Skip to content

Automate ISO 27001 readiness with adaptive compliance

For companies selling outside the United States, ISO 27001 has become the price of entry. See how growing teams close the gap between running a security program and proving it.

ISO 27001 controls

ISO 27001: Prove you run security as a managed system

Unified by design. Built for the AI era.

Iru AI is designed from the ground up to connect a grid of agents behind the scenes—across identity, endpoint, and compliance. Powered by the Iru Context Model, it understands your users, apps, and devices to act safely, intelligently, and in context across your organization.

Iru combines native endpoint and identity telemetry with supported integrations, making it easier to prepare for ISO 27001 compliance and stay audit-ready all year.

Implement ISO 27001 controls, don't just document them

Full Iru platform vs standalone compliance tools
Iru
Standalone compliance tools

Automate evidence collection

Automatically pull evidence from collected sources via Iru Compliance Automation.

Maintain your Statement of Applicability

Keep your SoA and risk treatment plan current as controls change, via Iru Compliance Automation (support clause 6.1.3 d).

Share compliance posture externally

Leverage a public-facing portal to share compliance posture via Iru Trust Center.

Harden device configuration

Enforce secure baselines and configuration management across your fleet via Iru Endpoint Management (supports A.8.1, A.8.9).

Encrypt data at rest

Apply full-disk encryption and manage recovery keys via Iru Endpoint Management (A.8.24).

Control user access

Enforce phishing-resistant authentication and separated admin accounts via Iru Workforce Identity (A.5.1.5, A.5.1.6, A.8.5).

Keep software up to date

Continuously detect and remediate OS and third-party software risk via Iru Vulnerability Management (A.8.8).

Protect against malware

Detect and contain malicious code on managed devices via Iru Endpoint Detection & Response (A.8.7).

Customize ISO 27001 controls for your unique business

Most compliance tools turn frameworks into generic checklists. Iru generates controls that are specific to your organization, in plain language, broken down into sub-tasks.

  • Iru AI generates tailored controls, based on your company context and audit details
  • You can migrate existing controls over from other products, or upload your own custom control set
  • Controls become actions the moment they are created, with suggested owners and due dates
ISO 27001 actions

Automate your ISO 27001 evidence collection

For connected and activated sources, Iru can discover and attach relevant artifacts to the supported control actions, reducing manual uploads. And because you can manage your devices and identity within Iru, that data is pulled natively.

  • Evidence flows in continuously from supported devices, integrations and systems
  • Iru AI helps to identify stale, missing or potentially irrelevant evidence for you to review
  • You stay better prepared before fieldwork begins, with fewer fire drills before your SOC 2 engagement
IS) 27001 evidence

Ensure continuous ISO 27001 audit readiness

Iru's Adaptive Compliance capabilities watch for changes in your organization, and automatically suggest updates to your controls and actions.

  • Iru AI regularly checks for changes to your sources, artifacts or company profile
  • If a change is detected, a control update recommendation is surfaced for you to review, often within 24 hours
  • No changes are made without your approval, and every change is logged for your auditors to review
ISO 27001 adaptive

Turn ISO 27001 preparation into an always-on workflow

Iru's AI-powered compliance solution helps IT, security and GRC teams spend less time on manual compliance work and stay audit-ready all year.

Let your team focus 
on what matters

Iru replaces fragmented tools with one AI-powered platform, so IT & security spend less time chasing tickets and more time improving the business.

Frequently asked
questions

Get answers to commonly asked questions

Who publishes and maintains ISO 27001 reporting requirements?

ISO/IEC 27001 is published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC)

ISO writes the standard but does not certify anyone against it. Certification is issued by independent certification bodies, which are in turn accredited by national accreditation bodies such as ANAB in the United States and UKAS in the United Kingdom.

What does ISO 27001 evaluate?

ISO 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).

Differing from other standards such as SOC 2, ISO 27001 evaluates whether you are actually running a management system — leadership involvement, risk assessment, defined objectives, internal audit, management review, and corrective action.  The standard is built from two parts: management system requirements in Clauses 4 through 10, and a normative reference set of information security controls in Annex A.

 

Do we have to implement all 93 Annex A controls?

No — and this is the single most common misconception about ISO 27001.

Annex A is a reference set, not a mandatory checklist. The standard asks you to determine the controls you need from your own risk assessment, then compare that set against Annex A to confirm you have not inadvertently left out something necessary. If the comparison surfaces a gap, you update your risk treatment plan and implement it. If it does not, you have satisfied the requirement.

You then document the results in a Statement of Applicability — which controls apply, why they apply, whether they are implemented, and your justification for excluding any that do not.

What is the difference between ISO 27001 and ISO 27002?

ISO 27001 is the requirements standard, and what you actually certify against. ISO 27002 is the companion guidance document: it describes each control in depth, with purpose, attributes, and implementation advice.

You cannot be certified to ISO 27002. Teams still buy it, because Annex A of 27001 gives you control titles while 27002 tells you what implementing each one actually involves.

What does an ISO 27001 engagement look like?

Initial certification runs in two stages, both performed by an accredited certification body.

  • Stage 1 is a readiness and design review. The auditor examines your ISMS documentation, your defined scope, your Statement of Applicability, and your risk assessment — and confirms you are ready to be audited properly.
  • Stage 2 tests whether the ISMS is actually implemented and operating effectively across your scope, through evidence sampling and interviews.

Gaps found at Stage 1 are your chance to fix things before they count against you.

 

What does an ISO 27001 engagement produce?

A certificate issued by the certification body, plus an audit report.

The certificate names your scope statement, which matters more than most buyers realize: a certificate covering one product line is not a certificate covering your whole company.

What are the potential outcomes of an ISO 27001 engagement?

Audit findings are recorded as nonconformities, and the distinction between the two types is critical:

  • Major nonconformity — a systemic failure, or an absent required element. Certification cannot be granted or maintained until you correct it and the certification body verifies the correction.
  • Minor nonconformity — an isolated lapse. Typically resolved through a corrective action plan without blocking certification.

Auditors may also raise observations or opportunities for improvement, which carry no obligation.

So unlike examinations for other frameworks, like SOC 2, you can straightforwardly fail to achieve certification — and an existing certificate can be suspended or withdrawn if major nonconformities go unresolved.

 

How long is an ISO 27001 report valid for?

Three years, on a defined cycle.

  • The certificate is issued for a three-year term.
  • Surveillance audits happen at least annually during that term. The first one must take place within 12 months of the certification decision.
  • A full recertification audit happens before the three years expire, restarting the cycle.

Certification is a continuous obligation, not a one-time event. Skipping a surveillance audit can cause the certificate to be suspended.

Is ISO 27001 certification legally mandatory?

No. ISO 27001 is a voluntary international standard, and no general law requires it.

In practice it functions as a commercial requirement rather than a legal one — particularly for selling into Europe, the UK, Japan, and enterprise procurement generally, where it is often the default expectation the way SOC 2 is in the US market.

 

Our certificate says ISO 27001:2013. Is that still valid?

No. Those certificates are no longer valid.

ISO/IEC 27001:2022 was published on 25 October 2022, and the transition period ran three years. All certifications issued against the 2013 edition expired or were withdrawn on 31 October 2025. If your certificate still references 2013, you are not currently certified and will need to complete a transition audit with your certification body.

What changed in the 2022 version of ISO 27001?

The most visible change is Annex A. The control set was restructured from 114 controls across 14 clauses into 93 controls across 4 themes — Organizational, People, Physical, and Technological.

Of those 93: 11 are new, 24 are merged from existing controls, and 58 were updated. Each control now carries a stated purpose and a set of attributes, replacing the old grouped control objectives.

The management system clauses changed less. The notable addition is Clause 6.3, Planning for changes, which requires changes to the ISMS to be made in a planned way. Clause 4.2 also gained a requirement to determine which interested-party requirements will be addressed through the ISMS.

Does the climate change amendment affect us?

Only marginally.

ISO published a 2024 amendment adding climate change consideration to the context-of-the-organization clauses across its management system standards, ISO 27001 included.

It adds no new controls and no new documentation requirement — your context analysis simply needs to consider whether climate change is a relevant issue.

Can Iru certify us, or issue an ISO 27001 certificate?

No compliance software can issue an ISO 27001 certificate. Certification must come from an independent certification body, accredited by a recognized accreditation body — that independence is the entire basis of the certificate's value.

 

Our platform acts as the engine room. It connects to your systems, gathers evidence continuously, manages your policies and Statement of Applicability, and hands your auditor an organized package instead of a scramble. If you would like to work with one of the certification bodies we partner with, please reach out to your rep.

 

Stay up to date

Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.