Compyl
Framework · ISO 27001ISO/IEC 27001:2022

ISO 27001 for a living ISMS, not a binder.

ISO 27001 isn’t just 93 controls, it’s a management system you have to keep alive: a risk assessment, a Statement of Applicability, and surveillance audits every single year. Compyl’s ISO 27001 compliance software runs the ISMS continuously, so it stays current, evidenced, and certification-ready.

Last reviewed September 2026 by the Compyl GRC team
93 Annex A controls125+ integrationsContinuous ISMS
ISO 27001 · ISMS readinessSurveillance audit · in 84 days
88%ready
Annex A evidence collected91%
SoA · applicable controls passing79 / 81
Evidence Health92
Clauses 4–10OrganizationalPeoplePhysical · 1 driftingTechnological
A.8.15 · LoggingCloudTrail on in all regions · AWS · refreshed 8 min ago
Passing
A.7.10 · Storage media2 decommissioned laptops missing wipe certificates · task assigned to IT
Drift → task
Statement of Applicability · in sync with the risk registerSoA current
The problem

An ISMS that lives in spreadsheets falls apart between audits

Most ISO 27001 programs slow to a crawl after certification, the Statement of Applicability drifts from reality, evidence scatters across teams, and the next surveillance audit turns into a scramble to rebuild what should have been running all along.

The SoA drifts from reality

Your risk assessment and Statement of Applicability are point-in-time documents. Controls change; the paperwork doesn’t, until an auditor finds the gap.

Surveillance never sleeps

Annual surveillance audits and a three-year recertification mean the ISMS is a permanent obligation, you can’t certify once and move on.

The ISMS lives in documents

Clauses, policies, and Annex A evidence spread across drives and spreadsheets, impossible to keep current by hand, and painful to prove on demand.

How it works

One continuous loop, from connected systems to audit-ready

Compyl runs the whole ISMS as an always-on cycle, risk, controls, evidence, and the Statement of Applicability stay in sync automatically.

01

Connect

Integrate cloud, identity, code, endpoint, and HR systems.

02

Collect evidence

Pull audit evidence automatically, in real time.

03

Map to Annex A

Link every artifact to its Annex A control and the ISMS.

04

Monitor

Watch controls continuously and flag drift early.

05

Stay audit-ready

Hand auditors a current evidence pack on demand.

The standard

The ISMS, plus 93 Annex A controls across four themes

ISO 27001 pairs the mandatory management-system clauses (4–10) with 93 Annex A controls you scope through a Statement of Applicability. Compyl maps evidence to every one.

ISMS

Mandatory
4–10 clauses

The management system itself, context, leadership, risk assessment, operation, and continual improvement.

Required for certification

Organizational

Annex A
37 controls

Policies, roles, supplier, threat-intel, and incident management, the backbone of the ISMS.

A.5.1 – A.5.37

People

Annex A
8 controls

Screening, awareness, responsibilities, remote working, and secure offboarding.

A.6.1 – A.6.8

Physical

Annex A
14 controls

Secure areas, equipment, clear-desk, and physical access to facilities and media.

A.7.1 – A.7.14

Technological

Annex A
34 controls

Access control, cryptography, logging, secure development, and monitoring.

A.8.1 – A.8.34
Automated evidence

Stop collecting ISO 27001 evidence by hand

The biggest cost of ISO 27001 isn’t the audit fee, it’s the weeks your team spends gathering proof for every control. Compyl collects it continuously from the systems you already run, so evidence is always current and always mapped to Annex A.

  • Pull evidence automatically from cloud, identity, code, and endpoint tools
  • Every artifact mapped to the Annex A control it supports
  • No more screenshots, spreadsheets, or last-minute requests
  • Export a complete, auditor-ready evidence pack on demand
Annex A evidence · collected automatically1,106 artifacts · live
AWS · IAM, CloudTrail, KMS388 artifacts · mapped to A.8.2, A.8.15, A.8.24
Synced 3m
Okta · users, MFA, groups201 artifacts · mapped to A.5.15–A.5.18
Synced 6m
GitHub · branch protection, reviews142 artifacts · mapped to A.8.25, A.8.28
Synced 12m
BambooHR · screening, offboarding84 artifacts · mapped to A.6.1, A.6.5
Synced 1h
Every artifact mapped to its Annex A control and the ISMSAuditor-ready pack
Evidence Health · New in 26.2

Know your evidence is audit-ready, automatically

Collecting evidence is only half the battle; stale or incomplete proof is where audits go sideways. Evidence Health continuously scores every artifact the moment it changes, so weak evidence surfaces weeks before an audit, not during it.

  • Every artifact scored on relevance, freshness, and completeness
  • An AI summary spells out exactly what’s missing and why
  • Re-scores automatically whenever the underlying evidence changes
  • Gaps surface with time to fix, not during the surveillance audit
Evidence HealthNew in 26.2 · re-scores on change
ArtifactRisk assessment · Clause 6.1.2
Score58 / 100
RelevanceHigh
FreshnessStale · 14 months
AI summary · what’s missingThe risk assessment predates the last two SoA changes: A.5.23 (cloud services) and A.8.9 (configuration management) were added without a corresponding risk entry. Re-run the assessment for those controls before the surveillance audit.
Create taskOpen risk register
Weak evidence surfaces weeks before the audit, not during itScored continuously
Continuous monitoring

Catch control drift before the auditor does

An ISO 27001 certificate is only as strong as the months between surveillance audits. Compyl monitors every control continuously, scores your posture in real time, and turns the moment a control slips into a tracked task, not a future nonconformity.

  • Live posture across every Annex A control
  • Automatic alerts the moment a control drifts out of compliance
  • Remediation tasks auto-assigned with owners and deadlines
  • A defensible, time-stamped trail across the whole certification cycle
Continuous monitoring81 applicable controls · checked hourly
Detected09:14 · public S3 bucket
AlertedOwner: Cloud team
Task openINFRA-2318 · due in 2 days
Verifiedauto re-check
A.8.3 · Information access restrictionDrifted 09:14 · remediation in progress
Drifting
A.8.5 · Secure authenticationMFA enforced org-wide · last check 08:00
Passing
A defensible, time-stamped trail across the whole certification cycleAudit trail
Collect once, reuse everywhere

Your ISO 27001 work becomes a head start on every other framework

ISO 27001 shares the majority of its controls with SOC 2, HIPAA, NIST, and PCI. Compyl cross-maps each control so one piece of evidence satisfies every framework it touches, which is why the second framework costs a fraction of the first.

  • One control mapped to its equivalent across 70+ frameworks
  • Collect evidence once and reuse it across every report
  • See instantly how ISO 27001 readiness translates to SOC 2 or HIPAA
  • Add the next framework without starting the program over
One ISO 27001 controlA.5.15 · Access controlLeast-privilege access enforced · evidence from Okta and AWS IAM1 piece of evidence
Also satisfies
SOC 2CC6.1 · CC6.3 Logical access controls
Satisfied
HIPAA Security Rule§164.312(a)(1) Access control · §164.308(a)(4) Information access management
Satisfied
NIST CSF 2.0PR.AA-01 · PR.AA-05 Access permissions
Satisfied
PCI DSS v4.0.1Req 7.2 · Req 7.3 Restrict access by business need
Satisfied
+ 70 more frameworks cross-mapped automatically
The path to certification

Stage 1, Stage 2, then surveillance for three years

Certification is a two-stage external audit, then annual surveillance and a full recertification at year three. Compyl keeps you ready for every checkpoint, not just the first.

Stage 1

Documentation review

The auditor checks whether your ISMS is designed and documented, scope, risk assessment, Statement of Applicability, and policies.

Checks
Is the ISMS designed and documented?
Output
Readiness for the Stage 2 audit
With Compyl
A complete SoA and documented ISMS, on demand
Stage 2 + annual surveillance

Implementation audit

The auditor samples evidence to confirm controls actually operate. Pass, and you’re certified, then surveillance audits each year, recertification at year three.

Checks
Do the controls operate as intended?
Cycle
Annual surveillance · recert at year 3
With Compyl
Continuous evidence keeps the whole 3-year cycle clean
Why Compyl for ISO 27001

Not a checkbox tool, a continuous compliance engine

Plenty of platforms get you a first ISO 27001 certificate. Compyl was built by security leaders to keep the ISMS true every day after, and to make the next framework easy.

01

Continuous, not point-in-time

Evidence and controls stay live year-round, so every surveillance audit is clean by default.

02

One connected system

Controls, evidence, risks, and policies in one platform, not a stack of disconnected tools.

03

125+ integrations

Pulls live data from the stack you already run, so posture reflects reality, not snapshots.

04

Agentic AI

AI maps controls, drafts remediations, and offloads busywork, your team stays in control.

05

Multi-framework by design

ISO 27001 evidence carries over to SOC 2, HIPAA, NIST, and PCI without redoing the work.

Beyond ISO 27001

Certify once, extend to every framework that follows

Compyl cross-maps controls so the work you do for ISO 27001 carries straight into the next framework on your roadmap.

Recognized by users on G2 · Rated a leader by the teams who use itG2 Momentum Leader, Summer 2026G2 High Performer Mid-Market, Summer 2026G2 Best Support Mid-Market, Summer 2026G2 Fastest Implementation Mid-Market, Summer 2026
93
Annex A controls mapped to evidence and the ISMS
125+
Native integrations feeding evidence automatically
Real-time
Evidence collection, no manual screenshots
Year-round
Audit readiness instead of a pre-audit scramble

“As our company scaled globally, Compyl supported our information security capabilities in jurisdictions around the world, helping us achieve full ISO and SOC certifications.”

MGMack GillCOO · via G2

What is ISO 27001, and how does Compyl help?

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It pairs mandatory management-system clauses (4–10) with 93 Annex A controls across four themes, Organizational, People, Physical, and Technological, which you scope through a Statement of Applicability. Unlike SOC 2, it is a certifiable standard: an accredited body audits you and issues a three-year certificate. Compyl turns ISO 27001 from a once-a-year scramble into an always-on ISMS: it connects to your existing systems, collects Annex A evidence automatically, maps it to the right controls, monitors every control continuously, and flags drift before it becomes a nonconformity, so you stay ready for Stage 2 and every surveillance audit.

Annex A

How does ISO 27001 compliance software cover the 93 Annex A controls?

ISO 27001:2022 groups its 93 Annex A controls into four themes. The certification audit checks the ISMS as a system, so the evidence has to stay current between Stage 2 and each surveillance audit.

Annex A themeControlsExamplesHow Compyl evidences it
Organizational37Policies, roles, supplier relationships, incident managementPolicy lifecycle, vendor risk and incident records mapped to each control
People8Screening, awareness, disciplinary process, remote workingHR system integrations and attestation campaigns
Physical14Secure areas, equipment, clear desk, media disposalAsset inventory tied to controls; periodic evidence tasks
Technological34Access control, logging, backups, secure development, cryptographyLive evidence from cloud, identity and code repositories
FAQ

ISO 27001 questions, answered

What is ISO 27001?

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). The 2022 version requires management-system clauses 4–10 plus 93 Annex A controls across four themes, Organizational, People, Physical, and Technological. Unlike SOC 2, it’s a certifiable standard: an accredited body audits your ISMS and issues a certificate valid for three years.

What’s the difference between the ISMS clauses and Annex A controls?

Clauses 4–10 define the management system itself, context, leadership, planning and risk assessment, support, operation, evaluation, and continual improvement, and are mandatory. Annex A is a catalog of 93 controls you select through a Statement of Applicability based on your risk assessment.

How does the ISO 27001 certification audit work?

Certification is a two-stage external audit. Stage 1 is a documentation review (is the ISMS designed and documented?). Stage 2 assesses implementation (do the controls actually operate?). After certification, annual surveillance audits confirm the ISMS is maintained, with a full recertification audit at the three-year mark.

How does Compyl automate ISO 27001?

Compyl connects to your existing stack, collects Annex A evidence automatically, maps it to controls and the ISMS, monitors controls continuously, scores evidence health, and flags drift before it becomes a nonconformity, a live, certification-ready posture instead of a pre-audit scramble.

How does Compyl score evidence quality?

Compyl 26.2 introduced Evidence Health, which continuously scores every piece of evidence on three dimensions, relevance, freshness, and completeness. Scoring runs automatically the moment evidence changes and includes an AI summary of what’s missing, so control gaps surface weeks before a surveillance audit instead of during it.

Can one ISO 27001 control satisfy other frameworks?

Yes. Compyl cross-maps each control so a single control and its evidence can satisfy ISO 27001 alongside SOC 2, HIPAA, NIST CSF, PCI DSS, and 70+ other frameworks. Collect the evidence once and reuse it everywhere it applies.

Who is Compyl’s ISO 27001 solution designed for?

Security and GRC teams at mid-market and enterprise organizations that need to certify, and then keep the ISMS running between surveillance audits without growing headcount, especially teams running ISO 27001 alongside SOC 2 or other frameworks.

Are ISO 27001:2013 certificates still valid?

No. The transition period ended on October 31, 2025. Under IAF MD 26, every certificate issued against ISO/IEC 27001:2013 expired or was withdrawn at that point, so a valid certificate today must be to ISO/IEC 27001:2022, including Amendment 1:2024.

What is the ISO 27001 climate change amendment?

ISO/IEC 27001:2022/Amd 1:2024 is part of ISO’s climate action changes to management system standards. It asks organizations to consider whether climate change is a relevant issue when setting the context of their ISMS. Certification bodies audit it as part of the current standard.

Is a new version of ISO 27001 coming?

ISO lists ISO/IEC 27001:2022 as the current edition, now in systematic review. No new edition has been published, so organizations should certify to the 2022 edition with Amendment 1:2024.

Do I need ISO 27001 before ISO 27701?

Not anymore. ISO/IEC 27701:2025, published in October 2025, is a standalone, certifiable privacy information management system standard. You can certify to it without ISO 27001, though running both on the shared management system structure is more efficient.

GRC your way

Keep the ISMS alive, not just certified

See how Compyl keeps the Statement of Applicability in sync, evidence current, and every surveillance audit clean, then carries the same work into the next framework.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies