CertiaSuite
ISO/IEC 27001:2022 · ES + EN

Know exactly what you are missing before the audit

CertiaSuite turns ISMS preparation into a list of concrete things: which controls are missing, which evidence has expired and what to do this week. It does not replace an auditor — it gets you ready for one.

No card. Summary report when you finish.

Audit readinessExample

Overall readiness

70%
Stage 1 · 82%Stage 2 · 54%
  • A.5.15Access controlVerified
  • A.8.7Malware protectionPending
  • A.6.3Awareness trainingGap

Oldest evidence: 3 months ago

A few of the 93 controls being assessed

A.5.1Security policiesA.5.15Access controlA.5.19Supplier securityA.5.24Incident managementA.6.3Awareness and trainingA.7.2Physical entryA.8.7Malware protectionA.8.12Data leakage preventionA.8.16Monitoring activitiesA.8.28Secure coding

93

Annex A controls, one by one

4–10

management clauses assessed

2

languages, from day one

11

modules across the ISMS cycle

Why getting certified drags on

01

Nobody knows where things stand

The information lives in shared folders, spreadsheets and two people’s heads. Asking «how far are we?» starts a three-day investigation.

02

Having the document is not having the control

A policy that is approved and never applied counts for nothing in a stage 2 audit. What gets checked is whether the control works, not whether the file exists.

03

Evidence expires quietly

A screenshot from fourteen months ago does not prove something is still running. It is one of the most common findings, and one of the easiest to avoid.

This is what you see when you log in

Four moments of the cycle, each with the screen that belongs to it. The data is made up; the structure is the product’s.

How it works

  1. 01

    Assess

    You answer a guided assessment in plain language, no jargon. You come out with a readiness percentage per clause and per theme, and a gap list prioritised by effort.

  2. 02

    Manage

    Risks, Statement of Applicability, versioned documents and evidence with expiry dates. All linked: from a control you can reach its risks, its documents and its proof.

  3. 03

    Operate

    Internal audit, nonconformities, management review and a calendar of what is due each month. This is the part that keeps the system alive between audits.

What is included

The full ISMS cycle, with the standard references that correspond to each part.

Clauses 4–10

Assessment and gap analysis

Evaluation of the management requirements and the 93 Annex A controls, with plain-language criteria and examples of the evidence that tends to be accepted and the kind that is not.

6.1.2 · 8.2 · 8.3

Risk management

Assets, configurable methodology, treatment and residual risk with owner approval. Every risk links to the controls that mitigate it.

6.1.3

Statement of Applicability

Status and justification control by control, with traceability to risks, documents and evidence. Exportable in a format a certification body can read.

7.5

Documents under change control

Versioning, approval flow, controlled distribution with acknowledgement and overdue-review alerts. The module meets the documentation requirement on its own.

Cross-cutting

Evidence with a shelf life

Every piece of proof carries a capture date, an owner and an expiry, with a freshness indicator per control and scheduled recurring collection.

9.2 · 10 · 9.3

Internal audit, corrective actions and review

Annual programme, typed findings with objective evidence, guided root cause analysis and review minutes pre-filled from the system’s own data.

What holds the platform up

A compliance product that does not practise what it preaches is unsellable. These three are not configuration options: they are in the engine.

Customer separation is enforced by the database

It does not depend on the code remembering to filter. Every table carries its isolation policy in PostgreSQL, and a three-layer suite tries to cross the boundary on every change and has to fail every time.

Your data lives where you chose

Each organization is created in a single region — Europe or the United States — and is not replicated outside it. Only encrypted backups cross.

Export works even if you stop paying

Until final deletion you can view and take everything with you, and you are emailed at every step before it. A design decision, not a courtesy.

Pricing

No card to get started. The annual plan is around 20% cheaper.

Free

$0/mo

Quick assessment and summary report.

  • A 30–45 minute assessment
  • Summary report as PDF
  • No card required

Starter

$99/mo

Full self-assessment, Statement of Applicability and reports.

  • All 93 controls and clauses 4–10
  • Exportable Statement of Applicability
  • Prioritised gap analysis
Most complete

Professional

$299/mo

The full cycle: documents, evidence, risk, internal audit and review.

  • Everything in Starter
  • Risk, documents and evidence
  • Internal audit, corrective actions and review

Enterprise

$699/mo

Corporate sign-in, API, invited external auditor and multi-company.

  • Everything in Professional
  • Corporate sign-in and API
  • Invited external auditor and multi-company

Prices in US dollars, per organization and month. Consultancies have their own plan per managed client.

Frequently asked questions

Does CertiaSuite certify me against ISO 27001?

No. CertiaSuite is a preparation, management and self-assessment tool: no software can issue an ISO/IEC 27001 certificate. Only accredited certification bodies issue them, after auditing your organization.

What the platform does is get you to that audit knowing exactly where you stand, with evidence in order and gaps identified.

How much does ISO 27001 certification cost?

The cost splits into three independent parts: the certification body’s audit, your team’s internal time, and any supporting tools or consultancy. The first is set by the certification body based on size and scope, and is the only one you cannot reduce on your own.

The part that usually gets out of hand is the second: time lost gathering scattered evidence and redoing documentation. That is precisely what a management platform cuts.

How long does it take to be ready for the audit?

It depends mostly on how much already exists and how much real attention the project gets, not on company size. An organization with written processes that only needs to order and evidence them moves far faster than one starting from scratch, even with ten times fewer people.

Anyone giving you a fixed timeline without looking at your situation is guessing. The first thing the platform gives you is exactly that picture.

What is the difference between stage 1 and stage 2 of the audit?

Stage 1 mainly reviews that the system is designed and documented: that the scope, risk methodology, Statement of Applicability and policies exist. Stage 2 checks that it also works, looking for evidence that controls actually operate day to day.

That is why CertiaSuite scores the two readiness levels separately: being fine for the first and not for the second is common, and knowing it early saves an expensive visit.

What does clause 6.1.2 of ISO 27001 require?

Clause 6.1.2 requires the organization to define and apply an information security risk assessment process: its own criteria for accepting risk, a repeatable way to identify and analyse risks, and assigned owners. The key word is repeatable: two people applying the method should reach comparable results.

In practice, what gets audited is that a written method exists, that it was actually used, and that the results connect to the treatment decisions.

What is the Statement of Applicability?

The Statement of Applicability is the document that walks through the 93 Annex A controls of ISO/IEC 27001:2022 and states, for each one, whether it applies to your organization, why, and what its implementation status is. It is one of the first documents a certification body asks for.

Its real value is not the list: it is traceability. A control should link to the risks it mitigates, the documents describing it and the evidence proving it operates.

Does it work for consultancies with several clients?

Yes. One person can have access to several organizations with different roles, and consultancies get a plan per managed client with grouped billing and their own brand: portal, emails and reports go out under their name and domain.

Each organization keeps its data completely separate from the rest.

Where is the data stored?

Each organization lives in a single region — Europe or the United States — chosen when the account is created, and its data is not replicated outside it. Only encrypted backups cross between regions.

Separation between customers does not depend on the code remembering to filter: the database enforces it.

Can I take my data with me if I stop paying?

Yes, always. Even if the account is suspended for non-payment, you can keep viewing and exporting everything — documents, evidence, Statement of Applicability and reports — until final deletion, and you are emailed at every step before it.

That is a design decision, not a courtesy: your data is not a hostage to make you pay.

Start by knowing where you stand

The quick assessment asks for no card and returns a summary of your main gaps.

Takes 30–45 minutes · Available in English and Spanish

CertiaSuite — Prepare and run your ISO 27001 ISMS without getting lost