Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

Best ISO 27001 Software in 2026

Direct answer: ISO 27001 software helps with two things: managing the ISMS documentation (scope, Statement of Applicability, risk treatment plan, internal audit, management review) and collecting evidence for the Annex A controls. Drata and Scrut handle multi-framework overlap well, Vanta and Secureframe cover it competently, and the documentation half is where ISO differs most from SOC 2. The certification audit is a separate accredited body and cannot be bought as software.

How ISO 27001 differs from SOC 2 for tooling

SOC 2 is an attestation against criteria. ISO 27001 certifies a management system, so the artefacts an auditor asks for are different: a defined scope, a Statement of Applicability justifying every Annex A control you did or did not apply, a risk assessment and treatment plan, evidence of internal audit, and records of management review. Tooling that is strong on technical evidence can still be thin on this documentation spine, which is where first-time ISO projects usually stall.

The options

Drata

Strong multi-framework handling, which matters because most teams doing ISO are also doing or planning SOC 2 and want the overlap counted once.

Scrut

Broad standard coverage for the price, frequently shortlisted for ISO plus others.

Vanta

Solid ISO support and the widest integration surface. Auditor familiarity is a real advantage during the Stage 1 and Stage 2 audits.

Secureframe

Comparable, with more included support depending on tier.

traztech Workspace, free

Covers the understanding and self-assessment half: every Annex A control in plain English, an evidence register, a policy library, and a risk register, which is the piece ISO leans on hardest. It does not generate a Statement of Applicability or run your internal audit, and it does not do continuous evidence collection. We build it, so check it yourself.

Running ISO 27001? Our ISO 27001 readiness track builds the ISMS that survives Stage 1 and Stage 2, with the Statement of Applicability an auditor will accept. ISO 27001 readiness

What no software does

  • Define your scope. The single most consequential ISO decision, and it is a judgement call.
  • Justify the Statement of Applicability. Each inclusion and exclusion needs a defensible reason.
  • Run the internal audit. It has to be independent of whoever operates the control.
  • Hold the management review. A meeting with minutes, not a dashboard.
  • Certify you. That is an accredited certification body, on a three-year cycle with surveillance audits.

Frequently asked

Can one tool cover ISO 27001 and SOC 2?

Yes, and it is usually the right move. The control overlap is real, particularly on policies, so the documents get written once.

Do I need software to certify?

No. The standard requires a management system, not a subscription.

What is the biggest first-timer mistake?

Scoping too broadly. A wide scope multiplies evidence, audit days, and cost, and it is very hard to narrow later.

How these platforms are actually priced

Published pricing is rare in this category, so it is worth knowing the levers before the first call. Almost every vendor prices on a combination of headcount band and framework count, with an annual commitment and a separate implementation or onboarding fee in the first year. Headcount is usually taken from your identity provider rather than your payroll, which matters if you carry a lot of contractor accounts. Framework count is where the number moves fastest, because adding SOC 2 alongside ISO 27001 is often a meaningful uplift even though the underlying evidence is largely shared.

The negotiable items, in rough order of how much they move: contract length, since two and three year terms buy real discounts and also lock in the headcount band; the implementation fee, which is frequently waived at quarter end; the number of frameworks included at signature rather than added later at list price; and the renewal uplift, which is worth capping in the original agreement because an uncapped renewal after you have three years of evidence inside the platform is a negotiation you will lose. Ask directly what happens to your data if you leave, in what format, and whether the export includes evidence artefacts or only the metadata about them. Most of the lock-in in this category is not the integrations. It is three years of collected evidence you cannot take with you.

What "automated evidence" means to an auditor

Vendors present a compliance percentage on a dashboard, and it is easy to read that as audit readiness. It is not, and understanding the gap saves a painful Stage 1. What these platforms automate well is the technical, continuously observable state of your cloud and SaaS estate: whether encryption is enabled, whether multi-factor authentication is on for every account, whether logging is configured, whether endpoints are encrypted and patched, whether access was granted and removed around joiner and leaver events.

What they cannot automate is anything that requires judgement or a human process leaving a record. Whether your risk assessment method is appropriate to your context. Whether your Statement of Applicability justifications are defensible. Whether the internal audit was performed by somebody independent of the process audited. Whether management review actually considered the inputs the standard requires and made decisions. Whether awareness training changed anything. Across the 93 Annex A controls plus clauses 4 to 10, the automatable share is meaningful but it sits almost entirely in Annex A's technological theme. The clauses, which are the part that certification actually turns on, are essentially all manual. A platform reporting 96% while your management review has never been held is reporting on the half of the standard that was never the hard half.

The 2022 revision and what tooling does with it

The current Annex A is organised into four themes: organisational, people, physical and technological. The revision consolidated the old control set and introduced controls that did not previously exist as standalone items, covering areas such as threat intelligence, information security for use of cloud services, ICT readiness for business continuity, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, secure coding, and physical security monitoring.

When evaluating a platform, check how it handles these newer controls specifically rather than the control library as a whole. Several of them are where thin implementations show: information deletion and data masking usually get a policy template and nothing else, secure coding is often mapped to a repository setting that does not evidence the control, and threat intelligence tends to be an unassigned checkbox. Ask the vendor to show you, in the demo, the exact evidence they would collect for information deletion. The quality of that answer predicts the quality of the rest.

The demo questions that separate the tools

Book the demo with a list rather than letting the vendor drive. Ask which of your actual integrations are supported, naming your real stack rather than accepting a logo wall, because coverage on the major cloud providers is universal and coverage on the second-tier tools your team actually uses is not. Ask to see the Statement of Applicability output as a document, not as a screen, since an auditor receives a document. Ask how exclusions are recorded and whether the justification text is free-form or structured.

Ask how the internal audit module works, and specifically whether it supports recording an auditor who is independent of the control owner. Ask how many of your Annex A controls will be automated versus manual on day one for your stack, and hold them to a number. Ask what happens when a control fails, meaning who is notified and whether it creates a task with an owner and a due date or simply turns a tile red. Ask which accredited certification bodies their customers commonly use and whether the auditors have seen the platform's export format before, because auditor familiarity genuinely reduces friction during Stage 2. Finally, ask for a customer reference at your size and in your country who has completed certification, not one who is mid-implementation.

The multi-framework overlap is real but shallower than the marketing

Running ISO 27001 and SOC 2 in one platform is usually correct, and the saving is genuine on policies, on the technical control evidence, and on the annual rhythm of access reviews and vendor reviews. The saving is smaller than the dashboards suggest, for a reason that is not obvious until you are inside it: the evidence titles and the specific artefacts each framework's auditor wants are not identical, even where the underlying control is the same.

An access review satisfies both frameworks, but a SOC 2 auditor may want the population, the sample and the reviewer's sign-off in a particular arrangement, while an ISO auditor is checking that the review is part of a managed system with a defined frequency and a link back to your risk treatment. Platforms handle this by mapping one control to multiple criteria, which works, but the evidence register ends up with near-duplicate entries and someone has to keep them straight. Budget for that reconciliation instead of assuming the mapping is free. It is the most common reason a team with a green dashboard still spends two weeks assembling an audit pack.

Where the dashboard and the auditor disagree

Three specific mismatches account for most of the surprise at Stage 1. The first is scope. The platform monitors whatever you connected, and your certification scope is whatever you defined in the ISMS. If you connected three cloud accounts and your scope statement covers a business unit, those are different boundaries and the auditor works from yours.

The second is the age of the evidence. A control that has been passing for nine days shows green, and an auditor assessing a management system wants to see it operating over time with records. Certification in the first year is more forgiving on this than a SOC 2 Type II, but Stage 2 still looks for a system that has run rather than one that was configured last month.

The third is the difference between a control being configured and a control being managed. Multi-factor authentication being on is a fact the platform can observe. That your organisation decided it was required, wrote it into a policy, communicated it, monitors exceptions and reviews it is a management system, and that is what you are being certified against. The standard certifies the system, not the settings.

The spreadsheet route, honestly costed

Plenty of organisations certify without buying a platform, and it is a reasonable choice under specific conditions: under roughly thirty people, a single cloud provider, a small SaaS estate, one product, and somebody internally who will genuinely own the ISMS rather than adding it to an already full job. In that situation you need a risk register, a control register mapped to Annex A with implementation notes, a Statement of Applicability, a policy set, an evidence folder with a consistent naming convention, an internal audit programme, and a management review record.

The real cost is time rather than licence fees. Expect the initial build to take a determined internal owner several weeks of part-time work, and then a few hours a month to keep evidence current, rising around internal audit and management review. That is cheaper than a platform for a small team, and it stops being cheaper somewhere around the point where you have multiple cloud accounts, more than about fifty people, or a second framework in flight. The failure mode of the spreadsheet route is not the spreadsheet. It is that the person who owns it leaves and nobody else understands why an exclusion was written the way it was.

The parts you have to buy from people, not software

Internal audit has to be independent of the process being audited, which for a small team usually means it cannot be done by the person who built the ISMS. The options are another employee sufficiently removed from information security to be independent, an external internal auditor engaged for a couple of days, or your consultancy if they did not implement the controls they are auditing. Independence is checkable and certification bodies do check it.

Certification itself comes from an accredited certification body, and accreditation is worth verifying rather than assuming. In Canada that is the Standards Council of Canada, and international equivalents such as ANAB and UKAS are recognised. An unaccredited certificate is cheaper and is exactly the sort of thing a sharp enterprise procurement team spots. Audit effort is set by published rules based on your headcount and scope complexity, which is another reason a wide scope is expensive: it lengthens both audit stages and every surveillance visit for three years.

When you should not buy any of this

If ISO 27001 is on your roadmap because it appeared on a competitor's website rather than because a customer asked, do not buy a platform and do not start. Certification carries a three-year cycle with surveillance audits, and the ongoing cost is real. Establish that a buyer needs it first.

If your buyers are North American SaaS customers, check whether they actually want ISO 27001 or whether SOC 2 is the request. Buying a multi-framework platform to cover both when only one is being asked for doubles a cost for a benefit nobody requested. Similarly, if you are pre-certification and your problem is that you do not know what your gaps are, a platform will tell you which technical settings are wrong and will not tell you whether your scope is sensible or your risk method is defensible. Buying the tool first and discovering that afterwards is the most common wasted spend we see, and it is why we push people toward a gap analysis before a subscription rather than after.

And if what you want is to understand the standard before committing money to anything, the free Workspace covers the Annex A control set in plain English with an evidence register and a risk register, which is enough to work out where you stand. We build it, so treat that recommendation with the scepticism it deserves and go and look at it rather than taking our word. When you do need the ISMS built and defended through Stage 1 and Stage 2, that is what our ISO 27001 readiness track exists for, and continuous ownership afterwards sits in a retainer rather than a licence.

Year two, which is where the tool earns or loses its keep

The certificate runs on a three-year cycle with surveillance audits in between and a recertification at the end. That rhythm changes what you need from software. In year one you want help understanding the control set and building documentation. From year two onward you want the boring things: evidence that keeps collecting without anyone remembering to do it, nonconformities from the last audit tracked to closure with dates, a risk register that gets reviewed rather than archived, and a management review that happens because something prompted it.

Judge the renewal on that basis rather than on the year-one experience. Teams that certify successfully and then let the platform go quiet arrive at their first surveillance audit with a nine month gap in records, which is a far more awkward conversation than the original audit was. If nobody is going to open the tool between audits, the subscription is buying you a false sense of continuity, and the money is better spent on somebody whose job includes opening it.

Switching platforms without losing your history

Migration happens, usually because pricing moved at renewal or the first choice turned out to be thin on the documentation half. Do it between audit cycles rather than during one, and export before you cancel rather than after. Get the policy documents with their approval history, the risk register with treatment decisions and dates, the Statement of Applicability with its justification text, and the evidence artefacts themselves rather than links to them. Links to evidence stored inside the old platform stop resolving the day the contract ends, and an auditor asking for last quarter's access review will not accept a dead URL.

Expect the control mapping to differ between platforms, so budget a few days to re-map rather than assuming an import will land cleanly. Keep the old export as a static archive regardless of how well the migration goes, because your certification body may ask about a period that only exists in the old system.

Running ISO 27001? Our ISO 27001 readiness track builds the ISMS that survives Stage 1 and Stage 2, with the Statement of Applicability an auditor will accept.

ISO 27001 readinessOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on ISO 27001. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.