ISO 27001:2022

ISO 27001 readiness — without the consultant

ISO 27001 is the global standard for information security management. Fortify gives you a free gap assessment against the standard, a structured audit programme covering all 93 Annex A controls, and an evidence vault — so you arrive at certification ready, not scrambling.

Free gap assessment · ISO 27001 audit included from Essential bundle · £149/mo annual

Who pursues ISO 27001

The standard enterprise buyers and regulators expect

ISO 27001 certification signals to customers, partners, and regulators that your information security management system meets an independently verified international standard.

Enterprise sales and procurement

Enterprise buyers increasingly require ISO 27001 certification or evidence of ISO 27001-aligned controls before awarding contracts or granting system access.

Financial services and fintech

Banks, payment processors, and financial platforms often mandate ISO 27001 for technology suppliers. It is also referenced in FCA and PRA operational resilience guidance.

Healthcare and MedTech suppliers

NHS and private healthcare organisations require ISO 27001 (or alignment with it) from software suppliers and clinical data processors.

SaaS and cloud service providers

Enterprise customers expect their SaaS providers to hold ISO 27001. Without it, you lose deals at the security questionnaire stage.

Legal and professional services

Law firms and professional services practices increasingly pursue ISO 27001 to satisfy client expectations and SRA requirements around client data protection.

Any organisation ready to grow

ISO 27001 is the global gold standard for information security management. It demonstrates to customers, partners, and investors that you take security seriously.

What ISO 27001:2022 covers

10 clauses, 93 Annex A controls

ISO 27001:2022 restructured Annex A from 114 controls to 93, organised into organisational, people, physical, and technological domains. Fortify covers all of them.

Clauses 4–6

Context, leadership & planning

Defining scope, understanding context, leadership commitment, and information security objectives.

Clause 7

Support

Resources, competence, awareness, communication, and documented information.

Clause 8

Operation

Operational planning, risk treatment, and supplier relationships.

Clause 9

Performance evaluation

Monitoring, measurement, internal audit, and management review.

Clause 10

Improvement

Nonconformity, corrective action, and continual improvement.

Annex A

93 controls across 11 domains

Organisational, people, physical, and technological controls — assessed and evidenced control by control.

How Fortify helps

From gap check to certification-ready — in one platform

Fortify handles the preparation work so the certification body audit is a formality, not a fire drill.

01

Free gap assessment

Our Digital Resilience assessment maps your current posture against the ISO 27001 control domains. You get a readiness score and the key gaps identified — in 10 minutes.

02

Portal findings and risk register

Import your results. Findings populate your risk register. Track each gap with status, owner, due date, and evidence — live, not in a spreadsheet.

03

Structured ISO 27001 audit in the portal

Jamie, your AI ISO 27001 advisor, guides you through all clauses and Annex A controls. Attach evidence — policies, configurations, records — directly against each control.

04

Evidence pack and management review

Export your evidence summary, generate a management review report, and arrive at your certification body audit with nothing left to scramble for.

ISO 27001 Audit — Portal add-on

Guided ISO 27001 audit inside your Fortify portal

Jamie, your AI ISO 27001 advisor, takes you through all mandatory clauses and all 93 Annex A controls — with evidence capture, gap tracking, and a management review report generated automatically.

  • ✓All mandatory ISO 27001:2022 clauses covered
  • ✓93 Annex A controls with evidence attached per control
  • ✓Statement of Applicability (SoA) generation
  • ✓Management review report with AI narrative
  • ✓Risk register integrated with audit findings
  • ✓Exportable evidence pack for your certification body
Start in the portal →

Included in portal plans from Essential · View pricing

Find out where you stand — in 10 minutes

The free Digital Resilience assessment maps your current posture against the ISO 27001 control domains. No forms, no account needed.