ISO 27001 software: what to look for (UK buyer's checklist)

6 min read · Updated

Good ISO 27001 software should cut the work of building your information security management system and the work of keeping it running, without pretending to do the parts only your people and your certification body can do. Use this checklist when you compare tools, including ours.

1. Does it start you from a draft, or a blank page?

Templates still leave you writing everything. Look for a tool that drafts your scope, risk register, Statement of Applicability and policies from a description of your business, so you're editing rather than writing.

Ask: "Show me what it produces for a business like mine."

2. Who approves the documents?

Your auditor will want to see that people in your organisation decided and approved your ISMS. The software should record who approved which version and when, and top management should approve the things the standard expects them to (the information security policy, management review).

Red flag: anything that "auto-approves" or implies the tool signs things off for you.

3. Does it help you run the system, not just build it?

Most of the effort is after certification: access reviews, supplier reviews, restore tests, training, internal audits, management reviews, nonconformities. Look for:

  • tasks with owners and due dates, and reminders when they're due or overdue;
  • recurring work that sets itself up again once it's done;
  • evidence attached to the control it proves.

Ask: "What happens in month seven, when nobody's thinking about ISO 27001?"

4. Can people use it without logging in all the time?

The people who own actions (IT, HR, operations) are busy. Tools that work through email, with reminders people can reply to and inboxes that file correspondence against an incident or risk, get used. Tools that need a weekly login often don't.

5. How does your auditor see it?

Look for read-only, scoped auditor access to your approved records, so you're not exporting folders of PDFs before every audit.

6. Pricing traps

  • Per-user pricing: ISO 27001 involves everyone; per-seat pricing punishes that.
  • Per-framework add-ons: check what Cyber Essentials or continuity costs on top.
  • Annual lock-in only: fine if you're sure, risky if you're not.
  • The audit isn't included: your certification body's fees are separate in almost every case. Budget for them. See what ISO 27001 costs.

7. Honesty about certification

No software can certify you or guarantee you'll pass. Certification is awarded by an accredited certification body (UKAS-accredited in the UK). Be wary of any vendor that says otherwise.

How ClearIMS measures up

ClearIMS is for businesses that need ISO 27001 but don't want to build a compliance team to get there:

  • It drafts your scope, risk register, risk treatments, Statement of Applicability, policies and tasks from a plain-English description of your business.
  • A named person approves every record, with who, which version and when recorded. The AI never approves anything.
  • It works like a virtual ISMS manager: it emails people about outstanding actions, they can reply in plain text to update them, and incidents, risks and questionnaires can each have their own email address so correspondence is filed and summarised.
  • Your external auditor gets scoped, read-only access to approved records.
  • One monthly price with unlimited users; Cyber Essentials and business continuity included.

We make the software. Your certificate is awarded by your certification body, and nobody can guarantee it.

Take the 2-minute readiness check, or book a 20-minute call.

SOURCES

  1. ISO/IEC 27001:2022 (ISO)
  2. Find a UKAS-accredited certification body (UKAS)
FOUNDING CUSTOMER PROGRAMME · 10 PLACES

Ten organisations get the software at half price. We get to learn from them.

Start with the 30-day free trial. If ClearIMS earns its place, a founding seat locks £150 a month for 24 months, or £1,500 a year upfront. No VAT charged.

Apply for a founding placeBook a 20-minute callWe make the software. Your certification is yours, awarded by your certification body.