ISO/IEC 27001:2022
Get ready for ISO 27001 certification, with the evidence an auditor asks for already in place.
Regulane loads the whole of ISO/IEC 27001:2022 into your workspace on day one, written in plain language, and tracks every control, clause and piece of evidence against the test a certification auditor applies.
14-day trial · No card required · Priced per workspace, never per seat
- Annex A controls, seeded on day one
- 93
- Clause 4–10 requirements
- 30
- Evidence requests in the library
- 160
- Checks run every day
- 17
01The path to certification
9 steps, in the order an auditor expects them.
The ISO module shows one live step at a time, with its real numbers, and keeps the rest in view. These are the steps it walks you through.
- 01
Scope your ISMS
Record your industry and size. Everything after this is filtered by it.
- 02
Publish your core policies
Adopt the starter set, edit it to fit and publish. Training and attestations hang off these.
- 03
Give the controls owners
A control with no owner is a control nobody is doing. Assign the work before evidencing it.
- 04
Attach evidence to controls
The document, screenshot or record that proves each control is real.
- 05
Build the risk register
Log your risks and give each one a treatment plan. An auditor opens this first.
- 06
Train your team
Everyone with access completes awareness training, and the record is kept.
- 07
Run an internal audit
Find your own gaps before the certification body does. It is required, not optional.
- 08
Meet clauses 4 to 10
Scope, leadership, risk assessment, internal audit, management review and improvement: the management system itself.
- 09
Complete the applicable controls
Each applicable Annex A control implemented, at maturity 3 or more, with current evidence and no failing check.
When every step is done, including every applicable control and clauses 4 to 10, the module says the next move is booking a certification body.
02Annex A
All 93 controls, and a readiness figure you can defend.
Each control carries a status, a maturity, an owner, its evidence and the result of any check that covers it.
A control counts towards readiness only when it is completed, at maturity 3 or more, has current evidence and no failing check. A file counts as evidence once a manager or admin has accepted it; a description or a link alone does not.
- Organizational controls
- 37
- People controls
- 8
- Physical controls
- 14
- Technical controls
- 34
A control counts when it is completed, at maturity 3 or more, has current evidence and no failing check.
| Control | Title | Theme | Status | Maturity | Evidence |
|---|---|---|---|---|---|
| A.5.1 | Policies for information securityCompletedCurrent | Organizational | Completed | Current | |
| A.5.15 | Access controlCompletedCurrent | Organizational | Completed | Current | |
| A.5.18 | Access rightsIn progressExpired | Organizational | In progress | Expired | |
| A.5.19 | Information security in supplier relationshipsCompletedCurrent | Organizational | Completed | Current | |
| A.6.3 | Information security awareness, education and trainingCompletedCurrent | People | Completed | Current | |
| A.8.5 | Secure authenticationIn progressDue soon | Technical | In progress | Due soon | |
| A.8.15 | LoggingNot startedMissing | Technical | Not started | Missing |
03Clauses 4 to 10
The management system, which an auditor tests before any control.
30 requirements with owners and status, 13 of them naming the documented information the standard makes mandatory. A readiness figure built on Annex A alone says nothing about any of this.
- Clause 44 requirements
Context of the organization
- 4.1 Understanding the organization and its context
- 4.2 Understanding the needs and expectations of interested parties
- 4.3 Determining the scope of the information security management system
- and 1 more
- Clause 53 requirements
Leadership
- 5.1 Leadership and commitment
- 5.2 Policy
- 5.3 Organizational roles, responsibilities and authorities
- Clause 65 requirements
Planning
- 6.1.1 Actions to address risks and opportunities — general
- 6.1.2 Information security risk assessment
- 6.1.3 Information security risk treatment
- and 2 more
- Clause 77 requirements
Support
- 7.1 Resources
- 7.2 Competence
- 7.3 Awareness
- and 4 more
- Clause 83 requirements
Operation
- 8.1 Operational planning and control
- 8.2 Information security risk assessment
- 8.3 Information security risk treatment
- Clause 96 requirements
Performance evaluation
- 9.1 Monitoring, measurement, analysis and evaluation
- 9.2.1 Internal audit — general
- 9.2.2 Internal audit programme
- and 3 more
- Clause 102 requirements
Improvement
- 10.1 Continual improvement
- 10.2 Nonconformity and corrective action
04Statement of Applicability
Every control included or excluded, with the reason written down.
Mark each Annex A control applicable or excluded, record the justification and the implementation status, and export the Statement of Applicability to PDF or CSV. Excluded controls leave the readiness figure, and a daily check fails while any control has no recorded reason.
| Control | Applicability | Implementation or justification |
|---|---|---|
| A.7.4Physical security monitoring | Applicable | Implemented |
| A.8.5Secure authentication | Applicable | In progress |
| A.7.14Secure disposal or re-use of equipment | Applicable | Implemented |
| A.8.30Outsourced development | Excluded | No software development is outsourced |
05Evidence that stays current
The evidence library, and the checks that notice when it lapses.
160 evidence requests cover every clause 4–10 requirement and all 93 Annex A controls. Each says what to provide, gives examples an auditor accepts, names its owner and how often it must be refreshed. Evidence expires on that schedule, and the owner is reminded first.
The 17 daily checks
Each states its rule and lists exactly what fails it- Management system requirements implemented
Every requirement of clauses 4 to 10 is marked implemented.
- Statement of Applicability is justified6.1.3
Every Annex A control has a recorded reason for including or excluding it.
- Published policies are approvedA.5.1 · 5.2
Every published policy records who approved it and when.
- Policy reviews are up to dateA.5.1
Every published policy has a next review date that has not passed.
- Staff have acknowledged the policiesA.5.1 · 7.3
Every active member has acknowledged every published policy.
- Security awareness training is currentA.6.3 · 7.2 · 7.3
Every active member passed a security training module in the last 12 months.
- Asset inventory is kept up to dateA.5.9
An asset inventory exists and was updated in the last 12 months.
- Risk register is reviewed6.1.2 · 8.2
Risks are recorded and the register was reviewed in the last 12 months.
- Every open risk has an owner6.1.2
Each open risk is assigned to a named owner.
- High risks have a treatment plan6.1.3 · 8.3
Each open risk scoring 15 or more has a mitigation plan or a recorded treatment.
- Suppliers are assessed every yearA.5.19 · A.5.22
Each current supplier has a security assessment from the last 12 months.
- Data-processing agreements are in placeA.5.20 · A.5.34
Each supplier handling personal or confidential data has a data-processing agreement recorded.
- Internal audit completed this year9.2.1 · 9.2.2
At least one audit was completed in the last 12 months.
- Corrective actions are on time10.2
No open corrective action is past its due date.
- Lessons are recorded for closed incidentsA.5.27
Every incident closed in the last 12 months records the lessons learned.
- Access reviewed in the last six monthsA.5.18
An access review, with every item decided, was completed in the last six months.
- Breach reports are on timeA.5.5 · A.5.26
No statutory breach report (CERT-In, DPDP, GDPR) is past its deadline or was made after it.
Plus read-only GitHub checks: two-factor authentication required and in use, the number of owners, outside collaborators, and whether default branches require a pull request. A check with nothing to examine counts as evidence for nothing.
06Audit preparation
Find the gaps yourself, then rehearse the interview.
Internal audit checklist
Generated from your applicable Annex A controls. Findings are raised from checklist items, each with its corrective action.
Corrective actions that close properly
A corrective action is verified and closed by a manager who neither did the work nor is assigned it, with an effectiveness rating.
Audit Rehearsal
Industry firstA mock certification interview for each control owner, every answer checked against your records. Industry first.
Auditor access
Read-only access to the evidence, the checks and the control mappings. An auditor never takes a seat from your plan.
Document check
Check a policy against an ISO 27001 checklist for its type. Every quoted passage is found in your document by code before it is shown.
Questionnaire answers
Security questionnaires drafted from your published policies, controls and approved answers, each answer citing the records it rests on.
07Plainly
What Regulane does not do for ISO 27001.
Written down so nobody finds out halfway through a trial.
Regulane does not
- Issue certifications. It is not a certification body or an accredited auditor; certification follows an accredited body’s own audit.
- Collect evidence from AWS, Azure, Google Cloud or Microsoft 365, or run agents on servers and laptops.
- Reproduce the text of the standard. Everything is described in plain language; hold your own copy if you are certifying.
- Cover SOC 2, PCI DSS or HIPAA as dedicated control sets today. ISO 27001:2022 and the DPDP Act are the two that ship.
- Hold an ISO 27001 certification of its own at this time.
Questions
ISO 27001, answered plainly.
Does Regulane include all the ISO 27001:2022 Annex A controls?
Yes. All 93 Annex A controls of ISO/IEC 27001:2022 are loaded into every workspace on day one, each with plain-language guidance and what an auditor will check. The clause 4 to 10 management system requirements are there too, as 30 trackable requirements.
Can Regulane certify us for ISO 27001?
No. Certification is awarded by an accredited certification body after its own audit. Regulane is not a certification body or an accredited auditor; it gets your management system, controls and evidence ready for that audit, and lets you rehearse the interviews first.
Can we export a Statement of Applicability?
Yes. Each Annex A control is marked applicable or excluded with its justification and implementation status, and the Statement of Applicability exports to PDF or CSV. Excluded controls leave the readiness figures.
Does Regulane collect ISO 27001 evidence automatically from AWS, Azure or Google Cloud?
No. Regulane does not connect to cloud infrastructure. Its automated evidence comes from 17 daily checks over your own records in Regulane and read-only GitHub checks; everything else is handed in by a person and accepted by a manager or admin.
How does Audit Rehearsal help with an ISO 27001 audit?
It runs a mock certification interview with each control owner on the clauses and controls they own, and checks every answer against your records. A claim your records cannot back is shown as not backed, so you find it before the auditor does. It gives no score and no prediction of the audit result.
Do we still need a copy of the standard?
Yes, if you are certifying. Regulane describes every clause and control in plain language and says what an auditor will check, but it does not reproduce the text of ISO/IEC 27001:2022, which is copyrighted. Organisations certifying should hold a copy of the standard and Amendment 1:2024.
Keep reading
- DPDP ActThe Data Fiduciary obligations, the processing register, requests and breaches.
- SecurityWhere your data lives, what the code enforces, and what we do not claim.
- Regulatory IntelligenceWhich regulatory changes name something you run, and why.
- PricingPer workspace, never per seat. Published, not quoted.
Regulation changes every week. Your compliance programme should know what changed, and what to do next.
14-day trial · No card required · Per workspace, never per seat
