⚡ Every Mutex Systems product starts at £0 — create an account and go live today. See pricing →
grComply Compliance Frameworks Security Awareness Training TiLedger FlowChat Pricing Partners Resources About Reviews Contact Sign in to grComply Sign in to TiLedger Sign in to FlowChat
grComply framework · ISMS certification standard

ISO 27001 certification, with a live Statement of Applicability.

ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS), certified against 93 Annex A controls across four themes — Organisational, People, Physical, and Technological. grComply seeds the real 2022 Annex A structure, feeds A.8.8 vulnerability management from its own scanning, and closes A.6.3 security awareness training with the training module's completion record — so a Statement of Applicability export always reflects live, current completion rather than a snapshot from last quarter's audit prep.

4 Annex A themes · real 2022 control language — A.8.8 runs on live scanning, A.6.3 on the training module.
Back to all frameworks WhatsApp us
4Annex A themes
2022ISO revision seeded
A.8.8Runs on live scanning
StructuralSeed depth

What is ISO/IEC 27001? ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS) — a certifiable framework requiring organisations to implement and continuously improve a risk-based set of Annex A controls across four themes: Organisational, People, Physical, and Technological. Certification is issued by an accredited body following a Stage 1 and Stage 2 audit.

Why it's different

How grComply benefits your ISO 27001 programme

All four Annex A themes, real control language

A5 Organisational through A8 Technological seeded with actual 2022 control titles, not a generic checklist.

A.8.8 vulnerability management runs on live scan data

External and internal scanning with CVE enrichment feeds A.8.8 directly, findings triaged straight into the control.

A.6.3 awareness training becomes provable evidence

The training module's compliance-mapped courses satisfy A.6.3 with a real completion record, not a sign-in sheet.

Statement of Applicability reflects live completion

The completion cache updates as evidence lands, so an SoA export always matches current reality, not last quarter's audit prep.

Cross-maps to SOC 2, NIST CSF, and CIS automatically

An ISMS built on 27001 doesn't have to be rebuilt for a US customer's SOC 2 requirement — evidence uploaded once counts twice.

Certification audit workflow, not a shared drive

Observation, response, peer countersign, and versioned reports match how a Stage 1/2 ISO audit actually runs.

Structure

Four Annex A themes, seeded with the real 2022 control set

Seeded directly from the ISO/IEC 27001:2022 Annex A structure — Organisational, People, Physical, and Technological controls, with real control titles underneath.

A.5 — Organisational controls

Policies for information security, threat intelligence, acceptable use of assets, and information security for cloud services — the governance layer an ISMS sits on.

A.6 — People controls

Screening, and information security awareness, education and training (A.6.3) — closed directly by grComply's training module with a real completion record.

A.7 — Physical controls

Physical security perimeters and physical security monitoring — the estate's physical boundary controls.

A.8 — Technological controls

User endpoint devices, privileged access rights, secure authentication, management of technical vulnerabilities (A.8.8, fed by live scanning), logging, monitoring, and use of cryptography.

Evidence, mapped

Evidence grComply already models for ISO 27001

Real evidence-requirement examples from the seeded control library — the same evidence types every other framework in grComply uses, not a bespoke process for this one.

ControlEvidence typeExample
A.5.1 — Information security policyPolicy documentApproved information security policy
A.6.3 — Awareness trainingTraining documentAwareness training curriculum and attendance, from the training module
A.8.8 — Vulnerability managementVulnerability scan reportVulnerability management report from grComply's own scanning
A.8.15 — LoggingSIEM log sampleLogging configuration sample
A.8.2 — Privileged accessAttestationPrivileged access review sign-off

Why this matters: A Statement of Applicability is only as trustworthy as the evidence behind it — because grComply computes completion live from evidence, scans, and N/A decisions rather than a static checklist, an SoA export always matches what an auditor would find if they looked today.

Product screens

ISO 27001, in the live workspace

The same grComply workspace shown across the platform — control browser, mapping, evidence, and AI assist apply identically to ISO 27001.

FAQ

ISO 27001 in grComply

What is ISO/IEC 27001:2022?

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS), certified against a risk-based set of Annex A controls across four themes: Organisational, People, Physical, and Technological.

Does grComply support the full Annex A control set?

grComply seeds the real 2022 Annex A theme structure and representative control language across A5–A8 as a structural seed, expandable to the complete 93-control set via import for a certification-ready inventory.

How does A.8.8 vulnerability management work in grComply?

External and internal scanning with CVE enrichment (NVD, OSV, CISA KEV) generates findings that map directly into A.8.8, triaged by severity before counting as evidence.

Can training-module completions satisfy A.6.3?

Yes — a course mapped to A.6.3 in the training module produces a completion record that serves as the awareness-training evidence this control requires.

Does grComply generate a Statement of Applicability?

The completion cache — computed live from evidence, scans, observations, and N/A decisions — is exactly the data an SoA export draws from, so it always reflects current state rather than a stale audit-prep snapshot.

Can ISO 27001 evidence also satisfy SOC 2 or NIST CSF?

Where controls are genuinely equivalent, yes — cross-framework mapping lets one piece of evidence, like an A.8.2 privileged-access review, simultaneously credit an equivalent SOC 2 CC6.1 or NIST CSF PR.AA control.

Does grComply support the ISO 27001 certification audit process?

The platform's auditor-observation workflow, peer review, and versioned report packages mirror how a Stage 1/Stage 2 certification audit and subsequent surveillance audits actually run.

Can we run ISO 27001 alongside a cloud-specific extension like 27017?

Yes — ISO/IEC 27017 and 27018 load as cloud-specific extensions in the same tree, cross-mapped so shared controls aren't re-evidenced.

See ISO 27001 mapped into your control library

Powered by Mutex Systems. Back to Compliance Frameworks → · grComply overview → · Security Awareness Training →

Get in touch

Talk to us about ISO 27001

Tell us where your ISO 27001 programme stands today, and we'll route it to the right product specialist.

  • A product specialist replies personally — not a bot
  • No obligation after the first conversation
  • WhatsApp support also available 24/7

By submitting, you agree to be contacted about your enquiry. We respect your privacy.

Prefer to talk it through?

Book a meeting directly

Pick a time that works for you — 30 minutes with a product specialist, no sales script.

Ready to bring ISO 27001 into one control library?

We respond within one working day — or reach us instantly on WhatsApp.

WhatsApp us