Certification documentation,
without the dread.
We generate your complete ISO 27001 policy documents, tailored to your tech stack. Your team reviews and approves in one workspace — ready for your auditor in days, not months.
Your 93 controls. Plain and clear.
These controls document how your organisation manages information security at the leadership level — who is responsible, what is required, and how it is enforced. ISO 27001 requires that top management actively directs and supports your security programme.
A.5 · Organisational controls
1 of 5 complete- 5.1
Policies for information security
Approved - 5.2
Information security roles and responsibilities
In progress - 5.3
Segregation of duties
Not started - 5.4
Management responsibilities
In progress - 5.5
Contact with authorities
Not started
- Plain-English guidance
Every control includes a short explanation of what it means and what your auditor needs to see.
- Live status tracking
See at a glance what's approved, in progress, or waiting on your team — nothing gets lost.
- Team approval workflow
Editors draft the policy text; approvers sign off. Your audit trail is built as you work.
Four steps. Days, not months.
- ~15 minutes
Answer questions about your company
The setup wizard walks you through plain-English questions about your team, tools, and how you handle data. No compliance knowledge required.
- Immediately
Your 93 controls are generated
Based on your answers, AuditReady pre-fills all 93 ISO 27001:2022 controls, adapted to your stack — AWS, Okta, GitHub, GCP, and more.
- Typically 1–2 days
Review, edit, and approve as a team
Editors draft the policy text for each control; approvers sign off. The built-in gap analysis flags anything your auditor might question.
- Done
Export for your auditor
Download your complete documentation as Word or PDF. Edit any control and re-export at any time — no limit on revisions or exports.
This is what your auditor receives
Every control produces auditor-ready policy text like this — tailored to your company's details, tech stack, and team structure.
Download a sample policy (PDF)Access Control Policy
Version 2.1 · January 2025 · ISO/IEC 27001:2022 — Control A.5.151. Purpose
This policy establishes requirements for controlling access to Meridian Software Ltd's information assets, systems, and data. Access to all systems — including AWS production infrastructure (eu-west-1), GitHub source repositories, and Okta-managed applications — is granted on the principle of least privilege and reviewed quarterly.
2. Scope
This policy applies to all employees, contractors, and third-party vendors who access Meridian's systems. It covers cloud infrastructure (AWS), identity management (Okta), source control (GitHub), communication tools (Slack), and all applications listed in the approved software register.
3. Access control principles
Access rights are assigned based on the minimum required to perform a defined business function. Privileged accounts require multi-factor authentication. Quarterly access reviews are conducted by the CTO and documented in the access review log. Joiners, movers, and leavers are processed within one business day of HR notification via the identity management system.
Built for teams doing this for the first time.
All 93 controls — none skipped
The complete ISO 27001:2022 Annex A, pre-filled and adapted to your company. Nothing left blank, nothing assumed.
Tailored to your tech stack
Policies adjust to the tools you use — AWS, Okta, GitHub, GCP, and more — so there is nothing to fill in from scratch.
No compliance background needed
Designed for CTOs and engineering leads doing this for the first time. The wizard asks questions in plain English.
Your whole team, one workspace
Editors draft, approvers sign off, and any ISO 27001 consultant you invite works alongside them — no back-and-forth by email.
96,709 organisations certified in 2024
Up from 48,671 the year before. ISO 27001 is increasingly a baseline expectation, not a differentiator — and the path is shorter than most people think. (Source: ISO Survey 2024 / IAF CertSearch)The full standard — all 93 controls
Built on ISO/IEC 27001:2022 Annex A. Every control is included and pre-filled. We don't skip controls because they're inconvenient.What AuditReady is — and isn't
AuditReady prepares your documentation — the policies, controls, and evidence your auditor reviews. Certification itself is a separate step: it's granted by an accredited certification body after their formal audit of your company.
That audit typically costs around €6,000–8,000, paid directly to them. It's required on every route to ISO 27001 certification, regardless of how you prepare. Our job is to make sure you arrive ready for it.
Start free. Pay once when you're ready to export.
Consultants typically quote €14,000–€35,000; US compliance platforms run €11,000–17,000 every year. AuditReady is a one-time payment.
Setup wizard and company profile
All 93 controls, generated and visible
Gap analysis
Up to 3 people in your workspace
| 1–10 people | €990 |
| 11–50 people | €1,990 |
| 51–150 people | €2,990 |
| 151–500 people | €4,490 |
| 500+ people | €5,990 |
93 ISO 27001:2022 controls, tailored to your company
Policies adapt to your tech stack — AWS, Okta, GitHub, GCP, and more
Draft, review, and approve together — editors write, approvers sign off
Gap analysis that flags what's missing before your auditor does
Export your full policy as Word or PDF, as often as you need
Unlimited team members and consultant access — no per-seat fees
Plain-English guidance for every control
Working with a consultant — or looking for one?
Invite your consultant
Any ISO 27001 consultant can join your workspace at no extra cost. They get editor and assessor access — reading your wizard answers, reviewing controls, and adding private notes your team never sees.
Find a specialist
Browse vetted ISO 27001 consultants in the AuditReady directory. Send an engagement request with your workspace context already attached — no cold intro needed.
Things people ask before buying
What exactly do I receive?
A complete set of 93 ISO 27001:2022 controls, pre-filled with your company's details and tailored to the tools you use. You edit and approve them inside AuditReady, then export as a Word document or PDF that you and your auditor can review and sign off on.
Does this certify my company?
No — AuditReady generates the documentation your auditor reviews. Certification is issued by an accredited certification body after their formal audit. We make sure your documentation is thorough and ready for that audit.
What if my auditor requests changes?
Every control is editable inside AuditReady. Update any control at any time, export a fresh Word document or PDF, and send it to your auditor. There's no limit on edits or exports.
Can my team work on this together?
Yes. Once you've unlocked your program you can invite as many teammates as you like at no extra cost — there are no per-seat fees — with roles for admins, editors, approvers, and view-only members. A free workspace holds 3 people, which is room to bring in a colleague and whoever signs off the purchase. Consultants never count towards that. Editors draft policy content and submit controls for approval; approvers review and sign off — so the finished policy reflects decisions your team actually made.
Can we work with a consultant?
Yes. Invite a consultant you already work with, or find an ISO 27001 specialist in our consultant directory. Consultants get their own role in your workspace — they can edit content, assess your controls, and approve alongside your team.
How do I know if we're ready for the audit?
The built-in gap analysis reviews your answers and flags anything missing or inconsistent before your auditor sees it. You can resolve each gap or record a justified waiver — so nothing surprises you in the audit itself.
Which tech stacks do you support?
AWS, GCP, Azure, GitHub, GitLab, Bitbucket, Okta, Google Workspace, Slack, Jira, Linear, and more. During setup you select the tools you use and the documentation adjusts accordingly.
How long does setup take?
Most people complete the company profile in under 15 minutes. From there, your 93 controls are generated immediately. Review, edit, and approve — the whole process typically takes one to two days.
What does the certification audit itself cost?
The certification audit is conducted by an accredited certification body — a separate organisation from AuditReady. They charge independently; fees typically range from around €6,000 to €8,000 depending on your company size and scope. AuditReady's job is to make sure your documentation is thorough before that audit happens, so there are no surprises.
Is our company data secure?
Yes. AuditReady is hosted in Europe and all data is encrypted at rest and in transit. Our full subprocessor list is short by design: a European hosting provider, Lemon Squeezy — a Stripe company who process payments as merchant of record — and Resend for transactional email. The marketing site currently runs no advertising or analytics scripts; if we ever add any, they stay on the marketing site. There is no third-party tracking inside the app.
What if we already started with a consultant or another tool?
No problem. If you have existing policies, paste them into the relevant controls and edit from there. If you're already working with a consultant, invite them to your AuditReady workspace — they get full editor and assessor access and can pick up wherever you left off. AuditReady works alongside your existing process.
The path is already cleared.
Your complete ISO 27001 documentation, tailored to your company — ready for your auditor.