ISO 27001 ISMS Software

ISO 27001 compliance software, built by an auditor.

Run your full Information Security Management System in PICMS — risk register, Statement of Applicability across all 93 Annex A controls, document control with version history, audit cycle, management review. UK-built, IRCA-aligned, no fluff.

Start 14-Day Trial Book a Demo

A working ISMS, not a folder of policies

ISO 27001:2022 is a management system standard. The certificate hangs on whether you can demonstrate continuous, evidence-backed operation — not whether you have a 90-page Information Security Policy nobody reads.

An auditor walking into your stage-2 visit will check, in roughly this order: that you have a defined ISMS scope, a current risk assessment, a Statement of Applicability mapping every Annex A control to an applicability decision and supporting evidence, document control with version history and authorised approvers, an internal audit programme that has actually run, management review minutes from the last 12 months with verifiable inputs and outputs, a measurable continual improvement record, and incident handling logs.

Spreadsheets work — until they don't. A typical 50-person UK SME pursuing first 27001 certification ends up with one risk register on SharePoint, one Statement of Applicability in Excel, one document library in Teams, internal audit findings in a Word file, management review minutes in someone's mailbox, and zero golden-thread linking the lot. The audit isn't lost on the policy text. It's lost on traceability.

The clauses your auditor will reference

Clause 6.1

Risk assessment + treatment

5×5 matrix or equivalent, asset-based or scenario-based, applied consistently. Every risk traceable to a treatment decision (accept, mitigate, transfer, avoid) and to specific Annex A controls.

Clause 7.5

Documented information

Version history. Approver. Effective date. Distribution list. Retention period. Auditors check whether the document attached to a control evidence record is the version that was current at the time of the activity, not the latest one.

Clause 8

Operation

Risk treatment plan executed and tracked. Changes assessed before deployment. Incidents recorded with chain-of-custody for evidence.

Clause 9.2

Internal audit

Programme. Schedule. Auditor independence. Findings tracked through to closure with verification of effectiveness.

Clause 9.3

Management review

The 12 mandatory inputs from the standard. Decisions recorded. Actions tracked. Distribution evidenced.

Annex A

93 controls (2022 revision)

Each control either applicable (with evidence) or excluded (with justification). The Statement of Applicability is the auditor's reading list.

Every ISO 27001 obligation, mapped to a working module

Risk Register

Asset and scenario-based risks, 5×5 inherent + residual scoring, treatment plans, control linkage, owner assignment, review schedule.

Annex A Controls (93)

Live Statement of Applicability across all 93 ISO 27001:2022 Annex A controls. Per-control evidence linking with confidence scoring.

Document Control

Version history, approval workflow, soft delete with restore, ISO 9001 7.5-compliant. Every uploaded document indexed and searchable.

Internal Audit Module

Audit schedule, finding tracker, CAPA generation from findings, effectiveness verification, full audit trail per ISO 19011.

Management Review

Structured 5-section form with all 12 mandatory clause 9.3.2 inputs, action tracking through 9.3.3 outputs, distribution log.

Golden Thread

Auto-link risks to documents to incidents to CAPAs to audit findings — the traceability auditors look for, without manual cross-referencing.

Incident Command Centre

Voice-enabled incident logging, 5-Whys investigation, automatic CAPA generation, evidence attachment with chain-of-custody.

Training Records

Per-person competency matrix with expiry tracking — supports clause 7.2 evidence and Annex A.6.3 (information security awareness).

What PICMS does not do

Auditor-credible vendors don't pretend software replaces management. PICMS does not:

  • Replace your ISMS Manager. The standard requires accountable people; software supports their work.
  • Auto-implement controls. Annex A.5.16 (identity management) requires you to actually configure your identity provider — PICMS just records the evidence.
  • Issue your certificate. Only an accredited certification body does that. PICMS gets you ready and keeps you ready between audits.
  • Replace your penetration testing programme. Annex A.8.8 (vulnerability management) needs a real pen-test cadence; PICMS tracks the findings.

What PICMS does is give you, your team and your auditor a single source of truth for everything else — so the certification visit is a verification exercise, not a documentation hunt.

Who PICMS is built for

  • UK SMEs pursuing first ISO 27001 certification — typically 20–250 staff, in regulated or B2B sectors where customers are starting to demand ISMS evidence.
  • Existing certificate holders moving off spreadsheet-and-SharePoint sprawl. The migration takes a working week; the time savings recur every audit cycle.
  • ISO consultants managing multiple 27001 client engagements — see PICMS Partners for the white-label workspace model.

Pricing for ISO 27001 organisations

Three tiers fit most 27001 deployments:

  • Essentials — £199/month. One ISO standard (i.e. 27001 alone), 5 users, manual evidence mapping. Right for very small ISMS scopes.
  • Professional — £449/month. Three ISO standards (27001 + 9001 + 14001 or similar stack), 15 users, autonomous AI evidence agents, one industry pack included. The most common 27001 starting point.
  • Certification — £699/month. Five ISO standards, 30 users, unlimited AI queries, two industry packs included. Right for organisations integrating 27001 with broader compliance estates.

See full pricing →

Related reading

  • Trust & Security — our own ISO 27001 journey, UK data residency, encryption posture.
  • Quantum-Ready Compliance — Annex A.8.24 cryptographic controls and the post-quantum transition.
  • All features — the full module list including KPIs, supplier evaluation, environmental aspects, and more.
  • For Consultants — multi-client white-label platform.

Stop assembling your ISMS from spreadsheets.

14 days free, full feature access, no credit card surprise. Built by an IRCA Registered Principal Auditor — the kind of person who'd be on the other side of your certification visit.

Start Free Trial Book a Demo