ISO 27001 templates vs software: which is right for you?
ISO 27001 template packs (Word documents and spreadsheets) cost a few hundred pounds and give you a structure to fill in. Software costs more each month but can draft the content for you and keep the system running afterwards. For a business that will do the work itself, the real question isn't the price of the pack; it's how many hours you'll spend writing and then maintaining the system.
What templates are good at
- Cheap and familiar: Word and Excel, nothing new to learn.
- A checklist of what's needed: the right policy titles and register columns.
- Fine for a very simple scope with someone who already knows ISO 27001 well.
Where templates break down
- Generic content: a template policy describes a generic company. Auditors look for a system that fits your organisation, so you end up rewriting most of it.
- Approvals live in email: proving who approved which version, and when, means digging through inboxes.
- Nothing reminds you: access reviews, supplier reviews and restore tests depend on someone remembering. That's where most small ISMSs drift between audits.
- Version sprawl: "Risk register FINAL v3 (2).xlsx" on a shared drive.
- Evidence is scattered: screenshots and reports in folders, gathered in a rush before each audit.
What software should add
- A draft about your business, not a generic one.
- Recorded approvals with who, which version and when.
- Tasks, owners, due dates and reminders, so the running work happens.
- Evidence linked to the control it proves.
- Auditor access to approved records, instead of exporting folders.
A quick way to choose
| If... | Consider |
|---|---|
| You know ISO 27001 well, your scope is small and you're happy maintaining spreadsheets | Templates |
| ISO 27001 is landing on someone with a day job, or you want it to keep running without chasing | Software |
| You want someone to do it for you | A consultant (and software to keep it running afterwards) |
How ClearIMS helps
ClearIMS is for businesses that need ISO 27001 but don't want to build a compliance team to get there. Describe your business in plain English and it drafts your scope, risk register, Statement of Applicability, policies and tasks. A named person approves every record; the AI never approves anything. Then it works like a virtual ISMS manager: it emails people about outstanding actions, and they can reply in plain text to update them.
We make the software. Your certificate is awarded by your certification body, and nobody can guarantee it.
Take the 2-minute readiness check, or book a 20-minute call.