ISO 27001 isn’t just 93 controls, it’s a management system you have to keep alive: a risk assessment, a Statement of Applicability, and surveillance audits every single year. Compyl’s ISO 27001 compliance software runs the ISMS continuously, so it stays current, evidenced, and certification-ready.
Most ISO 27001 programs slow to a crawl after certification, the Statement of Applicability drifts from reality, evidence scatters across teams, and the next surveillance audit turns into a scramble to rebuild what should have been running all along.
Your risk assessment and Statement of Applicability are point-in-time documents. Controls change; the paperwork doesn’t, until an auditor finds the gap.
Annual surveillance audits and a three-year recertification mean the ISMS is a permanent obligation, you can’t certify once and move on.
Clauses, policies, and Annex A evidence spread across drives and spreadsheets, impossible to keep current by hand, and painful to prove on demand.
Compyl runs the whole ISMS as an always-on cycle, risk, controls, evidence, and the Statement of Applicability stay in sync automatically.
Integrate cloud, identity, code, endpoint, and HR systems.
Pull audit evidence automatically, in real time.
Link every artifact to its Annex A control and the ISMS.
Watch controls continuously and flag drift early.
Hand auditors a current evidence pack on demand.
ISO 27001 pairs the mandatory management-system clauses (4–10) with 93 Annex A controls you scope through a Statement of Applicability. Compyl maps evidence to every one.
The management system itself, context, leadership, risk assessment, operation, and continual improvement.
Policies, roles, supplier, threat-intel, and incident management, the backbone of the ISMS.
Screening, awareness, responsibilities, remote working, and secure offboarding.
Secure areas, equipment, clear-desk, and physical access to facilities and media.
Access control, cryptography, logging, secure development, and monitoring.
The biggest cost of ISO 27001 isn’t the audit fee, it’s the weeks your team spends gathering proof for every control. Compyl collects it continuously from the systems you already run, so evidence is always current and always mapped to Annex A.
Collecting evidence is only half the battle; stale or incomplete proof is where audits go sideways. Evidence Health continuously scores every artifact the moment it changes, so weak evidence surfaces weeks before an audit, not during it.
An ISO 27001 certificate is only as strong as the months between surveillance audits. Compyl monitors every control continuously, scores your posture in real time, and turns the moment a control slips into a tracked task, not a future nonconformity.
ISO 27001 shares the majority of its controls with SOC 2, HIPAA, NIST, and PCI. Compyl cross-maps each control so one piece of evidence satisfies every framework it touches, which is why the second framework costs a fraction of the first.
Certification is a two-stage external audit, then annual surveillance and a full recertification at year three. Compyl keeps you ready for every checkpoint, not just the first.
The auditor checks whether your ISMS is designed and documented, scope, risk assessment, Statement of Applicability, and policies.
The auditor samples evidence to confirm controls actually operate. Pass, and you’re certified, then surveillance audits each year, recertification at year three.
Plenty of platforms get you a first ISO 27001 certificate. Compyl was built by security leaders to keep the ISMS true every day after, and to make the next framework easy.
Evidence and controls stay live year-round, so every surveillance audit is clean by default.
Controls, evidence, risks, and policies in one platform, not a stack of disconnected tools.
Pulls live data from the stack you already run, so posture reflects reality, not snapshots.
AI maps controls, drafts remediations, and offloads busywork, your team stays in control.
ISO 27001 evidence carries over to SOC 2, HIPAA, NIST, and PCI without redoing the work.
Compyl cross-maps controls so the work you do for ISO 27001 carries straight into the next framework on your roadmap.
“As our company scaled globally, Compyl supported our information security capabilities in jurisdictions around the world, helping us achieve full ISO and SOC certifications.”
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It pairs mandatory management-system clauses (4–10) with 93 Annex A controls across four themes, Organizational, People, Physical, and Technological, which you scope through a Statement of Applicability. Unlike SOC 2, it is a certifiable standard: an accredited body audits you and issues a three-year certificate. Compyl turns ISO 27001 from a once-a-year scramble into an always-on ISMS: it connects to your existing systems, collects Annex A evidence automatically, maps it to the right controls, monitors every control continuously, and flags drift before it becomes a nonconformity, so you stay ready for Stage 2 and every surveillance audit.
ISO 27001:2022 groups its 93 Annex A controls into four themes. The certification audit checks the ISMS as a system, so the evidence has to stay current between Stage 2 and each surveillance audit.
| Annex A theme | Controls | Examples | How Compyl evidences it |
|---|---|---|---|
| Organizational | 37 | Policies, roles, supplier relationships, incident management | Policy lifecycle, vendor risk and incident records mapped to each control |
| People | 8 | Screening, awareness, disciplinary process, remote working | HR system integrations and attestation campaigns |
| Physical | 14 | Secure areas, equipment, clear desk, media disposal | Asset inventory tied to controls; periodic evidence tasks |
| Technological | 34 | Access control, logging, backups, secure development, cryptography | Live evidence from cloud, identity and code repositories |
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). The 2022 version requires management-system clauses 4–10 plus 93 Annex A controls across four themes, Organizational, People, Physical, and Technological. Unlike SOC 2, it’s a certifiable standard: an accredited body audits your ISMS and issues a certificate valid for three years.
Clauses 4–10 define the management system itself, context, leadership, planning and risk assessment, support, operation, evaluation, and continual improvement, and are mandatory. Annex A is a catalog of 93 controls you select through a Statement of Applicability based on your risk assessment.
Certification is a two-stage external audit. Stage 1 is a documentation review (is the ISMS designed and documented?). Stage 2 assesses implementation (do the controls actually operate?). After certification, annual surveillance audits confirm the ISMS is maintained, with a full recertification audit at the three-year mark.
Compyl connects to your existing stack, collects Annex A evidence automatically, maps it to controls and the ISMS, monitors controls continuously, scores evidence health, and flags drift before it becomes a nonconformity, a live, certification-ready posture instead of a pre-audit scramble.
Compyl 26.2 introduced Evidence Health, which continuously scores every piece of evidence on three dimensions, relevance, freshness, and completeness. Scoring runs automatically the moment evidence changes and includes an AI summary of what’s missing, so control gaps surface weeks before a surveillance audit instead of during it.
Yes. Compyl cross-maps each control so a single control and its evidence can satisfy ISO 27001 alongside SOC 2, HIPAA, NIST CSF, PCI DSS, and 70+ other frameworks. Collect the evidence once and reuse it everywhere it applies.
Security and GRC teams at mid-market and enterprise organizations that need to certify, and then keep the ISMS running between surveillance audits without growing headcount, especially teams running ISO 27001 alongside SOC 2 or other frameworks.
No. The transition period ended on October 31, 2025. Under IAF MD 26, every certificate issued against ISO/IEC 27001:2013 expired or was withdrawn at that point, so a valid certificate today must be to ISO/IEC 27001:2022, including Amendment 1:2024.
ISO/IEC 27001:2022/Amd 1:2024 is part of ISO’s climate action changes to management system standards. It asks organizations to consider whether climate change is a relevant issue when setting the context of their ISMS. Certification bodies audit it as part of the current standard.
ISO lists ISO/IEC 27001:2022 as the current edition, now in systematic review. No new edition has been published, so organizations should certify to the 2022 edition with Amendment 1:2024.
Not anymore. ISO/IEC 27701:2025, published in October 2025, is a standalone, certifiable privacy information management system standard. You can certify to it without ISO 27001, though running both on the shared management system structure is more efficient.
See how Compyl keeps the Statement of Applicability in sync, evidence current, and every surveillance audit clean, then carries the same work into the next framework.