Complies

ISMS · ANNEX A · CERTIFICATION

ISO 27001 software: ISO 27001 compliance software, audit and certification tools for your ISMS

ISO 27001:2022 asks for a working management system, not a binder: a scoped ISMS, a risk assessment you can defend, a Statement of Applicability covering all 93 Annex A controls, internal audits, and management reviews on a cadence. Complies keeps all of it running between audits.

See pricing

From $79/mo · Prices published · No sales call · Monthly billing

SOC 2 · TRUST SERVICES CRITERIA

Audit readiness

0 %

Your auditor makes the final call

Built for teams of 5 to 200

AWS GitHub Google Workspace Slack Jira Azure Okta
ISO 27001

What ISO 27001 software actually does

ISO 27001 software builds and operates the information security management system the standard requires, then keeps the evidence a certification body will sample. Concretely it does three jobs: it tracks the Clause 4 to 10 management requirements as recurring obligations with named owners, it maps your controls against all 93 Annex A controls in ISO/IEC 27001:2022 and keeps the Statement of Applicability current, and it collects the technical evidence behind those controls on a schedule so stage 1 and stage 2 are a review rather than an excavation. Complies does that for companies of 5 to 200 people, where the ISMS belongs to a founder, a head of engineering, or a first security hire rather than a department. The Annex A control set breaks into four themes: 37 organizational controls, 8 people controls, 14 physical controls, and 34 technological controls. Complies holds them in one library alongside SOC 2, GDPR, HIPAA, and PCI DSS, so a control you map once counts everywhere it applies. That cross-mapping is the practical reason teams pick this over an ISO-only tool: if you finished SOC 2 first, roughly 60 percent of your ISO 27001 work is already done, because access control, change management, incident response, and vendor review are the same controls under different numbering. Evidence reads from AWS, GitHub, Google Workspace, Azure, and Okta, configuration only, never your customer data. What is different here is how you buy it. Prices are published at $79 to $499 a month, billing can be monthly, and every framework is cross-mapped from the Growth tier, so there is no demo, no quote, and no annual contract before your first Annex A control is mapped. No software issues an ISO 27001 certificate. An accredited certification body does that after stage 1 and stage 2 audits, and any tool implying otherwise is selling you something it cannot deliver.

Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.

Last updated July 2026

THE THREE JOBS

What ISO 27001 software has to get right

1

The ISMS: Clauses 4 to 10 as obligations with owners

Most teams get Annex A roughly right and fail on the management system around it. Clause 6.1.2 wants a documented risk assessment, Clause 9.2 wants internal audits at planned intervals, Clause 9.3 wants management reviews, and Clause 10 wants nonconformities tracked to closure. Complies turns each one into a recurring obligation with a named owner and a due date, so the ISMS keeps running in month seven instead of going quiet until the surveillance audit is booked.

compliance obligation tracking
2

All 93 Annex A controls, mapped once and counted everywhere

Annex A in ISO 27001:2022 is 93 controls across four themes: 37 organizational, 8 people, 14 physical, 34 technological. Complies holds them in one library shared with SOC 2, GDPR, HIPAA, and PCI DSS, marks each control applicable or justified out, and keeps the Statement of Applicability current as things change. A.5.15 access control is SOC 2 CC6.1, GDPR Article 32, HIPAA 164.312(a), and PCI DSS Requirement 7 wearing different labels, so you maintain it in one place.

control mapping software
3

ISO 27001 audit software: evidence for stage 1 and stage 2

Certification runs in two passes. Stage 1 reviews your documentation, mostly scope, risk assessment, SoA, and policies. Stage 2 tests whether you actually do what you wrote. Complies pulls the technical evidence continuously from your cloud and identity stack, attaches each artifact to the control it proves, and exports an organized pack when the auditor asks for a sample. Internal audit findings and management review minutes live in the same place, because stage 1 asks for those too.

automated evidence collection
COMPARE

Three ways to run ISO 27001, and who each one fits

There are three honest ways to get to an ISO 27001 certificate, and the right one depends on your size and how you prefer to buy software. Here is the comparison including where Complies is the wrong answer.

Dimension Spreadsheet ISMS plus a consultant Sales-led compliance platform Complies
Best for One-off certification with expert hand-holding Funded startups wanting a guided, sales-led rollout Teams of 5 to 200 running ISO 27001 part-time
Annex A coverage A spreadsheet you maintain by hand Full control library, framework packs by tier All 93 controls, cross-mapped from Growth
Statement of Applicability A document that drifts between audits Generated and maintained in-platform Generated from the control library, current by default
Risk assessment A workshop deck, refreshed annually if you remember Built-in risk module, depth varies by platform A register with owners, treatment decisions, and control links
Evidence collection Manual screenshots before each audit Automated across a wide integration set Automated from AWS, GitHub, Google Workspace, Azure, Okta
Reusing SOC 2 work You re-do it, in a second spreadsheet Usually supported, sometimes priced per framework Shared control library, SOC 2 pre-fills roughly 60 percent
How you buy Consultant day rates, scoped per engagement Demo, quote, then an annual contract Published price, sign up, start the same afternoon
Pricing Consultant fees on top of your own hours Quote-only; Vendr put 2026 medians near $15,000 to $25,000 a year Published: $79, $199, $499 per month

Read it honestly. If ISO 27001 is a one-time contractual requirement and you have budget for a consultant to carry it, that route works and we will not pretend otherwise. If you want a dedicated customer success manager walking you through certification, Vanta, Drata, and Sprinto are built for exactly that and do it well. Complies fits the team that wants the ISMS running continuously, at a price they can read, without a sales cycle in front of it. Certification body fees are separate in every column, because the auditor is always a different company. If you are also weighing the sales-led platforms on price, the detailed breakdowns are on Vanta alternatives, Drata alternatives and Sprinto alternatives.

CAPABILITIES

What changes once the ISMS lives in software

The Statement of Applicability stops drifting

The SoA is the document auditors open first, and in a spreadsheet ISMS it is usually months out of date. Here it is generated from the live control library, so a control you retire or add is reflected the same day rather than the week before stage 1.

SOC 2 work pre-fills roughly 60 percent of ISO 27001

Access control, change management, risk assessment, incident response, and vendor review carry across both frameworks. One control library means finishing SOC 2 leaves you with a partially complete Annex A rather than a blank second project.

Internal audits and management reviews actually happen

Clause 9.2 and Clause 9.3 are where small ISMS programs quietly fail, because nothing chases them. They land on the compliance calendar with owners and due dates, and the findings are stored as the evidence stage 1 expects to see.

Evidence collects itself between audits

Access lists, encryption settings, MFA enforcement, and patch cadence read from AWS, GitHub, Google Workspace, Azure, and Okta on a schedule and attach to the Annex A control they prove. Gathering artifacts is the single biggest time sink in a manual certification push.

A readiness score that will not flatter you

One number for where the ISMS stands, plus a ranked gap list naming what is missing and who owns it. It never reads 100, because no tool can promise a certification outcome, and a dashboard that is always green tells you nothing.

A price you can read before you talk to anyone

Starter is $79 a month, Growth $199, Scale $499, all published, with monthly billing available. Quote-only and annual-first is the norm in this category, so a public number is genuinely unusual.

HOW IT WORKS

From signup to a stage 1 ready ISMS

01

Scope the ISMS and pick ISO 27001

Define what the management system covers, then select ISO 27001:2022. Complies generates the Clause 4 to 10 obligations and the full 93 control Annex A set, already cross-mapped against any other framework you carry.

02

Connect the systems your evidence lives in

Point Complies at AWS, GitHub, Google Workspace, Azure, and Okta. It reads configuration rather than customer data and starts attaching artifacts to the controls they prove, on a schedule.

03

Work the risk register and build the SoA

Rate each risk, record a treatment decision, and link it to the control that reduces it. Mark every Annex A control applicable or justified out, and the Statement of Applicability builds itself from those decisions.

04

Run internal audit and management review, then certify

Both land on the calendar with owners. When the readiness score holds and the gap list is clear, export the evidence pack and book stage 1 and stage 2 with an accredited certification body.

FIT

Who this is for, and who it is not

A GOOD FIT WHEN

  • You are 5 to 200 people and ISO 27001 is somebody's second job rather than a department.
  • A customer or a deal is asking for ISO 27001 certification and you need the ISMS standing up now.
  • You already have SOC 2 and refuse to rebuild the same controls in a second spreadsheet.
  • You want the Statement of Applicability and the risk register in one system, current between audits.
  • You would rather read a published price than sit through a demo to find out what it costs.

LOOK ELSEWHERE WHEN

  • You want a consultant to write the ISMS for you. That is a services engagement, and Complies is software.
  • You need a certificate issued. Only an accredited certification body can do that, after stage 1 and stage 2.
  • You run a multi-entity enterprise risk program with a dedicated GRC team, where a configurable suite earns its price.
  • You need CMMC, consent management, cookie banners, DSAR automation, or data mapping. Complies does not do any of those.
QUESTIONS

Common questions about ISO 27001 software

ISO 27001 software builds and runs the information security management system ISO/IEC 27001:2022 requires. It tracks the Clause 4 to 10 management obligations, maps your controls against all 93 Annex A controls, maintains the Statement of Applicability, holds the risk register, and collects the evidence a certification body samples at stage 2. It prepares you for certification; it does not issue the certificate.

No, the standard never mentions software, and small scopes have been certified on spreadsheets and shared drives. Software earns its place when the ISMS has to stay alive between audits: chasing internal audits, keeping the SoA current, re-collecting evidence every cycle, and proving Clause 9 actually ran. If you carry a second framework such as SOC 2, the cross-mapping alone usually pays for the tool.

ISO 27001 audit software covers two different audits. Internal audits under Clause 9.2 are your own check on the ISMS, scheduled and evidenced. The certification audit is external and runs in two stages: stage 1 reviews your documentation, and stage 2 tests whether you do what you documented. Audit software schedules the internal cycle, tracks findings to closure, and organizes the evidence pack the external auditor samples.

Complies publishes its prices: $79 a month on Starter, $199 on Growth, and $499 on Scale at the yearly-billed rate, with monthly available at $95, $239, and $599. ISO 27001 cross-mapping ships from Growth. Most platforms in this category are quote-only, and the third-party broker Vendr reported 2026 medians of roughly $15,000 a year for Sprinto, $20,000 for Vanta and Secureframe, and $24,868 for Drata. Certification body fees are separate and are quoted per audit day rather than as a flat fee; published 2026 guides put them commonly between $5,000 and $15,000 for a US company under 50 people.

There are open source ISMS templates, control spreadsheets, and a handful of self-hosted GRC projects, and for a very small scope with engineering time to spare they can work. What they generally do not give you is automated evidence collection from your cloud and identity providers, or a maintained cross-map to other frameworks, so you take on the integration work and the upkeep yourself. The real cost is engineer hours rather than license fees.

Annex A of ISO 27001:2022 contains 93 controls, restructured from the 114 in the 2013 version and grouped into four themes: 37 organizational controls in A.5, 8 people controls in A.6, 14 physical controls in A.7, and 34 technological controls in A.8. Not every control has to apply, but Clause 6.1.3 requires you to justify each exclusion in the Statement of Applicability.

Yes, if it keeps one shared control library rather than a separate checklist per framework. In Complies a control is defined once and marked satisfied against every framework it serves, so teams arriving with a completed SOC 2 typically start ISO 27001 around 60 percent pre-filled. What SOC 2 does not cover is the ISMS machinery itself: scope, Statement of Applicability, internal audit, and management review.

No. An accredited certification body issues the certificate after a stage 1 documentation audit and a stage 2 implementation audit, and certificates run on a three year cycle with annual surveillance audits in between. Software gets the ISMS documented, the controls mapped, and the evidence organized so those audits go smoothly. Any vendor implying it can certify you is describing something it has no authority to do.

GO DEEPER

Frameworks and guides

Run the ISMS, not the spreadsheet

Prices published, $79 to $499 a month. Monthly billing. Start today, no sales call.