Software versus spreadsheets
Spreadsheets are not the enemy. They are an excellent place to think and a poor place to keep a management system operating for three years. This page sets out where the line usually falls, without pretending the answer is always software.
Where spreadsheets hold up
For a first risk assessment, a gap analysis or a control list on one standard, a spreadsheet is faster than any tool. It is flexible, everyone can use it, and it costs nothing. Plenty of organisations reach their first certificate this way and are right to.
Where it starts to cost more than it saves
The difficulty is not the first version; it is the second year. A spreadsheet stores values, not relationships. It cannot tell you that a control has no owner, that its evidence is fourteen months old, that the same control appears in three tabs with different wording, or that an audit finding was never closed. Each of those is discovered by a person looking, and people stop looking when the work is busy.
| Consideration | Spreadsheets and documents | A linked management system |
|---|---|---|
| Setup speed | Immediate — open a file and start | Import existing records, then map to standards |
| Traceability | Manual cross-references between files | Risk, control, owner and evidence linked as records |
| Ownership | A name typed in a cell | Named owner with reminders until the work closes |
| Evidence freshness | Visible only if someone checks the date | Review interval per item; staleness surfaces itself |
| Multiple standards | A separate workbook per standard, re-keyed | One control mapped to every standard it satisfies |
| Audit preparation | Collate and re-check before each audit | Export the current position at any time |
| Buyer questionnaires | Rewritten from memory each time | Answered from the same controls and evidence |
| Cost | No licence; time cost rises with scope | Published subscription; time cost flatter as scope grows |
| Best suited to | One standard, small scope, one owner | Several standards, several owners, recurring assurance |
A reasonable test
Ask three questions of your current spreadsheet. Who owns control A.5.15 and when did they last evidence it? Which other standards depend on that same control? What is still open from the last internal audit? If answering takes longer than a minute, the cost has moved from the tool to the searching. If it does not, keep the spreadsheet.
If you do want the linked version, the risk, controls and evidence page describes the record structure, and the risk register template is free either way.
Deciding how to run it
Where spreadsheets hold up, and where traceability breaks.
One register across standards, or one system per standard.
What each approach leaves behind after certification.
Scope, configuration effort and who actually operates it.
Answers buyers, procurement and auditors want
Can you certify to ISO 27001 using spreadsheets?+
Yes. The standards require records, not software. Organisations certify with documents and spreadsheets every year. The question is what maintaining them costs once the system has to keep running between audits.
When are spreadsheets genuinely fine?+
A single standard, a small scope, one person doing the work, and an audit date in the near future. The overhead of any tool is hard to justify against that.
What breaks first?+
Usually ownership and freshness. Nothing in a spreadsheet chases the person responsible, and nothing marks evidence as out of date, so gaps appear quietly and are found during the audit.
See how your existing risks, controls and evidence could become one integrated management system
Bring what you already have — a part-finished risk register, a folder of policies, last year's audit findings — and see it mapped across the standards you need.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.