Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

The four categories of ISO 27001 tools and when each one is worth buying

ISO 27001 Tools: Complete Guide to the 4 Categories

ISO 27001 tools cover everything from a single spreadsheet to a six-figure GRC
platform, and the gap between them is not features — it is how much of your certification effort each
one actually removes.

What ISO 27001 tools are for

An ISMS generates three things continuously: decisions about which controls apply, evidence that
they operate, and a record of where you are against the standard. Tooling exists to hold those three
things. Everything else is packaging.

That framing matters because the market is sold on dashboards. A dashboard is a view of your
data; it is not a substitute for having made the decisions underneath it. Organisations regularly buy
a platform, populate a fraction of it, and arrive at their audit with the same gaps they started
with — now spread across a system nobody has time to maintain.

The four categories of ISO 27001 tools

The four categories of ISO 27001 tools and when each one is worth buying
Most organisations need the first two long before the third.
Category What it does Best when
Assessment spreadsheet Scores every clause and control, produces the gap picture You need to know where you stand before committing budget
Document set Supplies the policies, procedures and records the standard requires The gaps are documentary rather than technical
GRC platform Workflow, task assignment, continuous evidence collection Multiple frameworks, several teams, ongoing surveillance audits
Technical scanners Test configuration, vulnerabilities, access Evidencing the technological controls specifically

Most organisations need the first two long before the third. A platform automates a process you
have already defined; bought early, it asks you to define that process inside someone else’s data
model while you are still learning the standard.

What ISO 27001 tools have to cover

ISO 27001 has two halves and a credible assessment tool scores both.

The main body, clauses 4 to 10, is where certification is actually won and lost —
context, leadership, planning, support, operation, performance evaluation and improvement. These are
the mandatory management-system requirements, and they cannot be marked “not applicable”.

The Annex A controls are the other half: 93 controls in four themes —
37 organizational, 8 people, 14 physical and 34 technological. Unlike the clauses, these can
be excluded, provided the exclusion is justified in your Statement of Applicability.

A tool that scores only Annex A is scoring the easier half. Auditors open with clauses 4 to 10.

Status scales in ISO 27001 tools, and why yes/no is not enough

A binary implemented/not-implemented field is the most common weakness in home-made ISO 27001
tools. Real programmes are mostly in between, and a two-value scale forces everything partial into
one bucket or the other — which means the tool cannot show progress and nobody updates it.

A workable scale separates not yet examined from examined and absent, then
grades the middle. One that works in practice runs: unknown, nonexistent, initial, limited, defined,
managed, optimised, plus an explicit not-applicable for justified Annex A exclusions. Seven grades is
enough to show movement quarter on quarter without inviting arguments about the difference between
adjacent levels.

The payoff is the rollup. Once every clause and control carries a status, the proportion sitting at
each level becomes the single most useful number in the programme — it tells you whether you are
three months or eighteen months from an audit, which no amount of task-list completion will.

Score the whole standard in one workbook.

The ISO 27001 Assessment Tool covers the mandatory ISMS requirements across clauses 4 to 10 and all 93 Annex A controls as a Statement of Applicability, with a seven-level maturity scale, a not-applicable option for justified exclusions, and a metrics sheet that reports the proportion of requirements and controls at each level.

Explore the ISO 27001 Assessment Tool →

Choosing between ISO 27001 tools

Three questions settle it faster than any feature comparison.

  1. Do you know your current position? If not, an assessment comes first. Buying
    workflow software to manage work you have not yet scoped is the most expensive order to do this in.
  2. Are your gaps documentary or technical? Missing policies are solved by a
    document set. Missing logging, patching or access review is solved by engineering, and no tool
    shortens that.
  3. How many frameworks are you carrying? One standard rarely justifies a platform.
    Three or more, with shared controls and overlapping audits, usually does.

The honest sequence for most first-time certifications is assess, then document, then remediate,
and consider a platform at the first surveillance audit — when you have a process worth automating.

How ISO 27001 tools should handle the Statement of Applicability

The Statement of Applicability is mandatory, and it is the document auditors use to navigate
everything else. It must state, for each of the 93 Annex A controls, whether it applies, the
justification for that decision, and whether it is implemented.

That last distinction defeats a lot of home-made trackers. Applicability and implementation are two
different fields: a control can be applicable and not yet implemented, which is a normal position
early in a programme. Collapsing them into one column produces a Statement of Applicability that
either overstates your maturity or wrongly excludes controls you simply have not built yet.

Exclusions need a reason that survives challenge. “Not relevant to us” is not one. “No application
development takes place; software is procured” is. Whatever holds your assessment should have a field
for that sentence, because writing it later, from memory, across dozens of controls is miserable.

Keeping the tool alive between audits

Certification is not the end of the work — surveillance audits follow, and the question at each one
is whether the ISMS has operated, not whether it was documented once.

The practical habit is a quarterly re-score rather than an annual scramble. Re-scoring a workbook
takes an afternoon when the previous statuses are already there, and the trend it produces is the
input management review under clause 9.3 actually needs. Programmes that let the assessment go stale
end up rebuilding it from scratch before every audit, which is how a one-afternoon task becomes a
two-week one.

Where ISO 27001 tools stop and the auditor starts

No tool produces a certificate. A certification body examines whether the management system exists,
operates and improves — and the evidence for that is meeting minutes, internal audit reports,
corrective actions, risk treatment decisions and management review records.

What good tooling does is make that evidence findable. When an auditor asks why control 8.16 is
marked applicable but not implemented, the answer should be one click away with a date and an owner
against it, not a search through email. That is the real test to apply when comparing ISO 27001
tools: not how much they can store, but how quickly they answer the question an auditor will actually
ask.

It is also why the assessment record and the document set matter more than the dashboard. Those two
artefacts are what the auditor reads; the dashboard is for you.

A note on cost

The spread is wide enough to distort decisions. An assessment workbook and a document set are a
one-off purchase in the low hundreds. A GRC platform is a recurring subscription, typically priced per
user or per framework, and it carries an implementation cost in your own team’s time that is routinely
larger than the licence.

That asymmetry is why sequencing matters more than selection. Spending a little to find out where
you stand, before committing to a subscription sized for a programme you have not scoped, is the
cheapest decision available — and if the assessment shows your gaps are documentary, the platform may
never be necessary at all.

Frequently asked questions

Do I need software to certify to ISO 27001?
No. The standard requires documented information and evidence of operation; it says nothing about
tooling. Plenty of organisations certify on a document set and a spreadsheet.

Can a spreadsheet really cover 93 controls?
Yes — the Statement of Applicability is itself a table. A spreadsheet handles scoring, justification
and reporting well. What it does not do is assign tasks or collect evidence automatically.

What is the difference between an assessment tool and a gap analysis?
A gap analysis is the exercise; an assessment tool is what you record it in. See our guide to the
ISO 27001 gap analysis for the method.

Should the tool include clauses 4 to 10 or just Annex A?
Both. The clauses are mandatory and non-excludable, and they are where auditors start.

When is a GRC platform worth it?
When you are running several frameworks with shared controls, or when evidence collection across
teams has become the bottleneck rather than the documentation.

Where this leaves you

Pick ISO 27001 tools by what they remove from your workload, not by what they display. Start by
scoring both halves of the standard — clauses 4 to 10 and the 93 Annex A controls — on a scale with
enough grades to show movement. That single artefact tells you whether your problem is documentary or
technical, and everything else follows from the answer.

Then buy for the gap you actually have. A platform bought before the assessment automates a
process you have not defined yet, and that is the most common way ISO 27001 tooling money is wasted.

References

More on ISO 27001

Score your position with the ISO 27001 Assessment Tool, or build the document set with the ISO 27001 Toolkit.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.