[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:best-iso-27001-compliance-software":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","best-iso-27001-compliance-software","Best ISO 27001 compliance software: what to ask before you compare features","Integration counts are easy to compare and rarely decide an audit. Here are the questions that do, including the one most vendors will not answer in writing.","2026-08-20",{"who":10,"when":11,"do":12},"A company choosing ISO 27001 software: the audit is decided by whether the tool can show, clause by clause, which records it holds and which it does not, keeps them dated through the three-year cycle, and lets the company leave with everything in open formats; feature counts and integration counts decide nothing at the audit.","Before a subscription is signed and before the records start living in a tool, since moving records mid-cycle is the cost that makes a bad choice expensive; and again at month fourteen, when the surveillance audit asks what was kept.","Ask each vendor four questions in writing: the clause coverage including the gaps, what happens in month fourteen, whether you can leave with your records, and what each integration actually produces; check every answer before you pay.","\nThe best ISO 27001 compliance software is the one that can show you, clause by clause, which records it holds and which it does not, keeps those records dated through the whole three-year certification cycle, and lets you leave with everything in open formats. Feature counts do not decide an audit. Four questions do, and every answer can be checked before you pay.\n\n## 1. Ask for clause coverage, including the gaps\n\nISO 27001 is clauses 4 to 10 plus 93 Annex A controls. An auditor works through the clauses. Ask any vendor for a clause-by-clause statement of what their product holds records for, **and what it does not**.\n\nThe gaps are the informative half. A vendor who cannot produce that list has not mapped their product to the standard, and a vendor whose list has no gaps has not read it honestly. [Ours is published](\u002Fiso-27001\u002Fcoverage) with the gaps in it, and it is generated from the same register the product runs on.\n\n## 2. Ask what happens in month fourteen\n\nCertification is three years with surveillance audits each year. Most tools are built for the first month: draft the Statement of Applicability, generate policies, look organised. The work that recurs is evidence going stale and needing to be collected again.\n\nAsk what the product does when evidence expires. If the answer is a reminder email, that is a to-do list. If evidence carries an expiry date and connected systems refresh it, that is a system.\n\n## 3. Ask whether you can leave\n\nAsk for an export containing every record an auditor would ask for, in a format you can read without the vendor. Ask whether you can use any accredited certification body, or only theirs. A tool bundled with an audit can be convenient, and it also removes your ability to compare quotes.\n\n## 4. Weigh integrations for what they actually do\n\nIntegration counts are the headline number in this category. They matter when they keep evidence current without anyone remembering to do it, which is real value. They matter much less as a total. Thirty integrations you do not use are not better than five you do, and each one that produces findings nobody triages becomes noise the team learns to ignore.\n\n## What none of this is about\n\nPrice. Categories in this market span roughly an order of magnitude, and the difference between tools is rarely worth optimising against the audit fee, which is set by [auditor days](\u002Fiso-27001\u002Fcost) rather than by software. Pick the one that will still have your records in month fourteen.\n",1789383986344]