When the auditor asks, answer with evidence.
A six-stage workspace that takes your organisation from a scope statement to management-review minutes. Every stage ends in a document your certification audit will ask for: a justified Statement of Applicability, a scored risk register, your ISMS policies, audited controls, dated minutes.
No compliance score. No invented percentages. Every answer traces to the clause behind it.
Stage 1 free · no card · sign in with your work account
Certification is not a form to fill. It is six pieces of evidence, produced in order.
Six stages, each one ends in a document.
Stages unlock in order; implementation and management review run in parallel once your Statement of Applicability is complete.
- 01ContextFree
- Define the context of your organization (Clause 4) — 19 guided questions, and an AI-drafted formal scope statement you approve.You produce A documented context and an agreed ISMS scope statement (.docx)
- 02Statement of Applicability
- Decide which of the 93 Annex A controls apply — and justify each. 17 baseline controls come pre-locked with their justification.You produce A complete, justified SoA (Word + Excel)
- 03Risk management
- Assess from a library of 102 scenarios (36 apply to every organisation), score on a 5×5 grid, and treat each risk down: avoid, mitigate, transfer, accept.You produce A scored inherent + residual risk register with treatment decisions
- 04Documents
- A 38-item worklist — 31 mandatory — assembled from 69 templates, merged with your answers and generated to Word. Edit offline, re-upload yours.You produce A complete, audit-ready set of ISMS policies and records
- 05Control implementation
- Capture evidence per control, assign owners, and take each through your internal audit — findings, corrective actions, target dates.You produce Every applicable control audited, with evidence and findings on record
- 06Management review
- Author the Clause 9.3 minutes: seven of twelve agenda items pre-fill from your live assessment; AI polishes your notes without inventing a word.You produce A dated, immutable management-review record, exported to Word
- 07External auditPlanned
- The planned seventh stage — a read-only, audit-ready view for your certification body. In development — we say so rather than sell it.
You are never lost.
Every assessment opens on one dashboard: six honest numbers, no invented score. When all six read complete, you are ready for your auditor — and you knew it before they did.
Illustrative — sample data, real dashboard.
What you walk out with.
- Statement of Applicability
- Cover page, control-by-control justification across all four Annex A themes — exported to Word and Excel.
- Risk register
- Inherent and residual scores with rationale on both sides, control mapping, treatment register — Word or Excel.
- ISMS document set
- Policies and records generated from your answers; every version stored, yours to edit and replace.
- Management-review minutes
- Immutable per cycle, agenda rolled up from the assessment itself.
- AI, with a leash
- The scope drafter and minutes refiner use only the facts in your answers — the system prompt forbids inventing numbers, findings, documents or decisions.
Nobody should write an ISMS policy from a blank page.
Everything is already drafted.
Information Security Policy
The top-level policy your certification body reads first — merged with your scope and context answers.
Risk Treatment Plan
Generated from your live risk register — treatments, owners and dates, not boilerplate.
Access Control Policy
One of the curated Annex A priority documents in Section B of the worklist.
Built for the two sides of an ISMS.
- Business sideCreator & Business Liaison
- Answer the context questions, decide applicability, run the risk register, upload evidence, own controls. Stages one to four are yours.
- GRC sideISMS Manager
- Owns the audit panel — findings, notes, required actions on every control. Working alone? Solo mode lets one person hold both roles honestly.
Seats are counted live from who actually holds a role — clear an owner and the seat frees immediately.
Stage 1 free, then a flat monthly seat plan.
Define your context and scope without a card. When you continue to the Statement of Applicability, pick a plan — cancel any time, and your records remain yours to export.
- 2 business seats + 1 GRC seat
- All six stages, all exports
- Full template library
- 4 business seats + 2 GRC seats
- All six stages, all exports
- Full template library
- Unlimited seats
- All six stages, all exports
- Priced per quote, no surprises
Prices shown are current list prices in USD, monthly, no annual lock-in. What is free stays described honestly on the pricing page — including exactly where the paywall sits.
Before you start.
Is Stage 1 actually free?
Yes — the full context questionnaire, the AI-drafted scope statement, and its Word export. The paywall sits exactly at the start of Stage 2, and the product tells you before you reach it.
Do we need a consultant?
No. The workspace is built to be self-served: guided questions, pre-justified baseline controls, a risk library, and drafted templates. If you do work with one, invite them into a GRC seat.
What exactly happens at the paywall?
Mutating actions past Stage 1 return a clear "subscription required" response with a link to the plans page — nothing is silently lost, and your Stage 1 work is kept.
Can our certification auditor log in?
Not yet — a read-only auditor view is planned, and we mark it as planned rather than sell it. Today you hand the auditor the exported documents, which is what they ask for anyway.
Where does our data live?
In regXperience's cloud infrastructure, with evidence files in dedicated storage. Sign-in is your existing Google or Microsoft work account — no separate password to manage. The full plain-words version is on our Your data page.
Your scope statement, this afternoon.
Nineteen questions about your organisation. One formal, audit-ready scope statement out the other side. Free, and yours to keep.
Start free — define your scopeSign in with your existing Google or Microsoft work account — no separate registration.
Information security management systems — requirements. The standard itself, at iso.org.
Source of the certificate count quoted above. Published by ISO.
The standard's text supersedes any summary on this page. We are a software workspace, not a certification body — certification is issued by your accredited auditor.