ACloud.Solutions

ISO 27001 and compliance

ISO 27001 compliance automation platform: what it replaces and what it does not

The demo is good. A dashboard turns from red to green as integrations connect, controls tick themselves off, and a salesperson says the word "audit-ready" in a sentence about weeks rather than months. The annual price is roughly what a contractor would cost for a month.

An iso 27001 compliance automation platform is genuinely useful for one specific thing and oversold for two others, and knowing which is which before you buy determines whether the money was well spent.

What an iso 27001 compliance automation platform actually does well

Evidence collection through integrations. This is the real product. Connect your identity provider, cloud accounts, device management and code repository, and the platform pulls MFA coverage, device compliance, access lists, branch protection and similar on a schedule, timestamps them, and keeps them.

That is the part of the job that is tedious, recurring and easy to skip, and which produces most of the anxiety before an audit. Buying it is a reasonable trade for money, and it is the same argument as scheduled evidence collection with somebody else maintaining the scripts.

Continuous monitoring against control checks. The platform notices when something drifts: a user without MFA, a machine that fell out of compliance, a repository without required reviews. Useful, and closer to operational monitoring than to compliance.

Policy templates and acknowledgement tracking. The templates are a starting point of variable quality. The acknowledgement tracking is genuinely handy, because chasing forty people is a job nobody wants.

Auditor collaboration. Some platforms give the auditor read access to the evidence, which removes a scramble. Worth more than it sounds.

What it does not do

Three things, and each is a substantial part of the project.

Your risk assessment. A platform can hold a risk register and offer a starter set of risks. It cannot assess your risks, because your risks depend on what your business does, which customers you have, what your contracts commit you to and what you have decided to accept. A generic register imported from a template is exactly the 214-row spreadsheet the risk assessment note warns about, with better styling.

An auditor will ask how you arrived at your criteria and who owns a specific risk. "The platform suggested it" is not an answer.

Your internal audit. Clause 9.2 requires impartial auditors. A platform is not an auditor, and the independence problem in the internal audit note is untouched by any amount of tooling.

Your management review. Clause 9.3 requires management to review the ISMS and make decisions. A dashboard is an input to that meeting, not the meeting.

There is a fourth, softer thing. A platform will not give you an understanding of your own ISMS. If it configures your controls and collects your evidence, you may reach certification without being able to explain your own system, and Stage 2 involves being asked to explain your own system.

The scoring trap

Every platform has a readiness percentage, and it is the most persuasive and least meaningful number in the product.

It measures the platform's own checks passing, weighted however the vendor chose. It does not measure whether your ISMS satisfies the standard, because most of the clauses are not automatable. So 98 percent readiness with no internal audit and no management review is a company that will not certify, and the number will not tell you that.

Treat it as a monitoring dashboard rather than as a compliance status. Green means the automated checks pass, which is a real and useful thing, and it is not the same as ready.

Evaluating one, without the demo doing the work

A scorecard that produces a decision rather than an impression. Score each out of five and weight to taste.

Integration coverage for your actual stack. Not the logo wall, your systems. If your identity is Entra, your devices are Intune, your cloud is Azure and your code is in Azure DevOps, check every one specifically. Coverage of the AWS-and-Okta combination is common and irrelevant to you.

Evidence quality. Ask to see a real evidence artefact for a control you care about. Some platforms produce a timestamped export; some produce a green tick whose underlying data you cannot retrieve. The tick is worthless at audit.

Export and exit. Can you take your evidence, policies and register out in a usable form when you leave. A platform holding two years of evidence you cannot export has you.

Framework fit. Many were built for SOC 2 first and added ISO 27001 later. The mapping is usually fine and occasionally loose, particularly around clauses 4 to 10 which have no SOC 2 equivalent. Ask specifically how they handle clause 9.

Auditor familiarity. Ask your certification body which platforms they see regularly. An auditor who knows the interface spends less time being shown around.

Total cost with growth. Pricing is usually per employee with tiers. Model it at your headcount in three years, not today, and check whether the price of a second framework is incremental or another full licence.

What it costs you in learning. Genuine and rarely discussed. If you intend to keep this in-house for years, a platform that does the thinking for you leaves you less able to defend it.

The honest answer

For a company of forty with one person on this, a platform is a reasonable purchase if you are paying for evidence collection and monitoring, and a poor one if you are paying to avoid understanding the standard.

The cheaper path is real: scheduled exports, a spreadsheet register, a document library, and a contractor for internal audit. That is what the book describes, and it costs less and teaches you more. It also takes more of your time, which may be the scarcer resource.

What does not work is buying a platform and treating the dashboard as the project. The clauses it cannot automate are the ones certification turns on.

No vendor is recommended here, and any comparison of specific products would go stale before you read it. Get two trials, run the scorecard above on your own stack, and ask each vendor to show you a real evidence artefact rather than a dashboard. The ISO 27001 standard is the thing you are being certified against, and no tool changes what it requires.