ISO 27001 for teams of 10–150 · EU-first

ISO 27001, minus the consultancy.

The management system behind certification — scoped in minutes, run as software, proven with records your auditor can verify. Flat-priced, self-serve, no sales call anywhere in the building.

€249/mo flat, excl. VAT · no card to start · cancel in-app anytime

5 of 6 shown — an example profile, not yours

Don't take our word for it — scope yourself

This is the product's actual scoping engine, running in your browser. Your answers stay on this page — nothing is sent anywhere.

Live demo · no signup

How many people are in the organization?

Question 1 of 7

A system of record, not a pile of templates

Everything an auditor will ask about lives in one place, versioned and connected — and the product always knows what your next step is. These are real screens from a demo organization.

Today: your path to certification

Readiness at a glance, the road to certification as an ordered checklist, and the operational numbers that slip — overdue tasks, expiring evidence, open corrective actions — before they become audit findings.

StandardOS dashboard: readiness, road to certification, operational stats

The SoA as a living document

All 93 controls with applicability, implementation status, and drafted justifications — reviewed control by control, exported as a hash-stamped PDF the moment your auditor asks.

StandardOS Statement of Applicability: controls with applicability decisions and justifications

Three steps to audit-ready

01

Scope in minutes

Answer seven questions and get a drafted Statement of Applicability — the master list of which of the 93 ISO 27001 controls apply to you and why — with a rationale against every one, ready to tailor.

02

Run the ISMS

Generated policies, a starter risk register, and a compliance calendar — editable, versioned, approved.

03

Prove it

Hash-stamped, tamper-evident PDFs and a one-click export your auditor understands instantly.

Why auditors relax when they see it

Records nobody can quietly rewrite. Including us.

Every change to your ISMS records is appended to a hash chain — each entry sealed with the fingerprint of the one before it, and with who made it. Backdate or edit history and the chain breaks, visibly. Every morning we email you your chain head, so the receipt lives in your mailbox rather than our database. Your exports carry the hashes and the content they cover, so your auditor can recompute the whole thing without us — we publish the rule and the script. We have not found another tool in this market that does.

Read the rule and the script

append-only · sha-256 chained · anchored daily to your inbox · verifiable without us

One price. No sales call.

€249/mo · excl. VAT

Flat, per organization. Every feature. Unlimited people.

Your certification body's audit fee is separate and paid to them — see what that costs.

  • All 93 ISO 27001:2022 controls + Statement of Applicability
  • Policy pack, risk register, compliance calendar
  • Tamper-evident records & one-click export
  • Unlimited people — no per-seat charge
  • Month-to-month · cancel in-app anytime
Start 14-day free trial

No card required to start · reminder email before any charge · cancellation policy

Sold to businesses and organizations only.

What's included, what isn't, and the total cost

Questions a careful buyer asks

Do I need a card to start?

No. The 14-day trial starts without payment details, and there is no auto-charge when it ends — a subscription begins only when you go through checkout yourself. We email you three days before the trial ends so the date is never a surprise. If you do nothing, you keep full access for five more days, then the workspace becomes read-only: nothing is deleted, and you can still sign in, read everything and export it all.

Is this consulting? Will someone call me?

No and no. StandardOS is software: the management system itself, with drafts generated for you to confirm. There is no sales team to call you — support is email, answered within one business day by the people who build the product.

Where is our data stored?

In the European Union (Ireland). StandardOS is operated by a Danish company under the GDPR. Our Article 28 data processing agreement is published in full at /legal/dpa — every customer, no signature and no sales call — and the Trust page lists every subprocessor and where each one processes data.

What does certification actually cost, in total?

Our €249/mo, plus an accredited certification body's audit fee — a separate company you pay directly. Nobody in this market publishes that fee, but it is auditor days × day rate and the days are fixed by ISO/IEC 27006, so you can work it out in advance. For a 25-person company it is roughly €8,000–€13,000 for initial certification and about a third of that annually after.

Work out your number →
How long does it take?

Four to seven months is realistic for a small software company. About three months is the floor no tool can beat: your internal audit and management review have to have actually happened before Stage 2, because the auditor samples those records. What software removes is the two-to-six months of building the system beforehand.

See the full timeline →
Does StandardOS cover the whole standard?

No — and the reason is not a missing feature. All 93 Annex A controls get a Statement of Applicability entry with a justification, and every one of the 26 management-system clauses in 4 to 10 has a place in the product. What no software can do is be the evidence: clause 5.1 is leadership demonstrating commitment, and every record still has to be something you actually wrote and meant. We print the clause-by-clause list before you pay, which most tools in this market do not.

See it clause by clause →
What if we want to leave?

Export everything, in open formats, with one click — during the trial, while subscribed, and for 90 days after cancelling. Cancellation itself is one click in Billing, effective end of the period.

Does StandardOS guarantee certification?

No tool can — certification is an accredited auditor's judgment of how your organization actually operates. What StandardOS does is make the system you'll be audited on: complete, consistent, and backed by records your auditor can verify.

Which standards are supported?

ISO/IEC 27001:2022 and ISO/IEC 42001:2023, the AI management system standard, with all 38 of its Annex A controls. Clauses 4 to 10 are the identical harmonised structure in every modern ISO standard — the same documents, risks, audits, reviews and corrective actions — so the machinery that runs one runs the other, and a record you keep for one counts towards both. We publish the clause-by-clause coverage for both before you pay.

See ISO 42001 →

Your auditor's first question is "show me your SoA."

Have a defensible draft before your coffee is cold — and the system to keep it true after.