Other frameworks
ISO 27001: information security management
ISO/IEC 27001 is the standard organisations reach for when they need to prove, to a customer or a regulator, that information security is managed systematically rather than ad hoc. This is the best-supported of the platform's non-AI-Act frameworks: enabling it gives you a real, itemised obligation list mapped to the standard's own clause and Annex A structure.
Transcript
This is the Compliance Frameworks page, where you turn on the regimes your organisation is tracking.
ISO 27001 certifies an information security management system. Clause six point one requires a documented risk assessment, and a risk treatment plan with a Statement of Applicability, listing which Annex A controls apply to you and why.
Enabling it is one toggle. That immediately adds ninety-nine real, itemised obligations to your Obligations page, matched to the standard's own clause and Annex A structure.
Here is the Obligations page. Ten items are platform managed, evidenced automatically from things like access reviews, vendor risk assessments, and policy acknowledgements. The rest are yours to complete.
Annex A groups controls into four themes: organisational, people, physical and technological. Your obligation list tells you which theme each item belongs to, so you can work through them systematically rather than guessing.
Why this is required
ISO 27001 certifies an Information Security Management System, or ISMS, not a fixed checklist of technical controls. Clause 6.1.2 requires a documented risk assessment process; Clause 6.1.3 requires a risk treatment plan and a Statement of Applicability, the single document that says which of Annex A's controls apply to you and why.
Annex A groups controls into four themes. A.5 Organisational controls (37 controls) covers policy, roles, supplier and cloud security, and incident management. A.6 People controls (8) covers screening, training, and what happens when someone leaves. A.7 Physical controls (14) covers secure areas and equipment. A.8 Technological controls (34) covers access control, cryptography, logging, and secure development.
None of this is optional if you want the certificate: an external auditor checks your ISMS against Clauses 4 to 10 and your Statement of Applicability against Annex A. But the standard itself deliberately doesn't tell you which controls to pick, only that you must justify your choices, which is why most organisations find the paperwork harder than the controls.
What EuroCompliant does
Enabling ISO 27001 under Settings → Frameworks adds it to your Obligations page with real, itemised guidance, not a generic placeholder: the platform's obligation engine has a working mapping for all ten of the standard's tracked clauses, more complete than several of the other frameworks below.
Two obligations are platform-managed and evidence themselves automatically: your risk assessment (once a system's risk assessment is complete) and your risk treatment plan and Statement of Applicability (once related documentation exists). The rest, including implementing your Annex A.5 through A.8 controls, are yours to complete and evidence.
A Statement of Applicability document type exists in the platform's document engine, built from your Annex A theme coverage. In-app one-click generation for it is being extended from the EU AI Act and GDPR document set it currently covers; if you need one issued now, your account team can generate it directly.
Walking through it
Enable ISO 27001
Turn the framework on. This adds its ten Clause and Annex A obligations to your Obligations page immediately.
Open /settings/profile?tab=frameworks →Review your obligations
Platform-managed items are collapsed by default; expand them to see what's already been evidenced from your risk assessments. Everything else needs your action.
Open /obligations →Work through the Annex A themes
Each Annex A obligation covers one theme (Organisational, People, Physical, Technological). Implement the controls that apply to you, and record why any others don't.
Attach evidence as you go
A policy document, a training record, an access review, whatever demonstrates the control is real. This is what an external auditor will actually ask to see.
Open /evidence →The law
Information security risk assessment
A documented process for identifying, analysing and evaluating information security risks.
Risk treatment
A risk treatment plan and a Statement of Applicability stating which Annex A controls apply and why.
Organisational controls
37 controls covering policy, roles, supplier and cloud security, and incident management.
Technological controls
34 controls covering access control, cryptography, logging, malware defence and secure development.
Frequently asked
Do we need to implement every Annex A control?
No. The Statement of Applicability is precisely the mechanism for excluding controls that genuinely don't apply to you, with a documented reason. What an auditor won't accept is excluding a control because it's inconvenient.
Does enabling this framework mean we're certified?
No. Certification requires an accredited external auditor to assess your ISMS and issue the certificate. The platform helps you build and evidence the ISMS; it doesn't replace the audit.
Related guides
Compliance checklists
How Articles 9 to 15 become tracked, owned, evidenced work rather than a document nobody reads.
Evidence vault & audit trail
Turning completed checklist items into artefacts a regulator can inspect, and the logging duties behind Articles 12 and 26.
Automated Scanning: Continuous Telemetry and Scan Pipelines
How scheduled scan jobs, 12 scan engines and local PII scrubbing produce dated Article 10/15 evidence without moving data outside the EEA.
SOC 2: AICPA Trust Services Criteria
The AICPA's Trust Services Criteria used in SOC 2 audits: the Common Criteria (security) plus, where in scope, Availability, Confidentiality and Processing Integrity. 43 tracked obligations, 12 platform-managed today, backed by real scan, audit-trail and policy-acknowledgment evidence.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial