ISO/IEC 27001:2022 · International certification · ISMS
FRAMEWORKISO 27001 certifies a management system, not a moment in time. Uproot operates it as living infrastructure 93 Annex A controls mapped to your stack, a Statement of Applicability that maintains itself.
Median time to Stage 2: 90 days
UKAS & ANAB-accredited bodies supported
acme-security · ISO 27001:2022
Stage 2 audit · 2026-08-10 · BSI
88%
cert-ready
Annex A · four themes
93 controls
Organizational
37 controls · A.5.1–A.5.37
91%
People
8 controls · A.6.1–A.6.8
100%
Physical
14 controls · A.7.1–A.7.14
79%
Technological
34 controls · A.8.1–A.8.34
85%
ISMS clauses · mandatory
Context → Improvement
94%
SoA version
v14 · live
Cert body
BSI · L. Osei
Days to Stage 2
41
SoA regenerated automatically
A new prod subnet triggered re-justification of A.8.20 network security. Applicability intact.
Annex A controls
93Reorganized in the 2022 revision into four themes down from 114 controls across 14 domains in 2013.
ISMS clauses
7· 4–10The mandatory management-system requirements. This is what actually gets certified.
Certification cycle
3yearsStage 1 + Stage 2, then annual surveillance audits, full recertification at year three.
Authority
ISO/IECCertified by an accredited body (UKAS, ANAB). A certification not an attestation.
Shared with SOC 2
~70%Most Annex A controls map to SOC 2 Common Criteria. Do one, you've nearly done the other.
The 2022 revision collapsed 14 domains into four readable themes. You justify each control's inclusion (or exclusion) in your Statement of Applicability. Uproot generates that document from your real environment and rewrites it the moment the environment changes.
Organizational
Policies, roles, threat intel, suppliers, and incident management the biggest theme, and where most of the ISMS lives.
People
Screening, terms of employment, awareness training, and offboarding.
Physical
Secure areas, equipment, and utilities largely inherited from your cloud provider's audited data centers.
Technological
Access control, cryptography, logging, secure development, network security where an engineering org actually lives.
Monitoring activities is the control teams most often "document" and least often prove. Here's how Uproot turns it into live evidence the certification body can read directly.
Networks, systems, and applications must be monitored for anomalous behaviour, with appropriate action taken to evaluate potential incidents. The control everyone writes a paragraph about and few can demonstrate on demand.
"When we evaluated our options for compliance and securing our systems, we found that UprootSecurity's compliance and security model aligned perfectly with our needs. It gave our team real-time visibility into the end-to-end process, saving our engineers hundreds of hours of manual effort."
A.8.16 · MONITORING ACTIVITIES
Networks & applications are monitored
Last evidenced 09:14:02 UTC · 218 monitors · sha256 verified
The control
What Annex A.8.16 asks for
Your real stack
What we read from your systems
Uproot points at the systems that actually do the monitoring not the runbook that describes them.
Evidence collected
Cryptographic, timestamped, immutable
Monitor coverage, alert routing, and triage timings are pulled from source APIs, hashed, and stored. No CSV exports, no screenshots of a dashboard.
For the auditor
Read-only portal, mapped to the SoA
The BSI auditor opens A.8.16 in the scoped portal and sees the justification, the implementation, and six months of operating evidence already linked to your Statement of Applicability.
SoA · included · Owner· Platform · Nonconformities · 0
A real path from a Series-B customer who already ran SOC 2 with Uproot. Net-new ISMS programs take a little longer at Stage 1.
Week 0
Scope the ISMS
Define boundaries, context, and interested parties. Uproot drafts the scope statement from your org and asset inventory.
Week 1–2
Generate the SoA
All 93 Annex A controls assessed against your stack. Inclusions justified, exclusions documented. Day-one coverage: 70–80%.
Week 3–6
Risk treatment
Risk register, treatment plan, and gap remediation issued as tickets to owners. Mandatory clauses 4–10 stood up.
Week 7–9
Stage 1 audit
Certification body reviews your ISMS documentation through the read-only portal. Findings closed before Stage 2.
Week 12–13
Stage 2 audit
The body tests that controls operate. Evidence is continuous, so there's nothing to scramble for.
Year 1–3
Certified + surveillance
Certificate issued. Annual surveillance audits read from the same live evidence. Recert at year three is a formality.
A Statement of Applicability in a spreadsheet, accurate the day it’s signed and drifting ever after
A binder of policies nobody operates, assembled for the auditor and shelved until next year
A £30k consultant who leaves, taking the only understanding of your ISMS with them
Surveillance audits that re-trigger the panic every single year
An SoA generated from your environment and rewritten automatically when it changes
Controls that operate in production, with evidence pulled from the systems that enforce them
The ISMS lives in one place your whole team can read no single point of failure
Surveillance audits are a portal invite, not a fire drill
A partial map of the evidence behind the Technological theme pulled from the systems that enforce each control, hashed and timestamped.
Access & auth
Okta · MFA + SSO
312
AWS · IAM least-priv
14 roles
GitHub · SSO enforced
org
1Password · secrets vault
live
Crypto & data
AWS · KMS at rest
all
ACM · TLS in transit
1.2+
S3 · public-access block
on
RDS · encryption
enabled
Logging & monitor
Datadog · monitors
218
CloudTrail · audit log
multi-rgn
GuardDuty · threat det
on
PagerDuty · on-call
12w
Secure dev
GitHub · branch protect
main
Snyk · dependency scan
live
CircleCI · pipeline
signed
Terraform · IaC review
enforced
Only an accredited certification body can issue an ISO 27001 certificate. Uproot is body-agnostic and gives yours a read-only portal scoped to your ISMS UKAS, ANAB, or any IAF-recognized accreditation.
Auro Security
CPA FIRM
Atom Audit
CPA FIRM
Cert Pro
CPA FIRM
Johanson Group
CPA FIRM
Prescient Security
CPA FIRM
Tempo audits
CPA FIRM
A-lign
CPA FIRM
MJD Advisors
CPA FIRM
Attinkom
CPA FIRM
Darata
CPA FIRM
CyberFortify
CPA FIRM
+ 23 more
on request
No, but they overlap heavily roughly 70% of controls. SOC 2 is a US attestation report; ISO 27001 is an international certification of your management system. Uproot maps both to the same evidence, so the second one is mostly already done.
The SoA lists all 93 Annex A controls and justifies whether each is included or excluded, with rationale. It’s the spine of your certification. Uproot generates it from your real environment and keeps it current automatically.
Stage 1 is a documentation and readiness review does the ISMS exist and make sense. Stage 2 tests that the controls actually operate. With continuous evidence, Stage 2 stops being a scramble.
No. You apply the controls relevant to your risks and justify any exclusions in the SoA. Most cloud-native companies exclude a handful of physical controls inherited from their provider’s audited data centers.
Three years, with annual surveillance audits in between. Full recertification happens at year three. Because Uproot’s evidence is continuous, surveillance audits are low-drama.
ISO/IEC 27001:2022 is current; the 2013 version is being retired. Uproot ships the 2022 Annex A (93 controls, four themes) and handles the transition mapping if you’re migrating an older ISMS.
Connect your stack, generate the Statement of Applicability, and watch readiness climb in real time. Invite your certification body when Stage 2 is a formality.