ISO 27001 certification, with a live Statement of Applicability.
ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS), certified against 93 Annex A controls across four themes — Organisational, People, Physical, and Technological. grComply seeds the real 2022 Annex A structure, feeds A.8.8 vulnerability management from its own scanning, and closes A.6.3 security awareness training with the training module's completion record — so a Statement of Applicability export always reflects live, current completion rather than a snapshot from last quarter's audit prep.
What is ISO/IEC 27001? ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS) — a certifiable framework requiring organisations to implement and continuously improve a risk-based set of Annex A controls across four themes: Organisational, People, Physical, and Technological. Certification is issued by an accredited body following a Stage 1 and Stage 2 audit.
How grComply benefits your ISO 27001 programme
All four Annex A themes, real control language
A5 Organisational through A8 Technological seeded with actual 2022 control titles, not a generic checklist.
A.8.8 vulnerability management runs on live scan data
External and internal scanning with CVE enrichment feeds A.8.8 directly, findings triaged straight into the control.
A.6.3 awareness training becomes provable evidence
The training module's compliance-mapped courses satisfy A.6.3 with a real completion record, not a sign-in sheet.
Statement of Applicability reflects live completion
The completion cache updates as evidence lands, so an SoA export always matches current reality, not last quarter's audit prep.
Cross-maps to SOC 2, NIST CSF, and CIS automatically
An ISMS built on 27001 doesn't have to be rebuilt for a US customer's SOC 2 requirement — evidence uploaded once counts twice.
Certification audit workflow, not a shared drive
Observation, response, peer countersign, and versioned reports match how a Stage 1/2 ISO audit actually runs.
Four Annex A themes, seeded with the real 2022 control set
Seeded directly from the ISO/IEC 27001:2022 Annex A structure — Organisational, People, Physical, and Technological controls, with real control titles underneath.
A.5 — Organisational controls
Policies for information security, threat intelligence, acceptable use of assets, and information security for cloud services — the governance layer an ISMS sits on.
A.6 — People controls
Screening, and information security awareness, education and training (A.6.3) — closed directly by grComply's training module with a real completion record.
A.7 — Physical controls
Physical security perimeters and physical security monitoring — the estate's physical boundary controls.
A.8 — Technological controls
User endpoint devices, privileged access rights, secure authentication, management of technical vulnerabilities (A.8.8, fed by live scanning), logging, monitoring, and use of cryptography.
Evidence grComply already models for ISO 27001
Real evidence-requirement examples from the seeded control library — the same evidence types every other framework in grComply uses, not a bespoke process for this one.
| Control | Evidence type | Example |
|---|---|---|
| A.5.1 — Information security policy | Policy document | Approved information security policy |
| A.6.3 — Awareness training | Training document | Awareness training curriculum and attendance, from the training module |
| A.8.8 — Vulnerability management | Vulnerability scan report | Vulnerability management report from grComply's own scanning |
| A.8.15 — Logging | SIEM log sample | Logging configuration sample |
| A.8.2 — Privileged access | Attestation | Privileged access review sign-off |
Why this matters: A Statement of Applicability is only as trustworthy as the evidence behind it — because grComply computes completion live from evidence, scans, and N/A decisions rather than a static checklist, an SoA export always matches what an auditor would find if they looked today.
ISO 27001, in the live workspace
The same grComply workspace shown across the platform — control browser, mapping, evidence, and AI assist apply identically to ISO 27001.






ISO 27001 in grComply
What is ISO/IEC 27001:2022?
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS), certified against a risk-based set of Annex A controls across four themes: Organisational, People, Physical, and Technological.
Does grComply support the full Annex A control set?
grComply seeds the real 2022 Annex A theme structure and representative control language across A5–A8 as a structural seed, expandable to the complete 93-control set via import for a certification-ready inventory.
How does A.8.8 vulnerability management work in grComply?
External and internal scanning with CVE enrichment (NVD, OSV, CISA KEV) generates findings that map directly into A.8.8, triaged by severity before counting as evidence.
Can training-module completions satisfy A.6.3?
Yes — a course mapped to A.6.3 in the training module produces a completion record that serves as the awareness-training evidence this control requires.
Does grComply generate a Statement of Applicability?
The completion cache — computed live from evidence, scans, observations, and N/A decisions — is exactly the data an SoA export draws from, so it always reflects current state rather than a stale audit-prep snapshot.
Can ISO 27001 evidence also satisfy SOC 2 or NIST CSF?
Where controls are genuinely equivalent, yes — cross-framework mapping lets one piece of evidence, like an A.8.2 privileged-access review, simultaneously credit an equivalent SOC 2 CC6.1 or NIST CSF PR.AA control.
Does grComply support the ISO 27001 certification audit process?
The platform's auditor-observation workflow, peer review, and versioned report packages mirror how a Stage 1/Stage 2 certification audit and subsequent surveillance audits actually run.
Can we run ISO 27001 alongside a cloud-specific extension like 27017?
Yes — ISO/IEC 27017 and 27018 load as cloud-specific extensions in the same tree, cross-mapped so shared controls aren't re-evidenced.
See ISO 27001 mapped into your control library
Powered by Mutex Systems. Back to Compliance Frameworks → · grComply overview → · Security Awareness Training →
Talk to us about ISO 27001
Tell us where your ISO 27001 programme stands today, and we'll route it to the right product specialist.
- A product specialist replies personally — not a bot
- No obligation after the first conversation
- WhatsApp support also available 24/7
By submitting, you agree to be contacted about your enquiry. We respect your privacy.
Book a meeting directly
Pick a time that works for you — 30 minutes with a product specialist, no sales script.
Ready to bring ISO 27001 into one control library?
We respond within one working day — or reach us instantly on WhatsApp.