Assessment and gap analysis
Evaluation of the management requirements and the 93 Annex A controls, with plain-language criteria and examples of the evidence that tends to be accepted and the kind that is not.
CertiaSuite turns ISMS preparation into a list of concrete things: which controls are missing, which evidence has expired and what to do this week. It does not replace an auditor — it gets you ready for one.
No card. Summary report when you finish.
Overall readiness
Oldest evidence: 3 months ago
A few of the 93 controls being assessed
93
Annex A controls, one by one
4–10
management clauses assessed
2
languages, from day one
11
modules across the ISMS cycle
The information lives in shared folders, spreadsheets and two people’s heads. Asking «how far are we?» starts a three-day investigation.
A policy that is approved and never applied counts for nothing in a stage 2 audit. What gets checked is whether the control works, not whether the file exists.
A screenshot from fourteen months ago does not prove something is still running. It is one of the most common findings, and one of the easiest to avoid.
Four moments of the cycle, each with the screen that belongs to it. The data is made up; the structure is the product’s.
You answer a guided assessment in plain language, no jargon. You come out with a readiness percentage per clause and per theme, and a gap list prioritised by effort.
Risks, Statement of Applicability, versioned documents and evidence with expiry dates. All linked: from a control you can reach its risks, its documents and its proof.
Internal audit, nonconformities, management review and a calendar of what is due each month. This is the part that keeps the system alive between audits.
The full ISMS cycle, with the standard references that correspond to each part.
Evaluation of the management requirements and the 93 Annex A controls, with plain-language criteria and examples of the evidence that tends to be accepted and the kind that is not.
Assets, configurable methodology, treatment and residual risk with owner approval. Every risk links to the controls that mitigate it.
Status and justification control by control, with traceability to risks, documents and evidence. Exportable in a format a certification body can read.
Versioning, approval flow, controlled distribution with acknowledgement and overdue-review alerts. The module meets the documentation requirement on its own.
Every piece of proof carries a capture date, an owner and an expiry, with a freshness indicator per control and scheduled recurring collection.
Annual programme, typed findings with objective evidence, guided root cause analysis and review minutes pre-filled from the system’s own data.
A compliance product that does not practise what it preaches is unsellable. These three are not configuration options: they are in the engine.
It does not depend on the code remembering to filter. Every table carries its isolation policy in PostgreSQL, and a three-layer suite tries to cross the boundary on every change and has to fail every time.
Each organization is created in a single region — Europe or the United States — and is not replicated outside it. Only encrypted backups cross.
Until final deletion you can view and take everything with you, and you are emailed at every step before it. A design decision, not a courtesy.
No card to get started. The annual plan is around 20% cheaper.
$0/mo
Quick assessment and summary report.
$99/mo
Full self-assessment, Statement of Applicability and reports.
$299/mo
The full cycle: documents, evidence, risk, internal audit and review.
$699/mo
Corporate sign-in, API, invited external auditor and multi-company.
Prices in US dollars, per organization and month. Consultancies have their own plan per managed client.
No. CertiaSuite is a preparation, management and self-assessment tool: no software can issue an ISO/IEC 27001 certificate. Only accredited certification bodies issue them, after auditing your organization.
What the platform does is get you to that audit knowing exactly where you stand, with evidence in order and gaps identified.
The cost splits into three independent parts: the certification body’s audit, your team’s internal time, and any supporting tools or consultancy. The first is set by the certification body based on size and scope, and is the only one you cannot reduce on your own.
The part that usually gets out of hand is the second: time lost gathering scattered evidence and redoing documentation. That is precisely what a management platform cuts.
It depends mostly on how much already exists and how much real attention the project gets, not on company size. An organization with written processes that only needs to order and evidence them moves far faster than one starting from scratch, even with ten times fewer people.
Anyone giving you a fixed timeline without looking at your situation is guessing. The first thing the platform gives you is exactly that picture.
Stage 1 mainly reviews that the system is designed and documented: that the scope, risk methodology, Statement of Applicability and policies exist. Stage 2 checks that it also works, looking for evidence that controls actually operate day to day.
That is why CertiaSuite scores the two readiness levels separately: being fine for the first and not for the second is common, and knowing it early saves an expensive visit.
Clause 6.1.2 requires the organization to define and apply an information security risk assessment process: its own criteria for accepting risk, a repeatable way to identify and analyse risks, and assigned owners. The key word is repeatable: two people applying the method should reach comparable results.
In practice, what gets audited is that a written method exists, that it was actually used, and that the results connect to the treatment decisions.
The Statement of Applicability is the document that walks through the 93 Annex A controls of ISO/IEC 27001:2022 and states, for each one, whether it applies to your organization, why, and what its implementation status is. It is one of the first documents a certification body asks for.
Its real value is not the list: it is traceability. A control should link to the risks it mitigates, the documents describing it and the evidence proving it operates.
Yes. One person can have access to several organizations with different roles, and consultancies get a plan per managed client with grouped billing and their own brand: portal, emails and reports go out under their name and domain.
Each organization keeps its data completely separate from the rest.
Each organization lives in a single region — Europe or the United States — chosen when the account is created, and its data is not replicated outside it. Only encrypted backups cross between regions.
Separation between customers does not depend on the code remembering to filter: the database enforces it.
Yes, always. Even if the account is suspended for non-payment, you can keep viewing and exporting everything — documents, evidence, Statement of Applicability and reports — until final deletion, and you are emailed at every step before it.
That is a design decision, not a courtesy: your data is not a hostage to make you pay.
The quick assessment asks for no card and returns a summary of your main gaps.
Takes 30–45 minutes · Available in English and Spanish