Standard · ISO/IEC 27001:2022
ISO 27001 compliance, run as a four-stage workflow.
One workspace that walks an organisation from Annex A scoping through the management review meeting minutes. Roles split across creator, business liaison, GRC liaison and control owner. Editing follows the platform billing state.
First month free. No card required.
The four stages.
- Stage 1 — Initial assessment and scoping
- Answer a questionnaire that determines which Annex A controls apply to your organisation.
- Review the inline Statement of Applicability and edit per-control justification.
- Submit. Stage 1 is the hard gate — the remaining stages unlock once it is submitted.
- Stage 2 — Document readiness
- Open the catalog of every ISMS document required for certification, sourced from the ISMS Master Document Matrix.
- For each document, record its status — Available, Partial, Not Available, N/A.
- Optionally upload a controlled copy.
- Generate the Document Readiness Report.
- Stage 3 — Control mapping and internal audit
- Capture evidence per control, assign owners, and upload files.
- Use AI-assisted policy generation alongside to draft any missing policies.
- The GRC liaison fills the internal audit findings column — compliance status, consultant notes, required actions.
- Stage 4 — Management review
- Walk a wizard that mirrors the ISO 27001 management review meeting minutes template.
- Each agenda item auto-prefills from the live assessment — audit findings, corrective actions, control status, objective fulfilment.
- Generate a .docx minutes document. Multiple historical reviews are retained per assessment.
Self-serve, or guided by a consultant.
- Self-serve
- Your team holds every role. The creator, business liaison, GRC liaison and control owners are all teammates you assign. No external party joins the workspace. You pay only the platform fee.
- Guided
- An independent consultant from the SME directory joins as the GRC liaison. They sit inside the same workspace and review the audit findings — compliance status, consultant notes, required actions — while your team owns the implementation columns. You pay the platform fee plus the consultant's review fee, prorated by the day.
Two rates. One while you work. One after.
Activewhile controls and evidence are in motion.
Passiveonce the audit ships and the workspace becomes a read-only record.
Self-serve
Your team runs the workflow end to end.
$550 / month
$30 / month
Guided
Platform fee plus an independent consultant from the SME directory. Browse rates after you sign in.
See directory
See directory
Rates shown are indicative. The exact daily number is displayed inside the product before any assessment is launched.
How the meter actually runs.
- Why two rates
- ISO 27001 readiness runs over months, not days. The meter is split so you pay full rate while controls and evidence are still in motion, and a much lower rate once the audit ships and the workspace becomes a read-only record.
- Prorated daily
- Charges accrue by the day. No annual contract. No per-seat fee. Cancel any time and the meter stops on the cancel date.
- First month free
- The first assessment on your first workflow is free for the first month. No card required at sign-up.
- Switch when the audit ships
- Flip the assessment to passive and the meter drops to the lower rate. The SoA, controls and evidence stay accessible and exportable.
What ISO 27001 compliance involves — and how a guided workflow helps
ISO/IEC 27001:2022 is the international standard for information security management. Certification tells your customers, partners and regulators that you run a working Information Security Management System (ISMS): you know what information you hold, you have assessed the risks to it, and you operate the Annex A controls — from access control and cryptography to supplier management and incident response — that keep those risks acceptable. For a growing SaaS or services business, it is increasingly the difference between clearing enterprise procurement and losing the deal.
The standard itself is only about two dozen pages, but getting audit-ready is a project: scoping the ISMS, running a risk assessment, producing a Statement of Applicability across 93 Annex A controls, writing and approving the mandatory documents, collecting evidence that controls actually operate, running an internal audit, and holding a management review. Companies with a dedicated GRC team manage that in spreadsheets; companies without one usually stall between the risk assessment and the evidence collection.
regXperience turns that project into a guided four-stage workflow. Stage one scopes your ISMS and runs the initial assessment against the 2022 clause structure. Stage two walks through document readiness — each mandatory document has a template to download, complete and upload. Stage three maps your controls, captures evidence per control, and runs the internal audit view your certification auditor will want to see. Stage four is the management review, with the sign-offs recorded. Every stage shows exactly what is done, what is missing, and who owns it — so a compliance lead, an office manager or an external consultant can drive certification readiness without specialist tooling experience.
See pricing — pay by the day, no annual contract — or browse the compliance guides to go deeper.
Frequently asked questions
How long does ISO 27001 certification take for a small business?
Most SMBs need three to six months from starting the gap assessment to being audit-ready, then one to two months for the certification audit itself (stage 1 document review plus stage 2 on-site or remote audit). The biggest variables are how much of your documentation already exists and how quickly control owners return evidence. A guided workflow compresses the calendar mainly by making the missing items visible from day one.
What documents does ISO 27001 actually require?
The 2022 revision mandates a defined ISMS scope, an information security policy, a risk assessment and risk treatment methodology with results, the Statement of Applicability, security objectives, evidence of competence, and records of monitoring, internal audit and management review — plus the operational policies your risk treatment relies on (access control, supplier security, incident management and so on). regXperience ships a template for each mandatory document in its document-readiness stage.
Do I need a consultant to get ISO 27001 certified?
No — certification bodies audit your ISMS, not who built it. Many SMBs certify with an internal owner spending a few hours a week inside a structured tool. A consultant speeds things up where you lack security context; regXperience supports both models, and its regXpert network can supply a consultant who works inside the same workflow you see.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is an international certification of your security management system against a fixed standard; SOC 2 is a North-American attestation report on controls you selected against the Trust Services Criteria. Buyers in Asia, the Middle East and Europe generally ask for ISO 27001; US enterprise buyers often ask for SOC 2. The control work overlaps heavily, so most companies do ISO 27001 first and reuse the evidence.
How much does ISO 27001 software cost on regXperience?
Pricing is per workflow, per day — an active daily rate while you are working towards readiness and a lower passive rate while the ISMS is in maintenance. There is no annual contract and no per-seat fee, and your first month on your first workflow is free. See the pricing page for the current day rates.
Start your first workflow — first month free
Sign in to start