KoComplyAgentic Compliance
ISO 27001 guide

ISO 27001 certification,without a six-month project.

ISO 27001 is the international standard for an information security management system. Unlike SOC 2 it results in a certificate, recognised by buyers across Europe, the Middle East and APAC. This guide covers the ISMS, the Statement of Applicability, the 93 Annex A controls of the 2022 revision, and the two-stage certification audit.

93
Annex A controls in ISO 27001:2022
3 yrs
Certificate validity with annual surveillance
2 stages
Documentation review, then certification audit
2–4 wks
To readiness with KoComply agents

Get a plan for your program

Tell us where you are and we'll send dates, effort and one simple all-inclusive price — plus your Startup Access pricing.

No spam. One reply from a real compliance architect.

The ISMS is the deliverable

ISO 27001 certifies a management system, not a product. Auditors look for a defined scope, leadership commitment, a risk assessment methodology, a treatment plan, measurable objectives, internal audit and management review. Documentation matters as much as tooling.

Statement of Applicability

The SoA lists every Annex A control, whether it applies, why, and its implementation status. It is the first document a certification body reads, and the fastest way to fail Stage 1 is an SoA that does not match reality. KoComply drafts it from your live estate rather than a template.

Annex A in the 2022 revision

The 2022 revision reorganised controls into four themes — organisational, people, physical and technological — and added eleven new ones covering threat intelligence, cloud services, data leakage prevention, secure coding and monitoring.

  • Organisational: policies, roles, supplier and cloud security
  • People: screening, awareness, remote working, disciplinary process
  • Physical: offices, equipment, secure disposal, clear desk
  • Technological: access control, cryptography, logging, secure development

Stage 1 and Stage 2

Stage 1 is a documentation review that confirms your ISMS exists and is ready to test. Stage 2 tests operating effectiveness through interviews and evidence sampling. Certificates run three years with annual surveillance audits in between.

How KoComply gets you there

Day 1–3

Define the ISMS scope

Agents read your product, cloud and org data to draft scope, context, interested parties and objectives.

Week 1

Risk register and SoA

A risk assessment is generated from your business model and stack, then mapped to Annex A with justifications.

Week 2

Controls and evidence

Policies, training, access reviews and supplier assessments run continuously with evidence collected daily.

Week 3–4

Internal audit and Stage 1

Internal audit and management review are packaged so the certification body can start Stage 1.

Founders building trust with KoComply

"People tasks got auto-completed, repos were classified automatically, and evidence just appeared. The fastest path to compliance I've seen."
Deepesh JayalFounder
"KoComply gave me AWS and codebase compliance posture in one view with clear steps to fix each issue and auto-added remediation tags. Saved weeks of work figuring out what to fix to be compliant."
HarshSr. Software Engineer
"KoComply turned a confusing compliance project into a clear, agent-driven workflow. We always knew the next step and who owned it."
VitragFounder

Frequently asked questions

How much does ISO 27001 cost?

With KoComply it's one simple all-inclusive price covering the agentic GRC platform, the full program and the certification audit — no separate auditor bill. Qualifying early-stage startups get exclusive KoComply Startup Access pricing and can pay in stages.

Is ISO 27001 better than SOC 2?

Neither is better. ISO 27001 opens Europe, the Middle East and APAC; SOC 2 opens US enterprise. Controls overlap heavily, so the second framework is much cheaper than the first.

Do we need an internal audit?

Yes. Internal audit and management review are mandatory clauses. Agents prepare both, including findings, corrective actions and minutes.

How fast can we certify?

Readiness in 2–4 weeks; the certification body then schedules Stage 1 and Stage 2, usually a few weeks apart.

Become compliance ready in 2–4 weeks

One price to KoComply covers everything — agentic GRC and the audit, all inclusive. Qualifying early-stage startups get Startup Access pricing and can pay in stages.