ISO 27001 software that turns your certificate into signed deals.

Procurement is gating your contract on ISO 27001. Your prospect wants a security questionnaire back this week. You don't have four months and a six-figure GRC budget. ISO-STANDARD.app is the SME-priced platform that gets you audit-ready and buyer-ready in the same workspace — built by a founder with 25+ years demonstrating trust to enterprise buyers.

The problem with most ISO 27001 tooling

Teams chasing ISO 27001 certification usually fall into one of two traps. The first is the spreadsheet trap: a risk register in one file, a controls log in another, policies in a shared drive, and a Statement of Applicability that nobody can reconcile to either. By audit week, nothing matches and someone is up at 2am copy-pasting.

The second is the enterprise GRC trap: six-figure annual contracts, a four-month implementation, and a consultant on retainer who configures every drop-down. The tool is powerful — but you are now running a GRC project instead of an ISMS.

Neither path is what ISO/IEC 27001 actually asks for. The standard wants evidence that your organisation identifies information security risks, picks treatment options, applies controls from Annex A, documents the decision, and reviews it on a cadence. That is a workflow, not a software stack.

A focused ISO 27001 platform

ISO-STANDARD.app is ISO 27001 software designed around the certification workflow itself. Every screen exists because an auditor will ask about it. Nothing exists that does not earn its place. The result is a tool small and medium teams can adopt in a day and still take to a UKAS-accredited Stage 2 audit.

The risk register, Annex A controls catalogue, policy library, Statement of Applicability and management review pack are pre-loaded and pre-linked. You pick a scope, edit the policies your organisation needs to change, score your top risks, and the SoA writes itself from the treatment decisions you made.

What's in the box

Risk register with the 5×5 model

Inherent and residual scoring, owner, treatment decision (the four Ts), target residual and review date — all in one editable view.

Annex A:2022 controls catalogue

All 93 controls pre-populated. Mark each in or out of scope with a justification; the Statement of Applicability assembles automatically.

Policy library

All mandatory clause 4–10 policies and the supporting topic policies. Branded PDF export with version, approver and effective date in the header.

Risk → control → policy traceability

Every risk links to the controls that treat it; every control links to the policy that documents it. Auditors stop asking "where is the evidence?".

Management review pack

One-click export of the inputs ISO 27001 clause 9.3 expects — KPIs, audit findings, risks, opportunities and changes — ready for the meeting minutes.

Evidence vault

Attach screenshots, policies, training records and supplier reviews to the specific control they evidence. No more "send me your evidence folder" emails.

Who it's for

SaaS startups winning their first enterprise deal

Pain: Procurement is gating the contract on an ISO 27001 certificate and the CTO is the de facto ISMS manager.

With ISO-STANDARD.app: A 60–90 day path to a Stage 2 audit, with the SoA, risk register and policies the auditor expects already in place.

Scale-ups consolidating from spreadsheets

Pain: Three years of patchwork — old register, drift between policies and reality, no clear owner per control.

With ISO-STANDARD.app: One canonical workspace where risks, controls, policies and evidence are linked. Drift becomes visible, not invisible.

MSPs and consultancies running multiple ISMSs

Pain: Every client gets a bespoke spreadsheet stack; handovers are painful and audits look different every time.

With ISO-STANDARD.app: A repeatable workspace per client with the same exports, the same controls catalogue and the same review cadence.

Why teams pick ISO-STANDARD.app over GRC suites

  • One standard, done well. Built for ISO 27001 first, not a 12-framework swiss army knife where 27001 is a tab.
  • No implementation project. Sign up, pick scope, you are working inside the ISMS in under an hour.
  • No consultant lock-in. The data model and exports are standard formats your auditor or your next tool can read.
  • Transparent pricing. No "contact sales" wall. Monthly, cancel any time.

Sample ISO 27001 evidence you can download now

Anonymised samples of Annex A evidence — the exact shape your Stage 2 auditor and your enterprise buyers expect. Download to benchmark your own.

Samples are anonymised for public preview. Real exports carry your workspace branding, signed timestamps and per-control mappings.

Start your ISO 27001 ISMS today

Spin up a free workspace with the risk register, Annex A controls, policies and Statement of Applicability already wired together. Bring an auditor when you are ready.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.