HomePlatformComplify ISMS
Complify ISMSISO 27001 : 2022

ISO 27001 Certification.
Without the Chaos.

Complify ISMS guides your organization from gap assessment to ISO 27001 certification — and maintains continuous compliance beyond it. Every clause, every control, fully automated.

93
Annex A Controls
40%
Faster Certification
2022
Latest Standard
ISMS Certification Status● Live
§ 4Context of the Organization
§ 5Leadership & Commitment
§ 6Planning & Risk Assessment
§ 8Operation & Implementation
§ 9Performance Evaluation
Overall Readiness87%
📅

Stage 2 Audit scheduled for April 14, 2026 · 6 controls pending evidence

The Standard

What ISO 27001 : 2022 requires

ISO 27001 is the internationally recognized standard for Information Security Management Systems. The 2022 revision restructured Annex A into four themes and 93 controls across 11 domains.

Complify ISMS maps every clause requirement and Annex A control to automated workflows, evidence tasks, and policy templates — so nothing falls through the cracks.

See How Complify Maps to ISO 27001 →
§4–6
Context, Leadership & Planning
Scope definition, interested parties, risk treatment
Clauses 4–6
A.5
Organizational Controls
Policies, roles, supplier relationships, threat intelligence
37 controls
A.6
People Controls
Screening, training, remote work, disciplinary process
8 controls
A.7
Physical Controls
Physical security, clear desk, equipment security
14 controls
A.8
Technological Controls
Access, malware, logging, cryptography, vulnerability mgmt
34 controls
Platform Capabilities

How Complify ISMS
accelerates certification

Every feature in Complify ISMS is designed around the ISO 27001 lifecycle — from initial gap assessment through surveillance audits and recertification.

🔍
Automated Gap Assessment

Start with a structured gap analysis against all ISO 27001:2022 clauses and Annex A controls. Complify automatically identifies missing policies, evidence gaps, and unassigned ownership — giving you a clear remediation roadmap from day one.

🗂️
Control Library & Mapping

All 93 Annex A controls are pre-loaded with descriptions, implementation guidance, and evidence requirements. Map your existing controls once and reuse them across ISO 27701, ISO 27017, and SOC 2 without duplication.

📄
Policy & Document Management

Generate ISO-aligned policies using our AI policy builder — Information Security Policy, ISMS Scope, Risk Treatment Plan, Statement of Applicability and more. Full approval workflows with version control and distribution tracking.

Continuous Evidence Collection

Connect your cloud infrastructure, identity providers, and HR systems. Complify automatically collects and maps technical evidence against controls — access reviews, vulnerability scans, encryption configurations and more.

📊
Risk Register & Treatment

Maintain a dynamic risk register aligned to ISO 27001 clause 6.1. Score risks using qualitative or quantitative methodologies, define treatment options, and track residual risk over time with full audit trail.

Audit Management

Manage Stage 1 and Stage 2 audits end-to-end. Grant secure read-only access to external auditors, provide structured evidence packages, track non-conformities, and manage corrective actions through to closure.

Annex A Coverage

All 93 controls. Fully covered.

Complify ISMS provides built-in guidance, evidence templates, and automation for every control in ISO 27001:2022 Annex A.

A.5.1
Policies for Information Security

AI-generated, pre-approved policy templates aligned to ISO requirements with automated review cycles.

A.5.23
Information Security for Cloud Services

Automated cloud configuration checks across AWS, Azure, and GCP mapped directly to this control.

A.6.3
Information Security Awareness Training

Track training completion and attestation across your entire organization from a single dashboard.

A.8.8
Management of Technical Vulnerabilities

Integrate with vulnerability scanners to automatically evidence your vulnerability management process.

A.5.10
Acceptable Use of Information Assets

Policy distribution with tracked acknowledgment and timestamped evidence for every employee.

A.8.5
Secure Authentication

Pull MFA enforcement and access control evidence directly from Okta, Azure AD, and Google Workspace.

A.5.19
Supplier Relationships

Automated vendor risk assessments and contract tracking keep your supply chain evidence audit-ready.

A.8.16
Monitoring Activities

Continuous log monitoring integration provides real-time evidence of your monitoring activities.

Certification Journey

From gap to certified
in a structured path.

Complify ISMS guides your team through every phase of the ISO 27001 certification process — with automation, templates, and a dedicated implementation specialist at each step.

1
Phase 1 · Weeks 1–2
Gap Assessment & Scoping

Define your ISMS scope, identify interested parties, and run a structured gap analysis against all ISO 27001:2022 requirements. Complify generates a prioritized remediation plan with ownership assignments and target dates.

Scope DefinitionGap AnalysisStakeholder MappingRemediation Plan
2
Phase 2 · Weeks 3–6
Risk Assessment & Treatment

Build your information asset inventory, identify threats and vulnerabilities, assess risk using your chosen methodology, and produce a risk treatment plan and Statement of Applicability — all within the platform.

Asset InventoryRisk RegisterRisk Treatment PlanStatement of Applicability
3
Phase 3 · Weeks 7–14
Control Implementation & Evidence

Implement policies, procedures, and technical controls across all Annex A domains. Complify continuously collects automated evidence from your connected systems and tracks manual evidence uploads with a full audit trail.

Policy RolloutAutomated EvidenceStaff TrainingControl Testing
4
Phase 4 · Weeks 15–16
Internal Audit & Management Review

Run a structured internal audit using Complify's built-in audit workflows. Document findings, assign corrective actions, and complete your management review — all with the timestamped records auditors require.

Internal AuditNon-Conformity ManagementManagement Review
5
Phase 5 · Certification
Stage 1 & Stage 2 Audit

Grant your certification body secure, structured access to your evidence through Complify's auditor portal. Respond to queries, manage non-conformities, and achieve certification — then stay continuously ready for surveillance audits.

Auditor PortalEvidence PackagesCertificationContinuous Compliance
Get Started

See Complify ISMS in action.

Our GRC specialists will walk you through a tailored demo of Complify ISMS — aligned to your organization's current compliance maturity and certification goals.