ISO 27001 certification, managed in one place.

All 93 Annex A controls of the 2022 revision, your risk treatment plan, and the evidence your certification body will ask for.

An ISMS is a system, not a document

ISO 27001 asks you to build and operate an information security management system: understand your context, assess risk, select controls, justify the ones you excluded, and then demonstrate that the whole thing is reviewed and improved on a cycle.

The 2022 revision reorganised Annex A from 114 controls into 93, grouped under four themes. If you certified against the 2013 version you have a transition to manage; if you are starting now, you start on 2022.

OpenGRC includes ISO 27001:2022 and the 2013 legacy bundle, so you can run the transition side by side rather than guessing at the delta.

Built for the ISMS

Risk-driven, the way the standard intends.

Risk treatment that links to controls

Risk treatment that links to controls

ISO 27001 is risk-led: controls exist because a risk justified them. Score inherent and residual risk on a 5x5 matrix, record the treatment decision, and link it to the Annex A controls and implementations that carry it out.

Your Statement of Applicability, evidenced

Your Statement of Applicability, evidenced

Every Annex A control carries applicability, ownership, implementation detail and test procedures — so the justification for including or excluding a control is recorded where the control lives, not in a separate spreadsheet.

Surveillance audits without the scramble

Surveillance audits without the scramble

Certification is three years with annual surveillance. Recurring assessment cadence, automated review reminders and an auditor portal mean each surveillance visit works from live evidence.

Annex A 2022, by theme

Annex A themeControls
5 Organizational controls37
6 People controls8
7 Physical controls14
8 Technological controls34

93 controls in total, plus the clause 4–10 management system requirements that the certification body assesses alongside them. The 2013 bundle (140 controls) is included too, for transition work.

ISO 27001 questions

Does OpenGRC certify us?

No. Certification comes from an accredited certification body after a Stage 1 and Stage 2 audit. OpenGRC is where the ISMS lives: risk assessment and treatment, Annex A controls and their implementations, evidence, internal audits, corrective actions and management review.

2022 or 2013?

Can we run ISO 27001 and SOC 2 together?

Does it handle internal audits?