Frameworks · ISO/IEC 27001:2022
ISO/IEC 27001: certify your information security management system.
We prepare and support your organization to certify ISO/IEC 27001:2022 — with an ISMS that stays valid between surveillance audits.
Who it applies to
ISO/IEC 27001 applies to any organization that manages sensitive information and needs to demonstrate that it protects it. It’s especially relevant when certification is a commercial or contractual requirement.
What the framework requires
The standard requires establishing, maintaining and improving a risk-based Information Security Management System (ISMS), together with the applicable controls from Annex A.
Clauses 4–10
Risk management
Annex A · 93 controls
Statement of applicability
Risks of not acting
- Being excluded from tenders and contracts that require a valid certification.
- Managing security without a risk-based framework or formal evidence.
- Facing audits with recurring findings and last-minute remediation.
- Losing traceability between controls, risks and evidence.
The i-Prot proposal
We design and implement the ISMS, define the risk assessment and the statement of applicability, and prepare the organization for the certification audit. All integrated into the CGF governance cycle, so the certification holds over time.
How we work with this framework
Assessment and gap analysis
Risk assessment and SoA
Controls implementation
Internal audit and review
Certification and upkeep
Deliverables
- Gap analysis
- Implementation plan
- Controls matrix
- System documentation
- Evidence
- Internal audit
- Management review
- Roadmap
How it connects with CGF
CGF uses ISO/IEC 27001 as a source of requirements. This framework mainly covers the Design, Implement, Operate & measure, and Improve stages of the cycle.
See the CGF methodology →
Complyze and ISO/IEC 27001
Complyze centralizes the 93 Annex A controls, their evidence and compliance status, and keeps progress by clause visible. Frameworks are the natural entry point to the platform.
Frequently asked questions
Ready to certify ISO/IEC 27001?
Tell us your context and we’ll propose a path to certification tailored to your organization.
By submitting you accept our privacy policy.