ISO 27001 readiness software for SMEs — audit-ready without the four-month project

You have a deal gated on ISO 27001, a team of five to fifty, and no ISMS manager. This is the workspace that takes you from a blank page to a Stage 2 audit: risk register, Annex A controls, policies, Statement of Applicability and evidence — one shared register, one shared control catalogue, one evidence base.

Where SMEs get stuck

The certificate isn't the hard part. Assembling consistent evidence with a day job is.

  • Procurement wants the certificate this quarter, and the CTO is also the de facto ISMS manager.
  • Risk lives in one spreadsheet, controls in another, policies in a shared drive — and the Statement of Applicability reconciles to neither.
  • Enterprise GRC quotes land at five or six figures with a four-month implementation and a consultant on retainer.
  • Nobody knows which of the 93 Annex A controls are actually in scope, or what evidence the auditor will ask for.
Product walkthrough

See the workspace in 24 seconds

A single pass through the workspace: create risks, treat them with Annex A controls, attach evidence, and export the Statement of Applicability and management review pack your auditor expects.

  1. 1
    Risk register

    Score inherent and residual risk on the 5×5 model, pick one of the four Ts, set an owner and a review date.

  2. 2
    Annex A control catalogue

    All 93 ISO 27001:2022 controls pre-loaded. Mark in or out of scope with a justification — that justification becomes your SoA.

  3. 3
    Policy library

    Clause 4–10 policies plus topic policies, with AI guided fill for the organisation-specific sections and branded PDF export.

  4. 4
    Evidence vault

    Attach access reviews, scan reports, training records and supplier reviews to the exact control they evidence.

  5. 5
    Control health & Fix it

    See which controls are failing or stale, then generate a plain-English remediation plan with owner, priority and suggested evidence.

  6. 6
    Audit & management review

    Plan internal audits, log findings, drive CAPAs, and export the clause 9.3 management review pack.

Spreadsheets vs ISO-STANDARD.app

The jobSpreadsheets & shared driveISO-STANDARD.app
Risk registerOne tab per year, formulas drift, no history of who changed a score.Versioned register with owners, review dates and an append-only audit trail.
Statement of ApplicabilityHand-maintained and out of sync with the register by audit week.Assembles itself from your in/out-of-scope decisions and justifications.
EvidenceA folder of screenshots nobody can map back to a control.Evidence attached to the control it proves, with dates and expiry reminders.
PoliciesVersion confusion — v3_final_FINAL.docx.Single source of truth with approver, effective date and acknowledgement tracking.
Audit weekSomeone reconciling four files at 2am.Export the pack; every claim traces risk → control → policy → evidence.

Spreadsheets are fine for a 10-risk pilot. They stop being fine the moment an auditor asks for traceability.

Free readiness assessment

Score your ISO 27001 readiness in about 20 minutes — free

Start a workspace, load the Annex A:2022 catalogue and mark what you already have in place. Control Health scores your gaps immediately, so you get a real readiness picture instead of a sales-qualified questionnaire.

  • Annex A coverage: implemented, partial, missing
  • Mandatory clause 4–10 documents you still owe
  • Risk register maturity and treatment coverage
  • Evidence gaps ranked by audit impact

Instant download, no sales call. We reply within one business day.

What it costs

Published pricing, monthly, cancel any time. No 'contact sales' wall.

Starter
£79/mo

First ISMS: risks, assets, controls, policies.

Growth
£199/mo

Audit programme, CAPA, SoA, Trust Center and AI ‘Fix this’ remediation.

Business
£399/mo

Microsoft 365 evidence automation, Jira and service-desk integrations, SSO.

Full feature-by-feature breakdown on the pricing page. No sales call required to start.

MM
Built by Michael McCarroll
25+ years · IT governance · Information security · AI

I've spent 25 years aligning technology, controls and compliance with what the business is actually trying to do — mostly for organisations without a GRC department. Every screen in this product exists because an auditor or an enterprise buyer asked for it, and nothing exists because it demoed well.

Read the founder story

Where to go next

Compare the wider platform on ISO 27001 software, see the full GRC workspace, or read the certification cost guide.

Answers buyers, procurement and auditors want

How long does ISO 27001 readiness take with this?+

Most SMEs reach a credible Stage 1 position in 30–60 days and Stage 2 in 60–120 days, depending on how much evidence already exists. The workspace is usable the hour you sign up — there is no implementation project.

Do you issue the certificate?+

No. Certification is issued by an accredited certification body after Stage 1 and Stage 2 audits. This platform gets your ISMS, evidence and exports into the shape those auditors expect.

Is the readiness assessment really free?+

Yes. You start a workspace, load the Annex A catalogue and get your gap score without a sales call or a card.

Can we move off spreadsheets we already maintain?+

Yes — CSV import with templates covers risks, assets, controls, policies and evidence, so your existing register comes across in minutes.

Start your ISO 27001 readiness today

Load the catalogue, score your gaps, and see exactly what stands between you and a Stage 2 audit — before you spend a penny on a certification body.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.