New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

Other frameworks

ISO 27001: information security management

ISO/IEC 27001 is the standard organisations reach for when they need to prove, to a customer or a regulator, that information security is managed systematically rather than ad hoc. This is the best-supported of the platform's non-AI-Act frameworks: enabling it gives you a real, itemised obligation list mapped to the standard's own clause and Annex A structure.

Transcript

This is the Compliance Frameworks page, where you turn on the regimes your organisation is tracking.

ISO 27001 certifies an information security management system. Clause six point one requires a documented risk assessment, and a risk treatment plan with a Statement of Applicability, listing which Annex A controls apply to you and why.

Enabling it is one toggle. That immediately adds ninety-nine real, itemised obligations to your Obligations page, matched to the standard's own clause and Annex A structure.

Here is the Obligations page. Ten items are platform managed, evidenced automatically from things like access reviews, vendor risk assessments, and policy acknowledgements. The rest are yours to complete.

Annex A groups controls into four themes: organisational, people, physical and technological. Your obligation list tells you which theme each item belongs to, so you can work through them systematically rather than guessing.

Why this is required

ISO 27001 certifies an Information Security Management System, or ISMS, not a fixed checklist of technical controls. Clause 6.1.2 requires a documented risk assessment process; Clause 6.1.3 requires a risk treatment plan and a Statement of Applicability, the single document that says which of Annex A's controls apply to you and why.

Annex A groups controls into four themes. A.5 Organisational controls (37 controls) covers policy, roles, supplier and cloud security, and incident management. A.6 People controls (8) covers screening, training, and what happens when someone leaves. A.7 Physical controls (14) covers secure areas and equipment. A.8 Technological controls (34) covers access control, cryptography, logging, and secure development.

None of this is optional if you want the certificate: an external auditor checks your ISMS against Clauses 4 to 10 and your Statement of Applicability against Annex A. But the standard itself deliberately doesn't tell you which controls to pick, only that you must justify your choices, which is why most organisations find the paperwork harder than the controls.

What EuroCompliant does

Enabling ISO 27001 under Settings → Frameworks adds it to your Obligations page with real, itemised guidance, not a generic placeholder: the platform's obligation engine has a working mapping for all ten of the standard's tracked clauses, more complete than several of the other frameworks below.

Two obligations are platform-managed and evidence themselves automatically: your risk assessment (once a system's risk assessment is complete) and your risk treatment plan and Statement of Applicability (once related documentation exists). The rest, including implementing your Annex A.5 through A.8 controls, are yours to complete and evidence.

A Statement of Applicability document type exists in the platform's document engine, built from your Annex A theme coverage. In-app one-click generation for it is being extended from the EU AI Act and GDPR document set it currently covers; if you need one issued now, your account team can generate it directly.

Walking through it

1

Enable ISO 27001

Turn the framework on. This adds its ten Clause and Annex A obligations to your Obligations page immediately.

Open /settings/profile?tab=frameworks →
2

Review your obligations

Platform-managed items are collapsed by default; expand them to see what's already been evidenced from your risk assessments. Everything else needs your action.

Open /obligations →
3

Work through the Annex A themes

Each Annex A obligation covers one theme (Organisational, People, Physical, Technological). Implement the controls that apply to you, and record why any others don't.

4

Attach evidence as you go

A policy document, a training record, an access review, whatever demonstrates the control is real. This is what an external auditor will actually ask to see.

Open /evidence →

The law

Frequently asked

Do we need to implement every Annex A control?

No. The Statement of Applicability is precisely the mechanism for excluding controls that genuinely don't apply to you, with a documented reason. What an auditor won't accept is excluding a control because it's inconvenient.

Does enabling this framework mean we're certified?

No. Certification requires an accredited external auditor to assess your ISMS and issue the certificate. The platform helps you build and evidence the ISMS; it doesn't replace the audit.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial