Standard · ISO/IEC 27001:2022

When the auditor asks, answer with evidence.

A six-stage workspace that takes your organisation from a scope statement to management-review minutes. Every stage ends in a document your certification audit will ask for: a justified Statement of Applicability, a scored risk register, your ISMS policies, audited controls, dated minutes.

No compliance score. No invented percentages. Every answer traces to the clause behind it.

Start free — define your scopeSee the six stages

Stage 1 free · no card · sign in with your work account

Generated by the workspace
Statement of Applicability
Organizational controls37 justified
People controls8 justified
Physical controls14 justified
Technological controls34 justified
ExportWord · Excel
Illustrative — sample data, real export format.
2022
Current to ISO/IEC 27001:2022 — clauses 4–10 and Annex A
93
Annex A controls mapped one-to-one, 17 baseline controls pre-justified
Word · Excel
Every stage ends in an exportable artifact, not a dashboard number
~96,700
organisations hold a valid ISO 27001 certificate
ISO Survey 2024

Certification is not a form to fill. It is six pieces of evidence, produced in order.

The journey

Six stages, each one ends in a document.

Stages unlock in order; implementation and management review run in parallel once your Statement of Applicability is complete.

swipe to follow the route
1ContextFREEscope statement2Statement of Applicabilityjustified SoA3Risk managementrisk register4DocumentsISMS policy set5Control implementationaudited controls6Management review9.3 minutesEXTERNAL AUDIT · PLANNED
01ContextFree
Define the context of your organization (Clause 4) — 19 guided questions, and an AI-drafted formal scope statement you approve.
You produce A documented context and an agreed ISMS scope statement (.docx)
02Statement of Applicability
Decide which of the 93 Annex A controls apply — and justify each. 17 baseline controls come pre-locked with their justification.
You produce A complete, justified SoA (Word + Excel)
03Risk management
Assess from a library of 102 scenarios (36 apply to every organisation), score on a 5×5 grid, and treat each risk down: avoid, mitigate, transfer, accept.
You produce A scored inherent + residual risk register with treatment decisions
04Documents
A 38-item worklist — 31 mandatory — assembled from 69 templates, merged with your answers and generated to Word. Edit offline, re-upload yours.
You produce A complete, audit-ready set of ISMS policies and records
05Control implementation
Capture evidence per control, assign owners, and take each through your internal audit — findings, corrective actions, target dates.
You produce Every applicable control audited, with evidence and findings on record
06Management review
Author the Clause 9.3 minutes: seven of twelve agenda items pre-fill from your live assessment; AI polishes your notes without inventing a word.
You produce A dated, immutable management-review record, exported to Word
07External auditPlanned
The planned seventh stage — a read-only, audit-ready view for your certification body. In development — we say so rather than sell it.
Always oriented

You are never lost.

Every assessment opens on one dashboard: six honest numbers, no invented score. When all six read complete, you are ready for your auditor — and you knew it before they did.

Controls applicable
78 / 93
justified in the SoA
Risks identified
34
scored inherent + residual
Residual within threshold
31 / 34
3 accepted with rationale
Documents ready
27 / 31
mandatory items generated
Controls audited
61 / 78
evidence + findings on record
Reviews on file
1
immutable, exported to Word

Illustrative — sample data, real dashboard.

The output

What you walk out with.

Statement of Applicability
Cover page, control-by-control justification across all four Annex A themes — exported to Word and Excel.
Risk register
Inherent and residual scores with rationale on both sides, control mapping, treatment register — Word or Excel.
ISMS document set
Policies and records generated from your answers; every version stored, yours to edit and replace.
Management-review minutes
Immutable per cycle, agenda rolled up from the assessment itself.
AI, with a leash
The scope drafter and minutes refiner use only the facts in your answers — the system prompt forbids inventing numbers, findings, documents or decisions.

Nobody should write an ISMS policy from a blank page.

The library

Everything is already drafted.

69
document templates
38
worklist items — 31 mandatory
102
risk scenarios, sector-aware
93
Annex A controls
Template · Clause 5

Information Security Policy

The top-level policy your certification body reads first — merged with your scope and context answers.

Mandatory
Template · Clause 6

Risk Treatment Plan

Generated from your live risk register — treatments, owners and dates, not boilerplate.

Mandatory
Template · Annex A 5.15

Access Control Policy

One of the curated Annex A priority documents in Section B of the worklist.

Recommended
Who does what

Built for the two sides of an ISMS.

Business side
Creator & Business Liaison
Answer the context questions, decide applicability, run the risk register, upload evidence, own controls. Stages one to four are yours.
GRC side
ISMS Manager
Owns the audit panel — findings, notes, required actions on every control. Working alone? Solo mode lets one person hold both roles honestly.

Seats are counted live from who actually holds a role — clear an owner and the seat frees immediately.

Pricing

Stage 1 free, then a flat monthly seat plan.

Define your context and scope without a card. When you continue to the Statement of Applicability, pick a plan — cancel any time, and your records remain yours to export.

Starter
$450
per month
  • 2 business seats + 1 GRC seat
  • All six stages, all exports
  • Full template library
Team
$750
per month
  • 4 business seats + 2 GRC seats
  • All six stages, all exports
  • Full template library
Enterprise
Custom
quoted per organisation
  • Unlimited seats
  • All six stages, all exports
  • Priced per quote, no surprises

Prices shown are current list prices in USD, monthly, no annual lock-in. What is free stays described honestly on the pricing page — including exactly where the paywall sits.

Fair questions

Before you start.

Is Stage 1 actually free?

Yes — the full context questionnaire, the AI-drafted scope statement, and its Word export. The paywall sits exactly at the start of Stage 2, and the product tells you before you reach it.

Do we need a consultant?

No. The workspace is built to be self-served: guided questions, pre-justified baseline controls, a risk library, and drafted templates. If you do work with one, invite them into a GRC seat.

What exactly happens at the paywall?

Mutating actions past Stage 1 return a clear "subscription required" response with a link to the plans page — nothing is silently lost, and your Stage 1 work is kept.

Can our certification auditor log in?

Not yet — a read-only auditor view is planned, and we mark it as planned rather than sell it. Today you hand the auditor the exported documents, which is what they ask for anyway.

Where does our data live?

In regXperience's cloud infrastructure, with evidence files in dedicated storage. Sign-in is your existing Google or Microsoft work account — no separate password to manage. The full plain-words version is on our Your data page.

Begin

Your scope statement, this afternoon.

Nineteen questions about your organisation. One formal, audit-ready scope statement out the other side. Free, and yours to keep.

Start free — define your scope

Sign in with your existing Google or Microsoft work account — no separate registration.

Sources
ISO/IEC 27001:2022

Information security management systems — requirements. The standard itself, at iso.org.

ISO Survey 2024

Source of the certificate count quoted above. Published by ISO.

The standard's text supersedes any summary on this page. We are a software workspace, not a certification body — certification is issued by your accredited auditor.

ISO 27001 — regXperience