ISMS · ANNEX A · CERTIFICATION
ISO 27001 software: ISO 27001 compliance software, audit and certification tools for your ISMS
ISO 27001:2022 asks for a working management system, not a binder: a scoped ISMS, a risk assessment you can defend, a Statement of Applicability covering all 93 Annex A controls, internal audits, and management reviews on a cadence. Complies keeps all of it running between audits.
From $79/mo · Prices published · No sales call · Monthly billing
Audit readiness
0 %
Built for teams of 5 to 200
What ISO 27001 software actually does
ISO 27001 software builds and operates the information security management system the standard requires, then keeps the evidence a certification body will sample. Concretely it does three jobs: it tracks the Clause 4 to 10 management requirements as recurring obligations with named owners, it maps your controls against all 93 Annex A controls in ISO/IEC 27001:2022 and keeps the Statement of Applicability current, and it collects the technical evidence behind those controls on a schedule so stage 1 and stage 2 are a review rather than an excavation. Complies does that for companies of 5 to 200 people, where the ISMS belongs to a founder, a head of engineering, or a first security hire rather than a department. The Annex A control set breaks into four themes: 37 organizational controls, 8 people controls, 14 physical controls, and 34 technological controls. Complies holds them in one library alongside SOC 2, GDPR, HIPAA, and PCI DSS, so a control you map once counts everywhere it applies. That cross-mapping is the practical reason teams pick this over an ISO-only tool: if you finished SOC 2 first, roughly 60 percent of your ISO 27001 work is already done, because access control, change management, incident response, and vendor review are the same controls under different numbering. Evidence reads from AWS, GitHub, Google Workspace, Azure, and Okta, configuration only, never your customer data. What is different here is how you buy it. Prices are published at $79 to $499 a month, billing can be monthly, and every framework is cross-mapped from the Growth tier, so there is no demo, no quote, and no annual contract before your first Annex A control is mapped. No software issues an ISO 27001 certificate. An accredited certification body does that after stage 1 and stage 2 audits, and any tool implying otherwise is selling you something it cannot deliver.
Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.
Last updated July 2026
What ISO 27001 software has to get right
The ISMS: Clauses 4 to 10 as obligations with owners
Most teams get Annex A roughly right and fail on the management system around it. Clause 6.1.2 wants a documented risk assessment, Clause 9.2 wants internal audits at planned intervals, Clause 9.3 wants management reviews, and Clause 10 wants nonconformities tracked to closure. Complies turns each one into a recurring obligation with a named owner and a due date, so the ISMS keeps running in month seven instead of going quiet until the surveillance audit is booked.
compliance obligation trackingAll 93 Annex A controls, mapped once and counted everywhere
Annex A in ISO 27001:2022 is 93 controls across four themes: 37 organizational, 8 people, 14 physical, 34 technological. Complies holds them in one library shared with SOC 2, GDPR, HIPAA, and PCI DSS, marks each control applicable or justified out, and keeps the Statement of Applicability current as things change. A.5.15 access control is SOC 2 CC6.1, GDPR Article 32, HIPAA 164.312(a), and PCI DSS Requirement 7 wearing different labels, so you maintain it in one place.
control mapping softwareISO 27001 audit software: evidence for stage 1 and stage 2
Certification runs in two passes. Stage 1 reviews your documentation, mostly scope, risk assessment, SoA, and policies. Stage 2 tests whether you actually do what you wrote. Complies pulls the technical evidence continuously from your cloud and identity stack, attaches each artifact to the control it proves, and exports an organized pack when the auditor asks for a sample. Internal audit findings and management review minutes live in the same place, because stage 1 asks for those too.
automated evidence collectionThree ways to run ISO 27001, and who each one fits
There are three honest ways to get to an ISO 27001 certificate, and the right one depends on your size and how you prefer to buy software. Here is the comparison including where Complies is the wrong answer.
| Dimension | Spreadsheet ISMS plus a consultant | Sales-led compliance platform | Complies |
|---|---|---|---|
| Best for | One-off certification with expert hand-holding | Funded startups wanting a guided, sales-led rollout | Teams of 5 to 200 running ISO 27001 part-time |
| Annex A coverage | A spreadsheet you maintain by hand | Full control library, framework packs by tier | All 93 controls, cross-mapped from Growth |
| Statement of Applicability | A document that drifts between audits | Generated and maintained in-platform | Generated from the control library, current by default |
| Risk assessment | A workshop deck, refreshed annually if you remember | Built-in risk module, depth varies by platform | A register with owners, treatment decisions, and control links |
| Evidence collection | Manual screenshots before each audit | Automated across a wide integration set | Automated from AWS, GitHub, Google Workspace, Azure, Okta |
| Reusing SOC 2 work | You re-do it, in a second spreadsheet | Usually supported, sometimes priced per framework | Shared control library, SOC 2 pre-fills roughly 60 percent |
| How you buy | Consultant day rates, scoped per engagement | Demo, quote, then an annual contract | Published price, sign up, start the same afternoon |
| Pricing | Consultant fees on top of your own hours | Quote-only; Vendr put 2026 medians near $15,000 to $25,000 a year | Published: $79, $199, $499 per month |
Read it honestly. If ISO 27001 is a one-time contractual requirement and you have budget for a consultant to carry it, that route works and we will not pretend otherwise. If you want a dedicated customer success manager walking you through certification, Vanta, Drata, and Sprinto are built for exactly that and do it well. Complies fits the team that wants the ISMS running continuously, at a price they can read, without a sales cycle in front of it. Certification body fees are separate in every column, because the auditor is always a different company. If you are also weighing the sales-led platforms on price, the detailed breakdowns are on Vanta alternatives, Drata alternatives and Sprinto alternatives.
What changes once the ISMS lives in software
The Statement of Applicability stops drifting
The SoA is the document auditors open first, and in a spreadsheet ISMS it is usually months out of date. Here it is generated from the live control library, so a control you retire or add is reflected the same day rather than the week before stage 1.
SOC 2 work pre-fills roughly 60 percent of ISO 27001
Access control, change management, risk assessment, incident response, and vendor review carry across both frameworks. One control library means finishing SOC 2 leaves you with a partially complete Annex A rather than a blank second project.
Internal audits and management reviews actually happen
Clause 9.2 and Clause 9.3 are where small ISMS programs quietly fail, because nothing chases them. They land on the compliance calendar with owners and due dates, and the findings are stored as the evidence stage 1 expects to see.
Evidence collects itself between audits
Access lists, encryption settings, MFA enforcement, and patch cadence read from AWS, GitHub, Google Workspace, Azure, and Okta on a schedule and attach to the Annex A control they prove. Gathering artifacts is the single biggest time sink in a manual certification push.
A readiness score that will not flatter you
One number for where the ISMS stands, plus a ranked gap list naming what is missing and who owns it. It never reads 100, because no tool can promise a certification outcome, and a dashboard that is always green tells you nothing.
A price you can read before you talk to anyone
Starter is $79 a month, Growth $199, Scale $499, all published, with monthly billing available. Quote-only and annual-first is the norm in this category, so a public number is genuinely unusual.
From signup to a stage 1 ready ISMS
Scope the ISMS and pick ISO 27001
Define what the management system covers, then select ISO 27001:2022. Complies generates the Clause 4 to 10 obligations and the full 93 control Annex A set, already cross-mapped against any other framework you carry.
Connect the systems your evidence lives in
Point Complies at AWS, GitHub, Google Workspace, Azure, and Okta. It reads configuration rather than customer data and starts attaching artifacts to the controls they prove, on a schedule.
Work the risk register and build the SoA
Rate each risk, record a treatment decision, and link it to the control that reduces it. Mark every Annex A control applicable or justified out, and the Statement of Applicability builds itself from those decisions.
Run internal audit and management review, then certify
Both land on the calendar with owners. When the readiness score holds and the gap list is clear, export the evidence pack and book stage 1 and stage 2 with an accredited certification body.
Who this is for, and who it is not
A GOOD FIT WHEN
- You are 5 to 200 people and ISO 27001 is somebody's second job rather than a department.
- A customer or a deal is asking for ISO 27001 certification and you need the ISMS standing up now.
- You already have SOC 2 and refuse to rebuild the same controls in a second spreadsheet.
- You want the Statement of Applicability and the risk register in one system, current between audits.
- You would rather read a published price than sit through a demo to find out what it costs.
LOOK ELSEWHERE WHEN
- You want a consultant to write the ISMS for you. That is a services engagement, and Complies is software.
- You need a certificate issued. Only an accredited certification body can do that, after stage 1 and stage 2.
- You run a multi-entity enterprise risk program with a dedicated GRC team, where a configurable suite earns its price.
- You need CMMC, consent management, cookie banners, DSAR automation, or data mapping. Complies does not do any of those.
Common questions about ISO 27001 software
ISO 27001 software builds and runs the information security management system ISO/IEC 27001:2022 requires. It tracks the Clause 4 to 10 management obligations, maps your controls against all 93 Annex A controls, maintains the Statement of Applicability, holds the risk register, and collects the evidence a certification body samples at stage 2. It prepares you for certification; it does not issue the certificate.
No, the standard never mentions software, and small scopes have been certified on spreadsheets and shared drives. Software earns its place when the ISMS has to stay alive between audits: chasing internal audits, keeping the SoA current, re-collecting evidence every cycle, and proving Clause 9 actually ran. If you carry a second framework such as SOC 2, the cross-mapping alone usually pays for the tool.
ISO 27001 audit software covers two different audits. Internal audits under Clause 9.2 are your own check on the ISMS, scheduled and evidenced. The certification audit is external and runs in two stages: stage 1 reviews your documentation, and stage 2 tests whether you do what you documented. Audit software schedules the internal cycle, tracks findings to closure, and organizes the evidence pack the external auditor samples.
Complies publishes its prices: $79 a month on Starter, $199 on Growth, and $499 on Scale at the yearly-billed rate, with monthly available at $95, $239, and $599. ISO 27001 cross-mapping ships from Growth. Most platforms in this category are quote-only, and the third-party broker Vendr reported 2026 medians of roughly $15,000 a year for Sprinto, $20,000 for Vanta and Secureframe, and $24,868 for Drata. Certification body fees are separate and are quoted per audit day rather than as a flat fee; published 2026 guides put them commonly between $5,000 and $15,000 for a US company under 50 people.
There are open source ISMS templates, control spreadsheets, and a handful of self-hosted GRC projects, and for a very small scope with engineering time to spare they can work. What they generally do not give you is automated evidence collection from your cloud and identity providers, or a maintained cross-map to other frameworks, so you take on the integration work and the upkeep yourself. The real cost is engineer hours rather than license fees.
Annex A of ISO 27001:2022 contains 93 controls, restructured from the 114 in the 2013 version and grouped into four themes: 37 organizational controls in A.5, 8 people controls in A.6, 14 physical controls in A.7, and 34 technological controls in A.8. Not every control has to apply, but Clause 6.1.3 requires you to justify each exclusion in the Statement of Applicability.
Yes, if it keeps one shared control library rather than a separate checklist per framework. In Complies a control is defined once and marked satisfied against every framework it serves, so teams arriving with a completed SOC 2 typically start ISO 27001 around 60 percent pre-filled. What SOC 2 does not cover is the ISMS machinery itself: scope, Statement of Applicability, internal audit, and management review.
No. An accredited certification body issues the certificate after a stage 1 documentation audit and a stage 2 implementation audit, and certificates run on a three year cycle with annual surveillance audits in between. Software gets the ISMS documented, the controls mapped, and the evidence organized so those audits go smoothly. Any vendor implying it can certify you is describing something it has no authority to do.
Frameworks and guides
ISO 27001 compliance software
SOC 2SOC 2 compliance software
ISO27001Best ISO 27001 Software for Small Teams (2026)
ISO 27001ISO 27001 Checklist: 13 Steps From Scope to Certification
FRAMEWORKSSOC 2 or ISO 27001 First? How to Sequence Them
Run the ISMS, not the spreadsheet
Prices published, $79 to $499 a month. Monthly billing. Start today, no sales call.