UprootSecurity
Book a demo

ISO/IEC 27001:2022 · International certification · ISMS

FRAMEWORK

A certified ISMSthat runs itself.

ISO 27001 certifies a management system, not a moment in time. Uproot operates it as living infrastructure 93 Annex A controls mapped to your stack, a Statement of Applicability that maintains itself.

Start ISO 27001Talk to an ISO lead

Median time to Stage 2: 90 days

·

UKAS & ANAB-accredited bodies supported

app.uproot.security · /framework/iso-27001
27001ISO/IEC

acme-security · ISO 27001:2022

Stage 2 audit · 2026-08-10 · BSI

88%

cert-ready

79 in place9 in progress2 open3 N/A

Annex A · four themes

93 controls

A.5

Organizational

37 controls · A.5.1–A.5.37

91%

A.6

People

8 controls · A.6.1–A.6.8

100%

A.7

Physical

14 controls · A.7.1–A.7.14

79%

A.8

Technological

34 controls · A.8.1–A.8.34

85%

4–10

ISMS clauses · mandatory

Context → Improvement

94%

SoA version

v14 · live

Cert body

BSI · L. Osei

Days to Stage 2

41

SoA regenerated automatically

A new prod subnet triggered re-justification of A.8.20 network security. Applicability intact.

Annex A controls

93

Reorganized in the 2022 revision into four themes down from 114 controls across 14 domains in 2013.

ISMS clauses

7· 4–10

The mandatory management-system requirements. This is what actually gets certified.

Certification cycle

3years

Stage 1 + Stage 2, then annual surveillance audits, full recertification at year three.

Authority

ISO/IEC

Certified by an accredited body (UKAS, ANAB). A certification not an attestation.

Shared with SOC 2

~70%

Most Annex A controls map to SOC 2 Common Criteria. Do one, you've nearly done the other.

Annex A · 2022

Ninety-three controls, four themes. One Statement of Applicability.

The 2022 revision collapsed 14 domains into four readable themes. You justify each control's inclusion (or exclusion) in your Statement of Applicability. Uproot generates that document from your real environment and rewrites it the moment the environment changes.

37 controls
A.5

Organizational

Policies, roles, threat intel, suppliers, and incident management the biggest theme, and where most of the ISMS lives.

A.5.1 Policies · A.5.7 Threat intel · A.5.16 Identity · A.5.23 Cloud services · A.5.30 ICT continuity
Controls37 · A.5.1–A.5.37
A.6

People

Screening, terms of employment, awareness training, and offboarding.

A.6.1 Screening · A.6.3 Awareness · A.6.5 Post-termination
Controls8 · A.6.1–A.6.8
A.7

Physical

Secure areas, equipment, and utilities largely inherited from your cloud provider's audited data centers.

A.7.1 Perimeters · A.7.4 Monitoring · A.7.10 Storage media
Controls14 · A.7.1–A.7.14
A.8

Technological

Access control, cryptography, logging, secure development, network security where an engineering org actually lives.

A.8.5 Auth · A.8.16 Monitoring · A.8.24 Crypto · A.8.28 Secure coding
Controls34 · A.8.1–A.8.34
One control, end to end

Auditors don't want your monitoring policy. They want A.8.16 running.

Monitoring activities is the control teams most often "document" and least often prove. Here's how Uproot turns it into live evidence the certification body can read directly.

A.8.16 Monitoring activities

Networks, systems, and applications must be monitored for anomalous behaviour, with appropriate action taken to evaluate potential incidents. The control everyone writes a paragraph about and few can demonstrate on demand.

"When we evaluated our options for compliance and securing our systems, we found that UprootSecurity's compliance and security model aligned perfectly with our needs. It gave our team real-time visibility into the end-to-end process, saving our engineers hundreds of hours of manual effort."

— Yogesh Narayan, CTO

A.8.16 · MONITORING ACTIVITIES

Networks & applications are monitored

Last evidenced 09:14:02 UTC · 218 monitors · sha256 verified

In place
01

The control

What Annex A.8.16 asks for

“Networks, systems and applications shall be monitored for anomalous behaviour and appropriate actions taken to evaluate potential information security incidents.”
02

Your real stack

What we read from your systems

Uproot points at the systems that actually do the monitoring not the runbook that describes them.

datadog ·monitors.listaws ·guardduty.findingspagerduty ·escalation.policysentry ·alert.rules
03

Evidence collected

Cryptographic, timestamped, immutable

Monitor coverage, alert routing, and triage timings are pulled from source APIs, hashed, and stored. No CSV exports, no screenshots of a dashboard.

218 monitors ·liveGuardDuty ·enabled all regionsMTTA ·p95 6.1m0 silenced criticals
04

For the auditor

Read-only portal, mapped to the SoA

The BSI auditor opens A.8.16 in the scoped portal and sees the justification, the implementation, and six months of operating evidence already linked to your Statement of Applicability.

SoA · included  ·  Owner· Platform  ·  Nonconformities · 0

SOC 2 CC7.2NIST DE.CM-1CIS 8.11
Path to certification

From ISMS kickoff to a UKAS-accredited certificate.

A real path from a Series-B customer who already ran SOC 2 with Uproot. Net-new ISMS programs take a little longer at Stage 1.

Week 0

Scope the ISMS

Define boundaries, context, and interested parties. Uproot drafts the scope statement from your org and asset inventory.

Week 1–2

Generate the SoA

All 93 Annex A controls assessed against your stack. Inclusions justified, exclusions documented. Day-one coverage: 70–80%.

Week 3–6

Risk treatment

Risk register, treatment plan, and gap remediation issued as tickets to owners. Mandatory clauses 4–10 stood up.

Week 7–9

Stage 1 audit

Certification body reviews your ISMS documentation through the read-only portal. Findings closed before Stage 2.

5

Week 12–13

Stage 2 audit

The body tests that controls operate. Evidence is continuous, so there's nothing to scramble for.

6

Year 1–3

Certified + surveillance

Certificate issued. Annual surveillance audits read from the same live evidence. Recert at year three is a formality.

The consultancy way
  • ×

    A Statement of Applicability in a spreadsheet, accurate the day it’s signed and drifting ever after

  • ×

    A binder of policies nobody operates, assembled for the auditor and shelved until next year

  • ×

    A £30k consultant who leaves, taking the only understanding of your ISMS with them

  • ×

    Surveillance audits that re-trigger the panic every single year

With Uproot
  • An SoA generated from your environment and rewritten automatically when it changes

  • Controls that operate in production, with evidence pulled from the systems that enforce them

  • The ISMS lives in one place your whole team can read no single point of failure

  • Surveillance audits are a portal invite, not a fire drill

Evidence map

Where Annex A actually lives. Uproot reads it there.

A partial map of the evidence behind the Technological theme pulled from the systems that enforce each control, hashed and timestamped.

A.8

Access & auth

  • Okta · MFA + SSO

    312

  • AWS · IAM least-priv

    14 roles

  • GitHub · SSO enforced

    org

  • 1Password · secrets vault

    live

A.8

Crypto & data

  • AWS · KMS at rest

    all

  • ACM · TLS in transit

    1.2+

  • S3 · public-access block

    on

  • RDS · encryption

    enabled

A.8

Logging & monitor

  • Datadog · monitors

    218

  • CloudTrail · audit log

    multi-rgn

  • GuardDuty · threat det

    on

  • PagerDuty · on-call

    12w

A.8

Secure dev

  • GitHub · branch protect

    main

  • Snyk · dependency scan

    live

  • CircleCI · pipeline

    signed

  • Terraform · IaC review

    enforced

Certification bodies

Bring your accredited body. Or pick one of ours.

Only an accredited certification body can issue an ISO 27001 certificate. Uproot is body-agnostic and gives yours a read-only portal scoped to your ISMS UKAS, ANAB, or any IAF-recognized accreditation.

Auro Security

CPA FIRM

Atom Audit

CPA FIRM

Cert Pro

CPA FIRM

Johanson Group

CPA FIRM

Prescient Security

CPA FIRM

Tempo audits

CPA FIRM

A-lign

CPA FIRM

MJD Advisors

CPA FIRM

Attinkom

CPA FIRM

Darata

CPA FIRM

CyberFortify

CPA FIRM

+ 23 more

on request

ISO 27001, plainly

Questions we get every week. Answered the way an engineer would.

Is ISO 27001 the same as SOC 2?+

No, but they overlap heavily roughly 70% of controls. SOC 2 is a US attestation report; ISO 27001 is an international certification of your management system. Uproot maps both to the same evidence, so the second one is mostly already done.

What's the Statement of Applicability?+

The SoA lists all 93 Annex A controls and justifies whether each is included or excluded, with rationale. It’s the spine of your certification. Uproot generates it from your real environment and keeps it current automatically.

What's the difference between Stage 1 and Stage 2?+

Stage 1 is a documentation and readiness review does the ISMS exist and make sense. Stage 2 tests that the controls actually operate. With continuous evidence, Stage 2 stops being a scramble.

Do I need all 93 controls?+

No. You apply the controls relevant to your risks and justify any exclusions in the SoA. Most cloud-native companies exclude a handful of physical controls inherited from their provider’s audited data centers.

How long does certification last?+

Three years, with annual surveillance audits in between. Full recertification happens at year three. Because Uproot’s evidence is continuous, surveillance audits are low-drama.

2013 vs 2022 which version?+

ISO/IEC 27001:2022 is current; the 2013 version is being retired. Uproot ships the 2022 Annex A (93 controls, four themes) and handles the transition mapping if you’re migrating an older ISMS.

Run the ISMS. Earn the certificate.

Connect your stack, generate the Statement of Applicability, and watch readiness climb in real time. Invite your certification body when Stage 2 is a formality.

Start ISO 27001Talk to an ISO lead
$uproot init --framework iso27001
building Statement of Applicabilityok
93 Annex A controls assessedok
74 in place · 19 to remediate80%
SoA generated in 3m 48slive