ISO27K

What an ISMS needs before you buy tooling

ISO 27001 asks for a defined list of documented information and records. None of it names a product. This page is the list, then the honest question of when software is worth paying for.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

An ISO 27001 management system needs eleven documented outputs before it needs any software: a scope statement, an information security policy, a risk assessment method, a risk assessment result, a risk treatment plan, a Statement of Applicability, the operational records the controls produce, competence and awareness records, internal audit records, management review minutes, and a log of nonconformities and corrective actions. Clauses 4 through 10 name all of them. None of the clauses names a vendor, a category of vendor, or a format. A certification body will accept a folder structure and a spreadsheet, and plenty of certified companies use exactly that.

11 Documented outputs the clauses require by name

$0 Minimum defensible year-one tooling cost, CAD

The artifacts the standard actually names

This is the table to work from. The left column is what you have to be able to hand over, the middle is where the requirement comes from, and the right is the smallest thing that satisfies it. A certification body audits the content, not the container.

ISO 27001:2022 documented information and records, and the minimum acceptable form
ArtifactWhere it is requiredMinimum acceptable form
Scope statementClause 4.3One page naming services, systems, locations and legal entities
Information security policyClause 5.2A short approved document signed by the accountable executive
Risk assessment methodClause 6.1.2A written method: criteria, scale, who scores, how often
Risk assessment resultsClause 6.1.2A register with an owner, a level and a decision per risk
Risk treatment planClause 6.1.3Treatments with owners and dates, traceable to risks
Statement of ApplicabilityClause 6.1.3 d)93 rows, four columns, justifications written as sentences
Security objectivesClause 6.2Measurable objectives with a target and a review date
Competence and awareness recordsClauses 7.2 and 7.3Training completion records with dates and names
Operational evidenceClause 8.1Access reviews, supplier reviews, backup and change records
Internal audit program recordsClause 9.2A plan, the audit report, and the findings raised
Management review minutesClause 9.3Minutes covering the required inputs, with decisions recorded
Nonconformity and corrective action logClause 10.2A log with root cause, action, owner and closure date

Twelve rows for eleven outputs, because objectives and the policy are often written into the same document and audited separately. The documentation page goes through what each one should contain, and the Statement of Applicability is the one worth reading before you write anything else, because it is where the other artifacts join up.

Documents and records are not the same problem

Most tooling arguments are really arguments about the second category, and the two behave completely differently once an audit window opens.

Documented information
Things you write once and then maintain: the scope, the policy, the risk method, the Statement of Applicability. Volume is low, change is slow, and version control plus an approval date is the entire requirement.
Records
Things the system produces as it runs: quarterly access reviews, supplier reviews, training completions, incident tickets, backup restore tests. Volume grows every month, and the auditor samples them by date.
Evidence register
The index that says which record answers which control, who owns it, how often it must be produced, and when it was last produced. It is not required by name in the standard. It is what stops the fortnight of hunting before stage 2.

Documents are a filing problem and any drive solves it. Records are a recurrence problem, and that is where a company either builds a register or spends the run-up to the audit reconstructing nine months of history. The question of whether to buy software is almost always a question about the records.

The order to produce them in

Producing these out of order is the most expensive mistake available, and it is easy to make because the Statement of Applicability is the artifact everyone has heard of.

  1. Write the scope. Everything below is scoped by it, and it goes on the certificate.
  2. Build the asset, data and supplier inventory. It is not a required artifact, and every required artifact below depends on it.
  3. Write the risk method, then run the assessment against the inventory.
  4. Decide treatments, and only then write the Statement of Applicability, so each control decision traces to a risk you can point at.
  5. Set up the evidence register before the controls start running, naming the record, the owner and the frequency for each one.
  6. Operate for at least three months and let the records accumulate on their own schedule.
  7. Run the internal audit, hold the management review, log what came out of both.

The full eleven-phase version with durations is on the implementation page. What matters here is that step 5 is the only one where tooling changes the outcome, and it is also the step most companies leave until the auditor is booked.

Check what you already have

Most companies partway through discover they hold more than they thought and that none of it is indexed. Work down this list before pricing anything.

0 of 0 in place ·

What the tooling options cost in CAD

There are three ways companies hold this material, and the year-one difference is the whole reason the question comes up.

Year-one cost of holding ISO 27001 artifacts, Canadian companies, 2026
ApproachYear one (CAD)What you getWhere it strains
Drive and spreadsheets $0 Documents versioned, records filed by hand No index from control to record, so the run-up to stage 2 is manual
Free compliance workspace $0 Control set written out, evidence register, risk register, policy templates, readiness scoring No automated collection, so someone still has to upload the records
Paid compliance platform $7,500 to $50,000 Continuous monitoring wired into your cloud, automated evidence collection, multi-framework mapping Priced per year and renews, and it collects nothing your cloud does not emit
Difference over three years$22,500 to $150,000Platform subscriptions renew. Budget them as an operating cost, not a project cost.

The platform band is wide because it covers everything from a single framework at a small company up to several frameworks with an audit-support tier attached. A Canadian company buying a platform for ISO 27001 alone usually lands in the lower half of it, around $8,000 to $30,000 CAD a year, and the cost breakdown puts that figure next to the certification body fee and the testing line, which is the comparison that usually settles the argument.

What a free workspace covers

A free workspace sits in the middle row of that table and it is a real option, not a compromise, for a company that has not yet started collecting records. TrazTech, which operates this site, runs one: traztech Workspace covers 14 frameworks including ISO 27001, with guided self-assessments, an evidence register mapped to controls, 40 policy templates with approval history, a risk register, vendor risk questionnaires and readiness scoring. There is no credit card, no trial period, no paid tier, no seat limit and no export fee, and if you hire the firm it is included at the same cost, which is nothing. Data stays in the workspace when an engagement ends. It is one option among several, and the row above it in the table is still perfectly defensible if your record volume is genuinely small.

What it does not do is watch your cloud. Nobody should choose it expecting that.

When a paid platform is the right purchase

Vanta and Drata are good products and thousands of companies certify with them. They do automated, continuous monitoring wired into your cloud accounts, which is a genuinely different job from organizing the artifacts on this page. Buy one when the evidence you need is machine-generated and continuous: cloud configuration drift, endpoint posture across a fleet you cannot poll by hand, or two or more frameworks running at once with overlapping control sets. Above roughly 30 people, or with ISO 27001 and SOC 2 in flight together, the automation earns the subscription quickly.

The question that decides it

Not headcount, and not budget. Ask how much of your required evidence a machine could collect without a person doing anything. If the honest answer is most of it, because your environment is cloud-native and your controls are technical, a platform saves real work every month and the subscription is cheap next to the time. If the honest answer is that your evidence is quarterly access reviews done by a person, supplier reviews done by a person and training records exported once a year, no amount of automation collects it and you are paying for a control mapping you could have written down.

Either way, the artifacts come first. A platform bought before the scope is written produces a mapped control set for a scope nobody has agreed to, which is the most common way a company spends money in month one and still fails stage 1. Work through the gap assessment first, and price tooling against what it finds.

Get a view on what you already have

Tell us your scope and where you are, and we will match you with Canadian firms that do ISO 27001 readiness work.

Get matched

Common questions

Can we get ISO 27001 certified using only spreadsheets?

Yes. ISO 27001 predates the compliance platforms by two decades and certification bodies audit content rather than format. What a spreadsheet does not give you is an index from each control to the record that proves it, so build that index deliberately or the weeks before stage 2 become a search operation.

Is a free compliance workspace enough for a first certification?

For a company whose evidence is mostly produced by people rather than machines, yes. A workspace that holds the control set, the evidence register, the risk register and the policies covers every artifact this page lists. It does not do continuous monitoring, so if your auditor or your customers expect configuration drift to be caught automatically, you need a paid platform as well as the artifacts, not instead of them.

When should we buy Vanta or Drata instead?

When most of your evidence is machine-generated, when you are running two or more frameworks at once, or when you are past roughly 30 people and the manual collection is eating a day a week. They do automated continuous monitoring against your cloud, which no document repository or free workspace does. Any firm that tells you a workspace replaces them is selling you something.

How many Annex A controls do we have to document?

All 93, in the Statement of Applicability, including the ones you exclude. Exclusions need a written justification. Separately, the 25 clause requirements in clauses 4 through 10 are not optional and cannot be excluded, which is why they are never expressed as a combined number with the Annex A controls.

Does a compliance platform write the Statement of Applicability?

It generates a draft from its own control mapping. The justification column comes out generic, and a stage 1 auditor reads that column first. Treat a generated Statement of Applicability as typing you did not have to do, then rewrite the justifications in your own words against your own risk assessment.