ISO 27001
ISO 27001 — the Statement of Applicability an auditor reads first.
Every Annex A control plus the management chapters, justified rather than asserted — the document that decides certification.
Price
All prices plus VAT, flat per company, hosted in Germany, cancel monthly.
See bundles →Questions? Request a demo →What ISO 27001 requires of you.
Define your ISMS scope and a policy your leadership team actually stands behind, not one nobody reads.
Run a risk assessment and treatment plan where every identified risk maps to an explicit decision.
Cover every applicable Annex A control in a Statement of Applicability an auditor can follow line by line.
Show a management review and internal audit cycle that has actually happened — not one that's merely scheduled.
In numbers, from our requirement catalogue
118
Requirements and controls in total
25
Requirements from the management chapters
93
Controls from Annex A (complete)
Every requirement carries a source, every one has at least one measure — checked by an automated catalogue test on every change. That's the foundation of our promise: audit-ready.
ISO 27001: frequently asked questions
What does the ISO 27001 module cost at Compliverse?
We don't publish a list price for this module — we calculate it with you, because scope, the number of companies and, for NIS2, the number of countries differ too much. You get a written quote with a fixed amount before anything starts. You can ask for one through the contact form; a sales call is not a precondition.
ISO 27001: legal obligation or voluntary?
Voluntary. There is no express legal duty behind it — until a large customer or a tender demands the certificate, and then at short notice. We say so plainly, because inventing an obligation is the fastest way to lose the trust this business runs on.
What does ISO 27001 actually require of us?
Define your ISMS scope and a policy your leadership team actually stands behind, not one nobody reads. Run a risk assessment and treatment plan where every identified risk maps to an explicit decision. Cover every applicable Annex A control in a Statement of Applicability an auditor can follow line by line. Show a management review and internal audit cycle that has actually happened — not one that's merely scheduled.
How completely does Compliverse cover ISO 27001?
Our catalogue holds 118 requirements for this framework. Each carries a legal source and each has at least one measure behind it — checked by an automated test on every change, not by good intentions. That is what "audit-ready" means for us: we do not guarantee that you end up compliant, because nobody can do that honestly. We guarantee that it is provable.
Our promise
We don't say “compliant”. We say audit-ready — and we can prove it.
Nobody can guarantee that a company did everything right in an audit — not even a provider who promises it more confidently. What can be guaranteed is this. Four points, each independently verifiable.
01
Complete against the statute text
Every provision we cover has at least one requirement, every requirement at least one measure — and every one carries its source citation. That's not a promise: an automated test checks the catalogue on every change. If it finds a gap, the module doesn't ship.
→ Verifiable in each framework's requirement catalogue
02
Current, with a date
We re-read the legal texts in the original wording every month and update the product, training and website to match. Every check lands publicly in the change log — even when nothing changed.
→ Public change log on the Legal Landscape page
03
Evidenced, not asserted
Every requirement we mark as met has a document, certificate or log behind it — with a source citation and a legal-status date. What you can't hand an auditor doesn't count as done with us.
→ Evidence package as PDF, exportable at any time
04
Honest about the boundary
We provide structure, documents and evidence — not legal advice for your specific case. Where a question belongs with a lawyer, we say so instead of selling you something.
→ No legal advice — printed on every document
Last checked on 01/09/2026. That's how you get evidence that survives scrutiny — instead of a binder that falls apart at the first follow-up question.
What becomes important next
Legal Landscape
Deadline radar and change log — every update with a checked date.
To Legal Landscape →More modules
Legal status checked on 01/09/2026 · Every statement with a source · No legal advice