Before you chase certification, read the contract.

Most organizations arrive at ISO 27001 because a customer, a prospect or a renewal mentioned it. The exact wording matters more than almost anything else you'll decide.

SOME CONTRACTS SAY ISO 27001 alignment Demonstrating that your security program follows ISO 27001 principles and controls.
OTHERS SAY ISO 27001 certification An accredited certification body has formally audited and certified your ISMS.

Those are not the same thing — and the difference can save you a great deal of time, cost and effort.

Which sentence is in your contract?

Go and look — it takes two minutes and it decides the size of everything that follows. Pick the one closer to what you've been sent.

If it's ambiguous, ask before you spend anything

Plenty of contracts are written by someone who used the words interchangeably. One email to your customer's procurement contact — "are you asking for alignment or for a certificate from an accredited body?" — is the highest-return question on this page.

ISO 27001 is not a list of controls. It's a management system.

The standard requires you to establish, operate, maintain, review and continually improve an Information Security Management System. The controls sit inside that — they aren't the point of it.

1Defined scope
What systems, people, locations and processes the ISMS covers.
2Security objectives
The business goals the security program exists to support.
3Risk assessment
A structured process for identifying and evaluating information security risks.
4Risk treatment
How each identified risk will be addressed, and which controls apply.
5Statement of Applicability
A record of which Annex A controls apply to you, and why.
6Annex A controls
The controls selected to support your risk treatment decisions.
7Internal audits
Periodic reviews of the management system, performed and recorded.
8Management review
Leadership reviewing effectiveness and performance. Actually leadership.
9Continual improvement
Using findings, incidents and audit results to improve over time.
Greypike does not issue ISO 27001 certifications

We're not a certification body. We help you prepare — organizing requirements, assigning work, managing evidence and reviewing readiness before an external certification audit.

Certification is performed by an accredited certification body. Just as a CPA firm issues a SOC 2 report, a certification body issues the certificate.

The 2022 revision changed the control structure

Organizations researching ISO 27001 run into a lot of outdated content. The current standard is ISO/IEC 27001:2022, and Annex A was restructured.

!

If the implementation guidance you're reading uses the old numbering, it predates the current revision. Check before you build anything from it.

Most ISO 27001 work is operational, not documentary

Organizations often assume ISO 27001 is mainly about writing documents. In practice, most requirements turn into activities that have to keep happening.

Risk reviewsAssessing new and changing risks as the business moves.
Access reviewsVerifying that users still hold appropriate access.
Vendor managementEvaluating supplier security risks, on a cycle.
Security trainingMaintaining awareness and the record that it happened.
Incident managementDocumenting and responding to events when they occur.
Internal auditsReviewing whether the management system is working.
Management reviewsLeadership oversight and the decisions that follow.
Policy maintenanceReviewing and updating governance documentation.
The framework is important. The work is what actually produces compliance. An ISMS that exists on paper and hasn't been operated is the single most common finding at a certification audit — and the hardest one to fix quickly.

How Greypike runs ISO 27001

Every ISO 27001 requirement becomes one or more tasks. Instead of maintaining an ISMS through spreadsheets and calendar reminders, the management system runs as a structured workflow — and a compliance manager checks the evidence before a certification body ever sees it.

WHO THIS USUALLY LANDS ON
Operations leadersTechnology leadersSecurity leadersIT managersFoundersQuality managers
A dedicated compliance manager, included Most organizations pursuing ISO 27001 have no dedicated compliance personnel. Greypike includes a named person who reviews completed work and makes sure the evidence is ready before an auditor or certification body sees it.

The strongest reason to pursue ISO 27001 may be the work you've already done

Most organizations arriving here have already completed meaningful security work. The mistake is assuming all of it has to be repeated.

TICK WHAT YOU'VE ALREADY GOT

What carries across0AREAS OF REUSE

Risk assessments remain risk assessments. Access reviews remain access reviews. Greypike maps completed tasks and supporting evidence across frameworks, so you leverage what you've already invested rather than restarting.

Why organizations choose Greypike

The challenge is not understanding the standard. It's making sure the work gets completed, evidence stays current, reviews happen on time, and an auditor receives a well-run programme rather than a folder.

The traditional ISO 27001 approach
Greypike
Separate compliance projects
Unified compliance program
Policy-heavy process
Task-based execution
Evidence scattered across systems
Centralized evidence management
Last-minute audit preparation
Continuous readiness
Consultant-dependent
Software with compliance manager review
Duplicate effort across frameworks
Framework reuse

Straightforward pricing

No sales process required to see the number. ISO 27001 is one framework, and one framework is what the subscription covers.

FOUNDING CUSTOMER PRICE
$399per month

or $4,000 a year, saving $788

First 25 customers only. Standard pricing is higher. Founding customers keep this rate for 24 months. 12-month term, no setup fee.

Book a demo
WHAT'S INCLUDED
A dedicated compliance manager
ISO 27001 converted into assigned tasks
Evidence management
Continuous monitoring
Framework mapping and reuse

Adding SOC 2 later? See framework pricing →

Build the management system. Not another spreadsheet.

ISO 27001 requirements become assigned tasks and recurring workflows, with evidence reviewed by a dedicated compliance manager. And if you have already done the work elsewhere, you bring it with you.