UprootSecurity
Book a demo

ISO/IEC 27001:2022 · International certification · ISMS

FRAMEWORK

ISO 27001 certification,explained and automated.

ISO 27001 certifies an information security management system the processes by which you run security against 93 Annex A controls. An accredited body audits it in two stages, then surveils it annually.

Start ISO 27001Talk to an ISO lead

Median time to Stage 2: 90 days

·

UKAS & ANAB-accredited bodies supported

The Uproot Security app on the ISO 27001:2022 framework screen: 123 requirements across 11 categories, with per-control test status against the ISMS scope.
ISO 27001

What goes in your Statement of Applicability?

Your Statement of Applicability lists all 93 Annex A controls and records, for each one, whether it applies and why. Excluding a control is allowed justifying the exclusion is mandatory. The certification body audits the SoA before it audits anything else.

Last reviewed

Annex A controls

93

Reorganized in the 2022 revision into four themes down from 114 controls across 14 domains in 2013.

ISMS clauses

7· 4–10

The mandatory management-system requirements. This is what actually gets certified.

Certification cycle

3years

Stage 1 + Stage 2, then annual surveillance audits, full recertification at year three.

Authority

ISO/IEC

Certified by an accredited body (UKAS, ANAB). A certification not an attestation.

Shared with SOC 2

~70%

Most Annex A controls map to SOC 2 Common Criteria. Do one, you've nearly done the other.

Annex A · 2022

Ninety-three controls, four themes. One Statement of Applicability.

The 2022 revision collapsed 14 domains into four readable themes. You justify each control's inclusion (or exclusion) in your Statement of Applicability. Uproot generates that document from your real environment and rewrites it the moment the environment changes.

37 controls
A.5

Organizational

Policies, roles, threat intel, suppliers, and incident management the biggest theme, and where most of the ISMS lives.

A.5.1 Policies · A.5.7 Threat intel · A.5.16 Identity · A.5.23 Cloud services · A.5.30 ICT continuity
Controls37 · A.5.1–A.5.37
A.6

People

Screening, terms of employment, awareness training, and offboarding.

A.6.1 Screening · A.6.3 Awareness · A.6.5 Post-termination
Controls8 · A.6.1–A.6.8
A.7

Physical

Secure areas, equipment, and utilities largely inherited from your cloud provider's audited data centers.

A.7.1 Perimeters · A.7.4 Monitoring · A.7.10 Storage media
Controls14 · A.7.1–A.7.14
A.8

Technological

Access control, cryptography, logging, secure development, network security where an engineering org actually lives.

A.8.5 Auth · A.8.16 Monitoring · A.8.24 Crypto · A.8.28 Secure coding
Controls34 · A.8.1–A.8.34
Path to certification

From ISMS kickoff to a UKAS-accredited certificate.

A real path from a Series-B customer who already ran SOC 2 with Uproot. Net-new ISMS programs take a little longer at Stage 1.

Week 0

Scope the ISMS

Define boundaries, context, and interested parties. Uproot drafts the scope statement from your org and asset inventory.

Week 1–2

Generate the SoA

All 93 Annex A controls assessed against your stack. Inclusions justified, exclusions documented. Day-one coverage: 70–80%.

Week 3–6

Risk treatment

Risk register, treatment plan, and gap remediation issued as tickets to owners. Mandatory clauses 4–10 stood up.

Week 7–9

Stage 1 audit

Certification body reviews your ISMS documentation through the read-only portal. Findings closed before Stage 2.

5

Week 12–13

Stage 2 audit

The body tests that controls operate. Evidence is continuous, so there's nothing to scramble for.

6

Year 1–3

Certified + surveillance

Certificate issued. Annual surveillance audits read from the same live evidence. Recert at year three is a formality.

The consultancy way
  • ×

    A Statement of Applicability in a spreadsheet, accurate the day it’s signed and drifting ever after

  • ×

    A binder of policies nobody operates, assembled for the auditor and shelved until next year

  • ×

    A £30k consultant who leaves, taking the only understanding of your ISMS with them

  • ×

    Surveillance audits that re-trigger the panic every single year

With Uproot
  • An SoA generated from your environment and rewritten automatically when it changes

  • Controls that operate in production, with evidence pulled from the systems that enforce them

  • The ISMS lives in one place your whole team can read no single point of failure

  • Surveillance audits are a portal invite, not a fire drill

Evidence map

Where Annex A actually lives. Uproot reads it there.

A partial map of the evidence behind the Technological theme pulled from the systems that enforce each control, hashed and timestamped.

A.8

Access & auth

  • Okta · MFA + SSO

    312

  • AWS · IAM least-priv

    14 roles

  • GitHub · SSO enforced

    org

  • 1Password · secrets vault

    live

A.8

Crypto & data

  • AWS · KMS at rest

    all

  • ACM · TLS in transit

    1.2+

  • S3 · public-access block

    on

  • RDS · encryption

    enabled

A.8

Logging & monitor

  • Datadog · monitors

    218

  • CloudTrail · audit log

    multi-rgn

  • GuardDuty · threat det

    on

  • PagerDuty · on-call

    12w

A.8

Secure dev

  • GitHub · branch protect

    main

  • Snyk · dependency scan

    live

  • CircleCI · pipeline

    signed

  • Terraform · IaC review

    enforced

Certification bodies

Bring your accredited body. Or pick one of ours.

Only an accredited certification body can issue an ISO 27001 certificate. Uproot is body-agnostic and gives yours a read-only portal scoped to your ISMS UKAS, ANAB, or any IAF-recognized accreditation.

Auro Security

CPA FIRM

Atom Audit

CPA FIRM

Cert Pro

CPA FIRM

Johanson Group

CPA FIRM

Prescient Security

CPA FIRM

Tempo audits

CPA FIRM

A-lign

CPA FIRM

MJD Advisors

CPA FIRM

Attinkom

CPA FIRM

Darata

CPA FIRM

Glocert

CPA FIRM

+ 23 more

on request

Everything on ISO 27001

8 articles

ISO 27001 certification process, Annex A controls, ISMS scope and ISO 42001 for AI management.

What ISO 27001 is

The standard, its structure, and the 93 Annex A controls.

  • What is ISO 27001? Everything You Need to Know

Tooling and adjacent standards

Risk software, and the AI management standard built on the same ISMS.

ISO 27001, plainly

Questions we get every week. Answered the way an engineer would.

Is ISO 27001 the same as SOC 2?+

No, but they overlap heavily roughly 70% of controls. SOC 2 is a US attestation report; ISO 27001 is an international certification of your management system. Uproot maps both to the same evidence, so the second one is mostly already done.

What's the Statement of Applicability?+

The SoA lists all 93 Annex A controls and justifies whether each is included or excluded, with rationale. It’s the spine of your certification. Uproot generates it from your real environment and keeps it current automatically.

What's the difference between Stage 1 and Stage 2?+

Stage 1 is a documentation and readiness review does the ISMS exist and make sense. Stage 2 tests that the controls actually operate. With continuous evidence, Stage 2 stops being a scramble.

Do I need all 93 controls?+

No. You apply the controls relevant to your risks and justify any exclusions in the SoA. Most cloud-native companies exclude a handful of physical controls inherited from their provider’s audited data centers.

How long does certification last?+

Three years, with annual surveillance audits in between. Full recertification happens at year three. Because Uproot’s evidence is continuous, surveillance audits are low-drama.

2013 vs 2022 which version?+

ISO/IEC 27001:2022 is current; the 2013 version is being retired. Uproot ships the 2022 Annex A (93 controls, four themes) and handles the transition mapping if you’re migrating an older ISMS.

Run the ISMS. Earn the certificate.

Connect your stack, generate the Statement of Applicability, and watch readiness climb in real time. Invite your certification body when Stage 2 is a formality.

Start ISO 27001Talk to an ISO lead
$uproot init --framework iso27001
building Statement of Applicabilityok
93 Annex A controls assessedok
74 in place · 19 to remediate80%
SoA generated in 3m 48slive