ISO 27001 software that turns your certificate into signed deals.
Procurement is gating your contract on ISO 27001. Your prospect wants a security questionnaire back this week. You don't have four months and a six-figure GRC budget. ISO-STANDARD.app is the SME-priced platform that gets you audit-ready and buyer-ready in the same workspace — built by a founder with 25+ years demonstrating trust to enterprise buyers.
The problem with most ISO 27001 tooling
Teams chasing ISO 27001 certification usually fall into one of two traps. The first is the spreadsheet trap: a risk register in one file, a controls log in another, policies in a shared drive, and a Statement of Applicability that nobody can reconcile to either. By audit week, nothing matches and someone is up at 2am copy-pasting.
The second is the enterprise GRC trap: six-figure annual contracts, a four-month implementation, and a consultant on retainer who configures every drop-down. The tool is powerful — but you are now running a GRC project instead of an ISMS.
Neither path is what ISO/IEC 27001 actually asks for. The standard wants evidence that your organisation identifies information security risks, picks treatment options, applies controls from Annex A, documents the decision, and reviews it on a cadence. That is a workflow, not a software stack.
A focused ISO 27001 platform
ISO-STANDARD.app is ISO 27001 software designed around the certification workflow itself. Every screen exists because an auditor will ask about it. Nothing exists that does not earn its place. The result is a tool small and medium teams can adopt in a day and still take to a UKAS-accredited Stage 2 audit.
The risk register, Annex A controls catalogue, policy library, Statement of Applicability and management review pack are pre-loaded and pre-linked. You pick a scope, edit the policies your organisation needs to change, score your top risks, and the SoA writes itself from the treatment decisions you made.
What's in the box
Risk register with the 5×5 model
Annex A:2022 controls catalogue
Policy library
Risk → control → policy traceability
Management review pack
Evidence vault
Who it's for
Pain: Procurement is gating the contract on an ISO 27001 certificate and the CTO is the de facto ISMS manager.
With ISO-STANDARD.app: A 60–90 day path to a Stage 2 audit, with the SoA, risk register and policies the auditor expects already in place.
Pain: Three years of patchwork — old register, drift between policies and reality, no clear owner per control.
With ISO-STANDARD.app: One canonical workspace where risks, controls, policies and evidence are linked. Drift becomes visible, not invisible.
Pain: Every client gets a bespoke spreadsheet stack; handovers are painful and audits look different every time.
With ISO-STANDARD.app: A repeatable workspace per client with the same exports, the same controls catalogue and the same review cadence.
Why teams pick ISO-STANDARD.app over GRC suites
- One standard, done well. Built for ISO 27001 first, not a 12-framework swiss army knife where 27001 is a tab.
- No implementation project. Sign up, pick scope, you are working inside the ISMS in under an hour.
- No consultant lock-in. The data model and exports are standard formats your auditor or your next tool can read.
- Transparent pricing. No "contact sales" wall. Monthly, cancel any time.
Sample ISO 27001 evidence you can download now
Anonymised samples of Annex A evidence — the exact shape your Stage 2 auditor and your enterprise buyers expect. Download to benchmark your own.
Reviewer sign-off across AWS, GitHub, Okta, RDS, Datadog, PagerDuty — with findings, remediation and attestation.
PDF · ISO 27001 A.5.15–18 · SOC 2 CC6.2/6.3 · Cyber Essentials
100% MFA coverage across the IdP and all federated SaaS, phishing-resistant factor distribution and exception log.
PDF · ISO 27001 A.5.17/A.8.5 · SOC 2 CC6.1 · PCI Req 8.4
Monthly authenticated ASV scan of the production perimeter with SLA-tracked remediation and risk acceptance log.
PDF · ISO 27001 A.8.8 · SOC 2 CC7.1 · PCI Req 11.3 · CE+
Right-sized supplier assessment covering certifications, data protection, access, incident notification and exit plan.
PDF · ISO 27001 A.5.19–22 · SOC 2 CC9.2 · GDPR Art. 28
Successful production database restore into an isolated VPC, RTO/RPO measured against policy with SRE sign-off.
PDF · ISO 27001 A.8.13 · ISO 20000-1 · SOC 2 A1.2
100% completion register with quiz scores and simulated-phishing outcomes for the annual awareness programme.
PDF · ISO 27001 A.6.3 · SOC 2 CC1.4 · GDPR · Cyber Essentials
Facilitated ransomware tabletop: participants, decisions, target vs observed timings, gaps identified and closed.
PDF · ISO 27001 A.5.24–27 · SOC 2 CC7.4 · PCI Req 12.10
Samples are anonymised for public preview. Real exports carry your workspace branding, signed timestamps and per-control mappings.
Start your ISO 27001 ISMS today
Spin up a free workspace with the risk register, Annex A controls, policies and Statement of Applicability already wired together. Bring an auditor when you are ready.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.