changes the SoA does not, and the auditor finds a control marked applicable that no risk in the register requires.

control mapping software
8.2

Repeat: at planned intervals and on significant change

Clause 8.2 requires the assessment at planned intervals or when significant changes are proposed or occur, and clause 9.3 feeds the results into management review. A spreadsheet has no concept of an interval. Complies puts the review on the compliance calendar with a named owner, records each one, and flags a revisit when a new system or vendor enters scope.

obligation tracking software
COMPARE

What ISO 27001:2022 requires of the risk process, clause by clause, and where Complies holds each piece

Most pages about ISO 27001 risk assessment describe a generic six-step method and never quote the clauses, which makes it impossible to check a tool, or your own spreadsheet, against what the certification auditor is actually reading from. Here is each requirement in the order the standard states it, what the auditor looks for as evidence, the way it typically fails, and where Complies records it. Use it as a specification for any tool on this page, ours included.

Clause and requirement What the auditor looks for Where it usually fails Where Complies holds it
6.1.2 a) Risk acceptance criteria and assessment criteria A documented statement of what level of risk the organization accepts and how likelihood and consequence are scored. Criteria written into a methodology document nobody applies, so ratings drift between assessors. The scoring matrix and acceptance threshold are fixed in the register, and every risk is rated against them.
6.1.2 b) Consistent, valid and comparable results Evidence that repeated assessments used the same method and can be compared over time. Each year a different person rebuilds the spreadsheet with different columns and scales. One register with a dated history per risk, so last year and this year sit in the same view.
6.1.2 c) Identify risks and risk owners Risks to confidentiality, integrity and availability within scope, each with a named owner. Risks owned by "IT" or by the person who left, so nobody can approve treatment or accept residual risk. A required owner field per risk, tied to a workspace user, with reassignment logged.
6.1.2 d) Analyze consequence, likelihood and level A rating for each risk with the reasoning behind it, producing a level of risk. Everything rated medium, which defends no prioritization decision. Likelihood and impact fields with a stored rationale, producing a level you can sort and defend.
6.1.2 e) Evaluate against criteria and prioritize A comparison of each level against the acceptance criteria and a treatment order that follows from it. Levels calculated but never compared with the threshold, so treatment order is whoever shouted loudest. Risks above the threshold are queued for treatment automatically; those below are recorded as accepted with a rationale.
6.1.3 a) to c) Treatment options and necessary controls A treatment decision per risk and the controls chosen, checked against Annex A so no necessary control was omitted. Controls chosen from a template rather than from the risks, so the link between a risk and its control cannot be shown. Each risk links to the controls that treat it; the Annex A comparison is a view of that same library.
6.1.3 d) Statement of Applicability The necessary controls, a justification for each inclusion, whether it is implemented, and a justification for each exclusion. A standalone SoA document that stops matching the register the first time a risk changes. The SoA is generated from the control library, marked applicable or justified out, and stays current as controls change.
6.1.3 e) and f) Treatment plan, owner approval and residual acceptance A plan with actions, owners and dates, approved by risk owners, who also accept the residual risk. A plan that exists as a slide deck, with no record of who approved it or when. Treatment actions are tracked obligations with owners and due dates; acceptance of residual risk is recorded per risk.
8.2 and 8.3 Perform at planned intervals, implement the plan Dated evidence that the assessment was repeated on schedule or on significant change, and that the plan was actually carried out. The single most common finding: the assessment was done once for certification and never repeated. Review cadence on the compliance calendar with a recorded outcome, plus a trigger when a new system or vendor is added.
9.3 c) Management review inputs Results of the risk assessment and the status of the treatment plan presented to management. Management review minutes that mention risk in one sentence with nothing attached. A register summary and treatment status exportable for the review pack.

One clarification, because template vendors keep it alive: ISO 27001 has not required an asset, threat and vulnerability inventory since the 2013 revision, and the 2022 edition does not either. An asset-based method is still the most common way to do the work and ISO/IEC 27005:2022 describes it in detail, but the auditor is checking the clauses above, not the columns of any particular template. If you have a good asset-based register, keep it. If you have a scenario-based one that meets 6.1.2, that is equally acceptable. Also note that certificates issued against ISO/IEC 27001:2013 expired on October 31, 2025, so any tool or template you adopt now needs the 2022 clause numbering and the 93-control Annex A. Compare the platforms that bundle risk management with the rest of the ISMS on Hicomply alternatives, Vanta alternatives and Drata alternatives.

DEDICATED TOOL, PLATFORM OR SPREADSHEET

ISO 27001 risk management tools compared, with the prices each vendor actually publishes

There are three shapes of product in this category and they are priced very differently: dedicated risk assessment tools built around the 27001 method, compliance automation platforms where risk is one module among many, and the spreadsheet most companies start with. The figures below were read off each vendor's own pricing page in September 2026. Where a vendor publishes nothing we say so rather than repeat a third-party estimate.

Tool What it actually is Who it fits Published pricing (September 2026)
Complies A risk register linked to a shared control library across ISO 27001, SOC 2, HIPAA, GDPR and PCI DSS, with the Statement of Applicability generated from control decisions and evidence collected on a schedule. US teams of 5 to 200 that want ISO 27001 risk, controls and evidence in one record at a price they can read first, usually alongside SOC 2. Published: Starter $79, Growth $199, Scale $499 a month billed yearly; the risk register is in Growth and above.
Conformio (Advisera) An ISO 27001 implementation tool built around document wizards, with a risk register that suggests Annex A controls and produces the methodology, assessment report, SoA and treatment plan. Small companies that want the mandatory 27001 documents written for them and are certifying against ISO 27001 alone. Published: Starter $169 a month or $1,399 a year with 3 users and up to 100 risks; Professional $289 a month or $2,399 a year with unlimited risks; Advanced $349 a month or $2,699 a year.
CyberComply (GRC Solutions, formerly vsRisk) The successor to the vsRisk assessment tool from Vigilant Software, now sold by GRC Solutions as a purpose-built ISO 27001 risk assessment and reporting tool. Organizations, mainly in the UK and EU, that want a dedicated risk tool with 27001 and 27005 reporting rather than a compliance platform. Not published; the product pages route to a quote request.
ISMS.online A document-first ISMS platform covering the full ISO 27001 clause set, with risk management, the SoA and policies in one workspace. Companies running a mature ISMS across several ISO standards who want the whole management system in one tool. Not published; pricing is described as bespoke.
Hicomply An ISO 27001 platform with risk assessment, SoA and audit management, priced per framework. Teams certifying against one framework first who want a fixed annual price. Published: Essentials $6,995 a year, Professional $13,995 a year, each covering one primary framework, with renewals carrying a 10% annual uplift.
Vanta, Drata, Secureframe, Sprinto Compliance automation platforms where the ISO 27001 risk register is one module inside a SOC 2 style control and integration set. Companies whose main driver is passing customer security reviews, with ISO 27001 risk folded into the same contract. Quote-only and annual-first; none publishes a rate card.
RiskWatch An ISO 27001 assessment and compliance management product covering the 93 Annex A controls with SoA generation. Organizations wanting a broader risk and compliance assessment tool that also covers other standards. Not published; the pricing page redirects to a quote form.
A spreadsheet or template Whatever columns you give it. Legitimately compliant if it meets 6.1.2 and 6.1.3 and is genuinely repeated and versioned. Very small scopes with one person who reliably owns the process and a certification body that accepts it. Free, until the surveillance audit asks how this year compares with last year.

Two honest notes. First, a spreadsheet is not a disqualification. Certification bodies accept spreadsheet-based risk assessments every week, and a well-kept one with dated versions and a matching SoA passes. The reason companies leave it is clause 8.2, not clause 6.1.2: the assessment gets repeated when the calendar forces it, and a spreadsheet has no calendar. Second, no tool on this list, ours included, reduces a risk by existing. Scoring is judgment. Software makes the judgment explicit, owned, repeated on schedule and defensible in front of the auditor, and that is the whole of what you are paying for.

CAPABILITIES

What Complies covers when the risk assessment has to survive a surveillance audit

Acceptance criteria applied, not just written

Clause 6.1.2 a) asks for criteria before any risk is scored. The scoring matrix and acceptance threshold live in the register itself, so every rating is made against the same scale and the auditor can see that year two used the method year one documented.

Risks linked to the controls that treat them

Each risk links to the Annex A and framework controls chosen to treat it, and the residual picture updates as those controls are implemented and evidenced. The link between a risk and its control is the thing clause 6.1.3 tests, and it cannot be shown across two files.

A Statement of Applicability that stays current

The SoA is produced from the control library, each control marked applicable or justified out. Change a treatment decision and the SoA reflects it, which removes the classic finding of an SoA that no longer matches the register.

Review at planned intervals, with a record

The risk review sits on the compliance calendar with an owner and a due date, and each review is recorded. When a new system, vendor or process enters scope the register flags a revisit, which is what clause 8.2 means by significant change.

One register across ISO 27001 and SOC 2

SOC 2 asks how risk informed control selection; ISO 27001 asks for the same thing with clause numbers. One register with one set of ratings serves both, so a US company chasing SOC 2 for customers and ISO 27001 for an enterprise deal is not scoring the same risks twice.

A price you can read before the sales call

Growth is $199 a month billed yearly and includes the register, cross-mapping, evidence collection and readiness scoring. Most platforms in this category will not quote until after a demo, which for a small team is a procurement cycle before you can scope the work.

HOW TO START

Running the ISO 27001 risk assessment in Complies

01

Set the criteria before scoring anything

Write the likelihood and consequence scales and the acceptance threshold first. Complies holds them in the register so they apply to every risk you add, which is the consistency clause 6.1.2 b) is looking for.

02

Start from the seeded register and assign owners

Complies seeds common risks for your stack and frameworks. Edit the draft, remove what does not apply, add what is specific to your architecture, and give every risk a named owner who can approve treatment and accept residual risk.

03

Treat each risk and let the SoA follow

Choose reduce, accept, avoid or share per risk, link the controls that treat it, and mark each control applicable or justified out. The Statement of Applicability and the treatment plan are views of those decisions rather than separate documents.

04

Connect cloud and identity so treatment is evidenced

Point Complies at AWS, Okta or Google Workspace and GitHub. It reads configuration and access rather than your data, and the controls treating each risk stop being a claim and become a scheduled observation. Then set the review cadence and let the calendar enforce clause 8.2.

FIT

Who this is for, and who it is not

A GOOD FIT WHEN

  • You are certifying against ISO 27001:2022 for the first time and want the risk assessment, SoA and evidence in one record.
  • You passed stage 2 with a spreadsheet and the surveillance audit is asking how this year compares with last year.
  • You already run SOC 2 and refuse to score the same risks a second time for ISO 27001.
  • Your Statement of Applicability was written once as a document and has quietly stopped matching the register.
  • You want a published price and monthly billing rather than a quote after a demo.

LOOK ELSEWHERE WHEN

  • You need a vulnerability scanner or a penetration test; those are separate services and this is not one.
  • You want a consultant to perform and write the assessment for you, or to run the internal audit on your behalf.
  • You are a large enterprise running integrated risk management across thousands of assets and several legal entities.
  • You need business continuity planning or ISO 22301, which Complies does not ship.
  • You want the mandatory 27001 documents written by a wizard; Complies holds the decisions and the evidence, and you write the policies from templates.
QUESTIONS

ISO 27001 risk assessment questions buyers actually ask

The ISO 27001 risk assessment is the process clause 6.1.2 requires: define acceptance and assessment criteria, identify risks to the confidentiality, integrity and availability of information inside the ISMS scope, name a risk owner for each, analyze consequence and likelihood to produce a level, and evaluate that level against your criteria to decide what gets treated first. Its output feeds risk treatment under 6.1.3 and the Statement of Applicability.

Yes. Clause 6.1.2 requires a documented risk assessment process, clause 6.1.3 requires a risk treatment process and a Statement of Applicability, and clause 8.2 requires the assessment to be performed at planned intervals and on significant change, with documented results retained. A certification body cannot issue a certificate without seeing all three.

The standard does not name an interval. Clause 8.2 says at planned intervals, or when significant changes are proposed or occur. Annual is the working norm, usually timed with the internal audit and ahead of the surveillance visit, but the real trigger is change: a new product, cloud provider, vendor holding your data, office or acquisition should each prompt an update rather than waiting for the anniversary.

No. The requirement to identify assets, threats and vulnerabilities was removed in the 2013 revision and is not in the 2022 edition. Asset-based assessment is still the most common method and ISO/IEC 27005:2022 describes it, but an event-based or scenario-based method that meets clause 6.1.2 is equally acceptable. What the auditor checks is that the method is defined, applied consistently and produces comparable results.

Risk assessment (clause 6.1.2) finds and rates the risks. Risk treatment (clause 6.1.3) decides what to do about each one: reduce it with controls, accept it, avoid the activity, or share it with a third party. Treatment is where the controls are chosen and checked against Annex A, where the Statement of Applicability is written, and where risk owners approve the plan and accept the residual risk that remains.

The Statement of Applicability, required by clause 6.1.3 d), lists the controls your risk treatment determined as necessary, whether each is implemented, the justification for including it, and the justification for excluding any Annex A control you decided not to apply. It is the document that connects the register to the control set, and it is the first thing most auditors ask for after the scope.

Annex A of ISO/IEC 27001:2022 contains 93 controls in four themes: 37 organizational, 8 people, 14 physical and 34 technological. The 2013 edition had 114 controls in 14 domains; the 2022 revision merged many and added eleven new ones, including threat intelligence, cloud services security, data masking and secure coding. Certificates against the 2013 edition expired on October 31, 2025.

ISO/IEC 27005:2022 is the guidance standard for information security risk management. It is not certifiable and you are not audited against it, but it describes the assessment methods, the risk criteria and the treatment options that clause 6 of ISO 27001 assumes. Most methodology documents cite it, and a tool that follows it will map cleanly onto the 27001 clauses.

The person with the accountability and authority to manage the risk, which usually means the manager who owns the system, process or team the risk sits in, not the compliance lead who runs the register. Clause 6.1.3 f) requires risk owners to approve the treatment plan and accept residual risk, so the owner has to be someone who can genuinely make that decision.

Yes, and many certified companies do. A spreadsheet is compliant if it applies documented criteria, records owners, consequence, likelihood and level for each risk, links treatment to controls, and is kept as dated versions so repeated assessments can be compared. Where it fails is clause 8.2: nothing in a spreadsheet makes the review happen on schedule, and the SoA has to be maintained separately by hand.

It ranges widely because the products differ in shape. Conformio publishes $169 to $349 a month, or $1,399 to $2,699 a year. Complies publishes $79, $199 and $499 a month billed yearly, with the risk register in Growth at $199. Hicomply publishes $6,995 and $13,995 a year per primary framework. Vanta, Drata, Secureframe, Sprinto, ISMS.online, RiskWatch and CyberComply do not publish figures. All prices read September 2026.

Yes, and it is the cheaper path when both are on the roadmap. SOC 2 asks how risk assessment informed control selection (the CC3 criteria) and ISO 27001 asks the same with clause numbers, so one register with one set of ratings serves both. What stays ISO-specific is the Statement of Applicability and the formal risk owner approval. Complies cross-maps SOC 2, ISO 27001, HIPAA, GDPR and PCI DSS from the Growth plan.

The risk treatment plan, required by clause 6.1.3 e), sets out what will be done about each risk above your acceptance threshold: the treatment option chosen, the controls to implement, who is responsible and by when. Risk owners must approve it and accept the residual risk, and clause 8.3 then requires you to implement it and keep records of the results. In Complies each action in the plan is a tracked obligation with an owner and a date.

GO DEEPER

Frameworks and guides

Run the ISO 27001 risk assessment as a living register, not a spreadsheet you reopen before the audit

Prices published, $79 to $499 a month. Monthly billing. Start today, no sales call.