---
title: "ISO 27001 with AuditBadger — ISMS platform for startups"
canonical: "https://auditbadger.com/iso27001/"
last-updated: "2026-09-22"
---

# ISO 27001 with AuditBadger — ISMS platform for startups

AuditBadger is an AI-powered ISMS (Information Security Management System) platform that takes a software startup from zero to **ISO 27001:2022 certification** without hiring a consultant. The product covers the full ISMS workbook (Clauses 4–10), all 93 Annex A controls via a guided Statement of Applicability, automated evidence collection, and AI-powered document adequacy verification.

## ISO 27001 in 60 seconds

- **ISO 27001:2022** is an international standard for information security management. Unlike SOC 2, it is a true certification, issued by an accredited certification body following a two-stage audit.
- The standard has two parts:
  - **Mandatory clauses 4–10** — context, leadership, planning, support, operation, evaluation, improvement
  - **Annex A** — 93 controls (down from 114 in the 2013 version), grouped into 4 themes (organizational, people, physical, technological)
- The **Statement of Applicability (SOA)** documents which Annex A controls apply to your organization and justifies any exclusions.
- Certification cycle: Stage 1 audit (documentation) → Stage 2 audit (implementation) → 3-year certification with annual surveillance audits.
- Typical timeline for a startup: **8–12 weeks** of ISMS implementation, then 4–8 weeks of audit windows.

## What AuditBadger handles for ISO 27001

| Area | What you get |
|---|---|
| **ISMS Workbook** | Every requirement in Clauses 4–10 with the standard text, auditor expectations, and evidence guidance, plus per-clause completion tracking |
| **Audit-readiness gating** | Built-in 80% completion gate per clause before the platform considers you Stage 1 ready |
| **Statement of Applicability (SOA)** | Guided control-by-control assessment of all **93 Annex A controls**, applicability justifications, approval workflow with user/date stamping |
| **AI document verification** | Every linked document is scored 0–100 against the requirement it satisfies, with specific gap findings ("Your Access Control Policy doesn't address periodic review cycles") |
| **Management reviews (Clause 9.3)** | All **10 required inputs** tracked automatically; reviews cannot be closed until every input is addressed |
| **Risk assessment** | Full lifecycle — identification, treatment (accept / mitigate / transfer / avoid), risk-to-control mapping, residual risk |
| **Internal audit** | Audit programme, findings, and CAPA (corrective and preventive action) workflow |
| **Automated evidence collection** | Recurring evidence from AWS, GCP, Azure, DigitalOcean, Scaleway, GitHub, Cloudflare, Linear, Shortcut, Slack, Google Workspace, and FleetDM; AI-assisted relevance for each clause/control |
| **Document management** | Policy library, version control, employee acknowledgment tracking, AI-generated policies for your actual stack |

## Annex A 2022 control breakdown

| Theme | Controls |
|---|---|
| **A.5 Organizational controls** | 37 controls |
| **A.6 People controls** | 8 controls |
| **A.7 Physical controls** | 14 controls |
| **A.8 Technological controls** | 34 controls |
| **Total** | **93 controls** |

AuditBadger presents each control with a recommended applicability decision based on your organization profile (software-only? remote-first? handles PII?), and stores the justification text required for the SOA.

## Mandatory clauses (4–10) — what each is for

| Clause | Purpose | Key AuditBadger module |
|---|---|---|
| **4. Context of the organization** | Identify stakeholders, scope of the ISMS | Context builder, scope statement |
| **5. Leadership** | Top management commitment, information security policy, roles | Policy library, RACI tracking |
| **6. Planning** | Risk assessment, risk treatment, security objectives, change planning | Risk register, objectives module |
| **7. Support** | Resources, competence, awareness, communication, documented information | Training & Awareness, document control |
| **8. Operation** | Operational planning, control of changes, risk treatment in practice | Operations module |
| **9. Performance evaluation** | Monitoring, internal audit, management review (with 10 mandatory inputs) | Internal audit + management review module |
| **10. Improvement** | Nonconformities, corrective actions, continual improvement | CAPA workflow |

## The 10 management review inputs (Clause 9.3) — all auto-tracked

1. Status of actions from previous management reviews
2. Changes in external and internal issues relevant to the ISMS
3. Changes in the needs and expectations of interested parties
4. Feedback on information security performance, including nonconformities, monitoring results, audit results, fulfilment of objectives
5. Feedback from interested parties
6. Results of risk assessment and status of the risk treatment plan
7. Opportunities for continual improvement
8. Decisions related to continual improvement and any need for changes to the ISMS

(Plus action item tracking, attendees, and improvement opportunities, all enforced before the review can be closed.)

## Automated evidence integrations

Same integrations as for SOC 2 — connected once, mapped to both frameworks.

| Integration | Evidence types |
|---|---|
| **AWS** | 22 — IAM, MFA, CloudTrail, GuardDuty, S3/RDS/EBS encryption, VPC, security groups |
| **Google Cloud** | 15 — IAM, MFA, Cloud Audit Logs, Security Command Center, KMS, Storage/SQL/Compute encryption, VPC Flow Logs, firewall rules |
| **GitHub** | 12 — org 2FA enforcement, branch protection, secret scanning, Dependabot, audit logs |
| **Cloudflare** | 11 — SSL/TLS, HSTS, WAF, DDoS protection, bot protection, rate limiting, DNSSEC |

Schedules: continuous, daily, weekly, monthly, or on-demand. AI scores each piece of evidence's relevance to each ISO requirement (0–100).

## Annex A control to AuditBadger module mapping

| Annex A range | What it covers | AuditBadger module |
|---|---|---|
| A.5.9 – A.5.14 | Information asset management | Asset management |
| A.5.19 – A.5.23 | Supplier relationships | Vendor assessment |
| A.5.24 – A.5.28 | Information security incident management | Incident management |
| A.5.29 – A.5.30 | Business continuity, ICT readiness | Business continuity |
| A.6 | People controls | Training & Awareness |
| A.8 | Technological controls (access, crypto, logging, network…) | Automated evidence collection + control implementation tracking |

## Certification stages — what AuditBadger does at each stage

1. **Implementation (8–12 weeks)**: Build the ISMS in the workbook. Complete Clauses 4–10. Run initial risk assessment. Generate SOA. Generate stack-aware policies.
2. **Stage 1 audit (documentation review)**: Auditor reviews ISMS documentation. The 80% completion gate prevents premature scheduling. AI document verification catches adequacy gaps before the auditor does.
3. **Stage 2 audit (implementation review)**: Auditor verifies the ISMS is actually implemented and effective. Automated evidence shows continuous operation. Findings tracked through the CAPA workflow.
4. **Certification + surveillance audits**: 3-year certification cycle. AuditBadger handles ongoing management reviews, objectives tracking, evidence freshness, and surveillance prep.

## Pricing

- **$250 / month** flat — full ISO 27001 module, all integrations, unlimited users
- Includes both ISO 27001 and SOC 2 — they share the same underlying control library and evidence
- Audit fees paid directly to your certification body (independent of AuditBadger)
- Typical certification body fees: €5k–15k for Stage 1 + Stage 2 combined; €2k–5k per annual surveillance audit

## Useful links

- Sign up: [auth.auditbadger.com/signup](https://auth.auditbadger.com/signup)
- Free policy generator (no signup): [/free-compliance-policies-generator](/free-compliance-policies-generator)
- Companion guide for SOC 2: [/compliance/soc2](/compliance/soc2)
- Compare to Vanta: [/compare/vanta](/compare/vanta)
- Compare to Drata: [/compare/drata](/compare/drata)
- Automated evidence detail: [/features/automated-evidence-collection](/features/automated-evidence-collection)
- Risk assessment detail: [/features/risk-assessment](/features/risk-assessment)
- Business continuity detail: [/features/business-continuity](/features/business-continuity)
- Contact: hello@auditbadger.com
