Skip to content

ISO/IEC 27001:2022

Get ready for ISO 27001 certification, with the evidence an auditor asks for already in place.

Regulane loads the whole of ISO/IEC 27001:2022 into your workspace on day one, written in plain language, and tracks every control, clause and piece of evidence against the test a certification auditor applies.

14-day trial · No card required · Priced per workspace, never per seat

Annex A controls, seeded on day one
93
Clause 4–10 requirements
30
Evidence requests in the library
160
Checks run every day
17

01The path to certification

9 steps, in the order an auditor expects them.

The ISO module shows one live step at a time, with its real numbers, and keeps the rest in view. These are the steps it walks you through.

  1. 01

    Scope your ISMS

    Record your industry and size. Everything after this is filtered by it.

  2. 02

    Publish your core policies

    Adopt the starter set, edit it to fit and publish. Training and attestations hang off these.

  3. 03

    Give the controls owners

    A control with no owner is a control nobody is doing. Assign the work before evidencing it.

  4. 04

    Attach evidence to controls

    The document, screenshot or record that proves each control is real.

  5. 05

    Build the risk register

    Log your risks and give each one a treatment plan. An auditor opens this first.

  6. 06

    Train your team

    Everyone with access completes awareness training, and the record is kept.

  7. 07

    Run an internal audit

    Find your own gaps before the certification body does. It is required, not optional.

  8. 08

    Meet clauses 4 to 10

    Scope, leadership, risk assessment, internal audit, management review and improvement: the management system itself.

  9. 09

    Complete the applicable controls

    Each applicable Annex A control implemented, at maturity 3 or more, with current evidence and no failing check.

When every step is done, including every applicable control and clauses 4 to 10, the module says the next move is booking a certification body.

02Annex A

All 93 controls, and a readiness figure you can defend.

Each control carries a status, a maturity, an owner, its evidence and the result of any check that covers it.

A control counts towards readiness only when it is completed, at maturity 3 or more, has current evidence and no failing check. A file counts as evidence once a manager or admin has accepted it; a description or a link alone does not.

Organizational controls
37
People controls
8
Physical controls
14
Technical controls
34
ISO 27001 · Controls
Compliance / ISO 27001
ISO 27001
ISO 27001:2022 Annex A controls, evidence and readiness.
Implementation status
92 applicable Annex A controls · 1 excluded in the Statement of Applicability
Completed 57 In progress 21 Not started 14

A control counts when it is completed, at maturity 3 or more, has current evidence and no failing check.

Controls
Filter by theme, status, evidence or applicability
ControlTitle
A.5.1Policies for information securityCompletedCurrent
A.5.15Access controlCompletedCurrent
A.5.18Access rightsIn progressExpired
A.5.19Information security in supplier relationshipsCompletedCurrent
A.6.3Information security awareness, education and trainingCompletedCurrent
A.8.5Secure authenticationIn progressDue soon
A.8.15LoggingNot startedMissing

03Clauses 4 to 10

The management system, which an auditor tests before any control.

30 requirements with owners and status, 13 of them naming the documented information the standard makes mandatory. A readiness figure built on Annex A alone says nothing about any of this.

  • Clause 44 requirements

    Context of the organization

    • 4.1 Understanding the organization and its context
    • 4.2 Understanding the needs and expectations of interested parties
    • 4.3 Determining the scope of the information security management system
    • and 1 more
  • Clause 53 requirements

    Leadership

    • 5.1 Leadership and commitment
    • 5.2 Policy
    • 5.3 Organizational roles, responsibilities and authorities
  • Clause 65 requirements

    Planning

    • 6.1.1 Actions to address risks and opportunities — general
    • 6.1.2 Information security risk assessment
    • 6.1.3 Information security risk treatment
    • and 2 more
  • Clause 77 requirements

    Support

    • 7.1 Resources
    • 7.2 Competence
    • 7.3 Awareness
    • and 4 more
  • Clause 83 requirements

    Operation

    • 8.1 Operational planning and control
    • 8.2 Information security risk assessment
    • 8.3 Information security risk treatment
  • Clause 96 requirements

    Performance evaluation

    • 9.1 Monitoring, measurement, analysis and evaluation
    • 9.2.1 Internal audit — general
    • 9.2.2 Internal audit programme
    • and 3 more
  • Clause 102 requirements

    Improvement

    • 10.1 Continual improvement
    • 10.2 Nonconformity and corrective action

04Statement of Applicability

Every control included or excluded, with the reason written down.

Mark each Annex A control applicable or excluded, record the justification and the implementation status, and export the Statement of Applicability to PDF or CSV. Excluded controls leave the readiness figure, and a daily check fails while any control has no recorded reason.

ISO 27001 · Readiness · Northwind Payments
Organizational26/37
People6/8
Physical9/14
Technical16/34
Statement of ApplicabilityExport PDF · CSV
ControlImplementation or justification
A.7.4Physical security monitoringImplemented
A.8.5Secure authenticationIn progress
A.7.14Secure disposal or re-use of equipmentImplemented
A.8.30Outsourced developmentNo software development is outsourced
Evidence library: 160 requestsDaily checks: 17Auditor access: read-only, no seat used

05Evidence that stays current

The evidence library, and the checks that notice when it lapses.

160 evidence requests cover every clause 4–10 requirement and all 93 Annex A controls. Each says what to provide, gives examples an auditor accepts, names its owner and how often it must be refreshed. Evidence expires on that schedule, and the owner is reminded first.

The 17 daily checks

Each states its rule and lists exactly what fails it
  • Management system requirements implemented

    Every requirement of clauses 4 to 10 is marked implemented.

  • Statement of Applicability is justified6.1.3

    Every Annex A control has a recorded reason for including or excluding it.

  • Published policies are approvedA.5.1 · 5.2

    Every published policy records who approved it and when.

  • Policy reviews are up to dateA.5.1

    Every published policy has a next review date that has not passed.

  • Staff have acknowledged the policiesA.5.1 · 7.3

    Every active member has acknowledged every published policy.

  • Security awareness training is currentA.6.3 · 7.2 · 7.3

    Every active member passed a security training module in the last 12 months.

  • Asset inventory is kept up to dateA.5.9

    An asset inventory exists and was updated in the last 12 months.

  • Risk register is reviewed6.1.2 · 8.2

    Risks are recorded and the register was reviewed in the last 12 months.

  • Every open risk has an owner6.1.2

    Each open risk is assigned to a named owner.

  • High risks have a treatment plan6.1.3 · 8.3

    Each open risk scoring 15 or more has a mitigation plan or a recorded treatment.

  • Suppliers are assessed every yearA.5.19 · A.5.22

    Each current supplier has a security assessment from the last 12 months.

  • Data-processing agreements are in placeA.5.20 · A.5.34

    Each supplier handling personal or confidential data has a data-processing agreement recorded.

  • Internal audit completed this year9.2.1 · 9.2.2

    At least one audit was completed in the last 12 months.

  • Corrective actions are on time10.2

    No open corrective action is past its due date.

  • Lessons are recorded for closed incidentsA.5.27

    Every incident closed in the last 12 months records the lessons learned.

  • Access reviewed in the last six monthsA.5.18

    An access review, with every item decided, was completed in the last six months.

  • Breach reports are on timeA.5.5 · A.5.26

    No statutory breach report (CERT-In, DPDP, GDPR) is past its deadline or was made after it.

Plus read-only GitHub checks: two-factor authentication required and in use, the number of owners, outside collaborators, and whether default branches require a pull request. A check with nothing to examine counts as evidence for nothing.

06Audit preparation

Find the gaps yourself, then rehearse the interview.

  • Internal audit checklist

    Generated from your applicable Annex A controls. Findings are raised from checklist items, each with its corrective action.

  • Corrective actions that close properly

    A corrective action is verified and closed by a manager who neither did the work nor is assigned it, with an effectiveness rating.

  • Audit Rehearsal

    Industry first

    A mock certification interview for each control owner, every answer checked against your records. Industry first.

  • Auditor access

    Read-only access to the evidence, the checks and the control mappings. An auditor never takes a seat from your plan.

  • Document check

    Check a policy against an ISO 27001 checklist for its type. Every quoted passage is found in your document by code before it is shown.

  • Questionnaire answers

    Security questionnaires drafted from your published policies, controls and approved answers, each answer citing the records it rests on.

07Plainly

What Regulane does not do for ISO 27001.

Written down so nobody finds out halfway through a trial.

Regulane does not

  • Issue certifications. It is not a certification body or an accredited auditor; certification follows an accredited body’s own audit.
  • Collect evidence from AWS, Azure, Google Cloud or Microsoft 365, or run agents on servers and laptops.
  • Reproduce the text of the standard. Everything is described in plain language; hold your own copy if you are certifying.
  • Cover SOC 2, PCI DSS or HIPAA as dedicated control sets today. ISO 27001:2022 and the DPDP Act are the two that ship.
  • Hold an ISO 27001 certification of its own at this time.

Questions

ISO 27001, answered plainly.

Does Regulane include all the ISO 27001:2022 Annex A controls?

Yes. All 93 Annex A controls of ISO/IEC 27001:2022 are loaded into every workspace on day one, each with plain-language guidance and what an auditor will check. The clause 4 to 10 management system requirements are there too, as 30 trackable requirements.

Can Regulane certify us for ISO 27001?

No. Certification is awarded by an accredited certification body after its own audit. Regulane is not a certification body or an accredited auditor; it gets your management system, controls and evidence ready for that audit, and lets you rehearse the interviews first.

Can we export a Statement of Applicability?

Yes. Each Annex A control is marked applicable or excluded with its justification and implementation status, and the Statement of Applicability exports to PDF or CSV. Excluded controls leave the readiness figures.

Does Regulane collect ISO 27001 evidence automatically from AWS, Azure or Google Cloud?

No. Regulane does not connect to cloud infrastructure. Its automated evidence comes from 17 daily checks over your own records in Regulane and read-only GitHub checks; everything else is handed in by a person and accepted by a manager or admin.

How does Audit Rehearsal help with an ISO 27001 audit?

It runs a mock certification interview with each control owner on the clauses and controls they own, and checks every answer against your records. A claim your records cannot back is shown as not backed, so you find it before the auditor does. It gives no score and no prediction of the audit result.

Do we still need a copy of the standard?

Yes, if you are certifying. Regulane describes every clause and control in plain language and says what an auditor will check, but it does not reproduce the text of ISO/IEC 27001:2022, which is copyrighted. Organisations certifying should hold a copy of the standard and Amendment 1:2024.

Regulation changes every week. Your compliance programme should know what changed, and what to do next.

14-day trial · No card required · Per workspace, never per seat