ISO 27001 certification, managed in one place.
All 93 Annex A controls of the 2022 revision, your risk treatment plan, and the evidence your certification body will ask for.
An ISMS is a system, not a document
ISO 27001 asks you to build and operate an information security management system: understand your context, assess risk, select controls, justify the ones you excluded, and then demonstrate that the whole thing is reviewed and improved on a cycle.
The 2022 revision reorganised Annex A from 114 controls into 93, grouped under four themes. If you certified against the 2013 version you have a transition to manage; if you are starting now, you start on 2022.
OpenGRC includes ISO 27001:2022 and the 2013 legacy bundle, so you can run the transition side by side rather than guessing at the delta.
Risk-driven, the way the standard intends.
Risk treatment that links to controls
ISO 27001 is risk-led: controls exist because a risk justified them. Score inherent and residual risk on a 5x5 matrix, record the treatment decision, and link it to the Annex A controls and implementations that carry it out.
Your Statement of Applicability, evidenced
Every Annex A control carries applicability, ownership, implementation detail and test procedures — so the justification for including or excluding a control is recorded where the control lives, not in a separate spreadsheet.
Surveillance audits without the scramble
Certification is three years with annual surveillance. Recurring assessment cadence, automated review reminders and an auditor portal mean each surveillance visit works from live evidence.
Annex A 2022, by theme
| Annex A theme | Controls |
|---|---|
| 5 Organizational controls | 37 |
| 6 People controls | 8 |
| 7 Physical controls | 14 |
| 8 Technological controls | 34 |
93 controls in total, plus the clause 4–10 management system requirements that the certification body assesses alongside them. The 2013 bundle (140 controls) is included too, for transition work.
ISO 27001 questions
Does OpenGRC certify us?
No. Certification comes from an accredited certification body after a Stage 1 and Stage 2 audit. OpenGRC is where the ISMS lives: risk assessment and treatment, Annex A controls and their implementations, evidence, internal audits, corrective actions and management review.
™