All frameworks
ISOAnnex A · ISMS

ISO 27001 compliance

The global baseline for information security.

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It defines how an organisation establishes, operates and continually improves security through risk management and a set of Annex A controls.

Start from the basics

The standard

ISO/IEC 27001:2022 — Information Security Management

Who needs it

Any organisation that wants a recognised, auditable security posture — especially those selling to enterprises or expanding internationally, where an ISO 27001 certificate is often a procurement requirement.

93

Annex A controls, pre-mapped

The basics

What is ISO 27001?

ISO/IEC 27001 is the world's most recognised information-security standard. Rather than handing you a checklist of technologies, it asks you to build a living management system — an ISMS — that identifies your risks, decides how to treat them, and proves you keep doing so over time.

Think of it less as a one-off exam and more as a way of running security on purpose. You define what you're protecting, assess what could go wrong, apply the Annex A controls that make sense, and review the whole thing regularly. The 2022 revision modernised those controls for cloud, threat intelligence and secure development.

Why it matters

What ISO 27001 does for your business

It opens doors

For enterprise and international deals, an ISO 27001 certificate is often a hard requirement — no certificate, no RFP. It's the credential that gets you shortlisted.

It's a universal language

Recognised in over 150 countries, it travels. One certification reassures buyers across Europe, the Middle East and APAC without re-explaining your security each time.

It makes you genuinely safer

Done properly, the risk-based approach forces you to find and fix real gaps — so it's not just a badge on the website, it's fewer incidents and calmer nights.

What it covers

Risk-based ISMS

A documented management system built around identifying, treating and monitoring information-security risks.

Annex A controls

93 controls across organisational, people, physical and technological themes (2022 revision).

Statement of Applicability

The SoA justifies which controls apply, why, and their implementation status — the spine of your audit.

Continual improvement

Internal audits, management review and corrective actions keep the ISMS living, not shelf-ware.

The hard way

Built by hand, an ISMS becomes a graveyard of spreadsheets, screenshots and out-of-date policies — and the annual audit turns into a month of panic. Most of that work is repetitive, and repetitive work is exactly what should be automated away.

The easier way, with Compliance One

  • Generates your Statement of Applicability from a single control set, pre-mapped to the 2022 Annex A.
  • Collects control evidence automatically from your cloud and identity stack.
  • Tracks risk treatment end-to-end and links each risk to the controls that mitigate it.
  • Produces internal-audit and management-review packages your certification body will recognise.

Do it once, reuse it everywhere. Evidence you collect for ISO 27001is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

How long does ISO 27001 take?
Done by hand, six months to a year is common. With a platform that provisions your controls, policies and Statement of Applicability up front and collects evidence automatically, teams get audit-ready far faster.
Is it Type I / Type II like SOC 2?
No — ISO 27001 is a certification: an initial Stage 1 and Stage 2 audit, then annual surveillance audits and a full recertification every three years. It's designed to be ongoing, not a one-time snapshot.
We already have SOC 2 — do we start over?
Not at all. The two overlap heavily. Compliance One maps your existing evidence across both, so ISO 27001 becomes mostly filling gaps rather than starting fresh.
What exactly is the Statement of Applicability?
The SoA lists every Annex A control, whether it applies to you, why, and its status — the backbone of your audit. Compliance One generates it for you.

Ready to tackle ISO 27001?

See exactly how Compliance One maps ISO 27001 to your environment in a 30-minute walkthrough — and how much of it we handle for you.