Every framework, one subscription

Every framework you adopt, run from one system.

A few questions, one button, and it stays compliant.

€249/mo flat, excl. VAT · no card to start · cancel in-app anytime

Frameworks

8 frameworks

  • ISO27001
    76%71/93
  • CRA
    78%7/9
  • NIS2
    80%8/10
  • ISO42001
    32%12/38
  • GDPR
    79%19/24
  • DORA
    24%4/17
  • AIACT
    35%6/17
  • MR
    11%1/9
An example profile, not yours

For ISO 27001, ISO 42001 and ISO 9001

Get certified, then stay certified

Support is included and answered within one business day by the people who build the product, before the certificate and through every surveillance year after it.

ISO27001ISO42001ISO9001

You do not need to be an expert.

Now in force . Reporting duties apply since 11 Sept 2026.

My product falls under the CRA.

Reporting duty
live
Technical file
Register my product

We need ISO 27001 and I am not an expert.

  1. 1. 10 questions
  2. 2. your system, built
  3. 3. we keep it running
Answer the 10 questions

€249/moevery feature14 days freeno card

Don't take our word for it. Scope yourself

This is the product's actual scoping engine, running in your browser. Your answers stay on this page. Nothing is sent anywhere.

Live demo · no signup

How many people are in the organization?

Question 1 of 7

Three dates the EU has already set

The obligations are written, the dates are fixed, and the documentation each one wants is what StandardOS drafts.

  • CRA: report an exploited vulnerability in 24 hours

    Article 14 makes reporting a duty for anyone placing a product with digital elements on the EU market. Two destinations, three deadlines, one clock that starts when you become aware.

    The reporting deadlines
  • Machinery Regulation: the technical file

    Regulation (EU) 2023/1230 replaces the Machinery Directive. A manufacturer needs the file, the declaration and the essential health and safety requirements assessed.

    What the file contains
  • CRA: the full technical documentation

    From December 2027 a product needs its Annex I assessment, its vulnerability handling, and a technical file an authority can ask for. 11 controlled documents.

    The CRA technical file

A system of record, not a pile of templates

Everything an auditor will ask about lives in one place, versioned and connected, and the product always knows what your next step is. Below are the two artefacts they read first, at the size they are read.

Today: your path to certification

Readiness at a glance, the road to certification as an ordered checklist, and the operational numbers that slip (overdue tasks, expiring evidence, open corrective actions) before they become audit findings.

Controlled documentv4Approved

Access Control Policy

Approved by
Jonas Weber, CISO
Approved on
Supersedes
v3 · 2025-11-02

sha256

9f2a1c77d0b4e83a5f6c2d19b7e4a08c3d5f91b2e7c46a80d1f3b5927ce4a061

Chain intact, anchored2026-09-07

A worked example, not a customer's record.

The SoA as a living document

All 93 controls with applicability, implementation status, and drafted justifications, reviewed control by control, exported as a hash-stamped PDF the moment your auditor asks.

Statement of ApplicabilityISO/IEC 27001:2022
A.8.24

Use of cryptography

Applicable

Justification

Customer data is encrypted at rest and in transit. TLS 1.2 and above is enforced at the edge, and database encryption is managed by the provider under the agreement in our supplier register.

Drafted by StandardOS from your scoping answers, edited by you on 3 August 2026.

A worked example, not a customer's record.

It signs in and checks, every day

A template pack tells you what to do. This connects to the 12 systems you already run and re-verifies 125 controls against them, on your own tenants, with read-only credentials you grant and can revoke.

125

checks re-run every day, against your own systems

  • Cloud infrastructure

    62

    Amazon Web Services · Microsoft Azure · Google Cloud

  • Identity and directory

    26

    Microsoft Entra ID · Okta · Google Workspace

  • Managed devices

    18

    Kandji · Jamf Pro · Microsoft Intune

  • Source code

    8

    GitHub

  • Vulnerability management

    6

    Snyk

  • HR system

    5

    Personio

Evidence collected this way carries the date it was read and the account it was read from, so it does not go stale between audits. When a check that was passing starts failing, the owners and admins hear about it the same day rather than the week before the audit.

Every check, and the scopes each connection asks for

Three steps to audit-ready

  1. 01

    Scope in minutes

    Answer seven questions and get a drafted Statement of Applicability (the master list of which of the 93 ISO 27001 controls apply to you and why) with a rationale against every one, ready to tailor.

  2. 02

    Run the ISMS

    Generated policies, a starter risk register, and a compliance calendar, all editable, versioned and approved. Then it keeps going: evidence carries an expiry date, connected systems refresh it on their own, and anything about to lapse reaches you before it does.

  3. 03

    Prove it

    Hash-stamped, tamper-evident PDFs and a one-click export your auditor understands instantly.

04Your certification auditBooked with an accredited body, which reads the four documents and checks they describe one organisation. That is the whole of Stage 1.

Why auditors relax when they see it

Records nobody can quietly rewrite. Including us.

Every change to your ISMS records is appended to a hash chain, each entry sealed with the fingerprint of the one before it and with who made it.

Breaking it shows
Backdate an entry or edit history and the chain breaks, visibly. There is no delete path, for anyone, including us.
A copy we cannot reach
Every morning we email your chain head to your owners and admins, so the receipt sits in your mailbox rather than in our database.
Checkable without us
Exports carry the hashes and the content they are computed over. Your auditor can recompute the whole chain; we publish the rule and the script.
Read the rule and the script

append-only · sha-256 chained · anchored daily to your inbox · verifiable without us

The questions your security review will ask

You are buying an information-security tool, so it goes through the same vendor review as everything else. Those answers were already published. They were not on this page.

Where does the data live?
The EU, and only the EU. Customer records are in Supabase's Ireland region, and every service that touches them is pinned to an EU region.
Hosting, backups and recovery
Can we use our own identity provider?
SAML 2.0 single sign-on through yours, set up by an owner and enforceable for every member. A second factor can be required for password sign-ins or for all of them, and both rules are enforced in the database rather than the interface.
How authentication works
How are tenants kept apart?
Row-level security on every table, enforced by Postgres rather than by application code, and asserted with pgTAP against a live database on every push.
Isolation, and how it is tested
Can we see the data processing agreement?
It is published in full, for every customer on every plan. No signature, no sales call, no request to make. Read it before you sign up if you want to.
The Article 28 agreement
What happens if we leave?
One-click export in open formats at any time, including for 90 days after cancellation. It carries the hashes, so a copy taken on the way out is still verifiable afterwards.
Export, retention and deletion
Can our auditor get in?
Yes, as a read-only role with a start and end date. They can read every record, change none, and run the export and the chain check themselves.
What an auditor sees

And the part most vendor pages leave out: of the ISO 9001 clauses, 21 are covered in full, 11 in part, and 4 not at all. We publish the register clause by clause, including the gaps, because a coverage claim you cannot check is not worth making.

The register, clause by clause

One price. No sales call.

€249/mo · excl. VAT

Flat, per organization. Every feature. Unlimited people.

Your certification body's audit fee is separate and paid to them. see what that costs.

  • All 93 ISO 27001:2022 controls + Statement of Applicability
  • Policy pack, risk register, compliance calendar
  • Tamper-evident records & one-click export
  • Unlimited people, no per-seat charge
  • Month-to-month · cancel in-app anytime
Start 14-day free trial

No card required to start · reminder email before any charge · cancellation policy

Sold to businesses and organizations only.

What's included, what isn't, and the total cost

Questions a careful buyer asks

While you are deciding

Do I need a card to start?

No. The 14-day trial starts without payment details, and there is no auto-charge when it ends. A subscription begins only when you go through checkout yourself. We email you three days before the trial ends so the date is never a surprise. If you do nothing, the workspace becomes read-only when the trial ends: nothing is deleted, and you can still sign in, read everything and export it all.

Is this consulting? Will someone call me?

It is software rather than consulting: the management system itself, with drafts generated for you to confirm. That does not mean you are on your own with it. Every screen explains what the clause behind it actually asks for, in plain language, and support is email, answered within one business day by the people who build the product. There is no sales team, and nobody will call you.

Should we do ISO 27001 or SOC 2?

It depends where your customers are, and it is worth checking rather than assuming. In EU public procurement it is not close: over the last 365 days ISO 27001 appears in 3,405 tender notices on TED, the EU's own procurement portal, against 104 for SOC 2, about 32.7 times more often. Counting every spelling of both, on 12 September 2026, and TED's search API is public so you can run it yourself. Those are mentions rather than requirements, and the ratio compares like with like. If you sell mainly to US companies the argument runs the other way: SOC 2 is the shape their procurement expects, and we do not do SOC 2.

See the TED numbers →
What does certification actually cost, in total?

Our €249/mo, plus an accredited certification body's audit fee, which is a separate company you pay directly. Nobody in this market publishes that fee, but it is auditor days × day rate and the days are fixed by ISO/IEC 27006, so you can work it out in advance. For a 25-person company it is roughly €8,000–€13,000 for initial certification and about a third of that annually after.

Work out your number →

While you are doing the work

What if we get stuck?

Email us, and a person who built the product answers within one business day. That is included in the price, not an add-on. Every screen also explains what the clause behind it actually asks for, in plain language, so most questions answer themselves before they reach us.

How long does it take?

Four to seven months is realistic for a small software company. About three months is the floor no tool can beat: your internal audit and management review have to have actually happened before Stage 2, because the auditor samples those records. What software removes is the two-to-six months of building the system beforehand.

See the full timeline →
Does StandardOS cover the whole standard?

No, and the reason is not a missing feature. All 93 Annex A controls get a Statement of Applicability entry with a justification, and every one of the 26 management-system clauses in 4 to 10 has a place in the product. What no software can do is be the evidence: clause 5.1 is leadership demonstrating commitment, and every record still has to be something you actually wrote and meant. We print the clause-by-clause list before you pay, which most tools in this market do not.

See it clause by clause →
Which standards are supported?

ISO/IEC 27001:2022 and ISO/IEC 42001:2023, the AI management system standard, with all 38 of its Annex A controls. Clauses 4 to 10 are the identical harmonised structure in every modern ISO standard: the same documents, risks, audits, reviews and corrective actions. So the machinery that runs one runs the other, and a record you keep for one counts towards both. We publish the clause-by-clause coverage for both before you pay.

See ISO 42001 →
What happens if something goes wrong before an audit?

You write to us and we look at it with you, within one business day. The product shows you what an auditor will sample before they arrive: overdue reviews, expired evidence, controls with nothing behind them. If the record is wrong, you fix the record; if the product is wrong, we fix the product. What we cannot do is sit in the audit for you or promise its outcome: certification is the auditor's judgment of how you actually operate.

Your data, and leaving

Where is our data stored?

In the European Union (Ireland), whichever country you are in. StandardOS is operated by a Danish company under the GDPR, so EU privacy law protects your records by default rather than by contract, wherever you are. Our Article 28 data processing agreement is published in full at /legal/dpa for every customer, with no signature and no sales call, and the Trust page lists every subprocessor and where each one processes data.

We are not in the EU. Is StandardOS for us?

Yes. ISO/IEC 27001 and ISO/IEC 42001 are international standards, audited to the same requirements by accredited bodies in every country, and the management system StandardOS builds is the standard's own, not a regional interpretation of it. The EU material you will see around this site is included on top: GDPR Article 30 processing records, Cyber Resilience Act Article 14 incident reporting, NIS2, and the EU AI Act position in the ISO 42001 templates. If those reach you, they are already there; if they do not, you can ignore them and nothing about the certification changes. Your certification body is local to you, and subscriptions are billed in euros.

What if we want to leave?

Export everything, in open formats, with one click, during the trial, while subscribed, and for 90 days after cancelling. Cancellation itself is one click in Billing, effective end of the period.

Does StandardOS guarantee certification?

No tool can. Certification is an accredited auditor's judgment of how your organization actually operates. What StandardOS does is make the system you'll be audited on: complete, consistent, and backed by records your auditor can verify.

Your auditor will ask for twelve months of records.

The time to start collecting them is not the month before the audit.

This page in:DeutschFrançaisNederlandsEspañolDansk