Before you chase certification, read the contract.
Most organizations arrive at ISO 27001 because a customer, a prospect or a renewal mentioned it. The exact wording matters more than almost anything else you'll decide.
Those are not the same thing — and the difference can save you a great deal of time, cost and effort.
Which sentence is in your contract?
Go and look — it takes two minutes and it decides the size of everything that follows. Pick the one closer to what you've been sent.
Plenty of contracts are written by someone who used the words interchangeably. One email to your customer's procurement contact — "are you asking for alignment or for a certificate from an accredited body?" — is the highest-return question on this page.
ISO 27001 is not a list of controls. It's a management system.
The standard requires you to establish, operate, maintain, review and continually improve an Information Security Management System. The controls sit inside that — they aren't the point of it.
We're not a certification body. We help you prepare — organizing requirements, assigning work, managing evidence and reviewing readiness before an external certification audit.
Certification is performed by an accredited certification body. Just as a CPA firm issues a SOC 2 report, a certification body issues the certificate.
The 2022 revision changed the control structure
Organizations researching ISO 27001 run into a lot of outdated content. The current standard is ISO/IEC 27001:2022, and Annex A was restructured.
If the implementation guidance you're reading uses the old numbering, it predates the current revision. Check before you build anything from it.
Most ISO 27001 work is operational, not documentary
Organizations often assume ISO 27001 is mainly about writing documents. In practice, most requirements turn into activities that have to keep happening.
How Greypike runs ISO 27001
Every ISO 27001 requirement becomes one or more tasks. Instead of maintaining an ISMS through spreadsheets and calendar reminders, the management system runs as a structured workflow — and a compliance manager checks the evidence before a certification body ever sees it.
Conduct the internal audit of the ISMS
Audit the management system against the standard and your own documented procedures. Record findings, assign corrective actions, and confirm they close.
Not yet — the audit found nothing, and an auditor who finds nothing is the finding. A clean internal audit with no observations reads as an audit that wasn't really performed. Look again at supplier reviews and access, then resubmit.
The strongest reason to pursue ISO 27001 may be the work you've already done
Most organizations arriving here have already completed meaningful security work. The mistake is assuming all of it has to be repeated.
TICK WHAT YOU'VE ALREADY GOT
Risk assessments remain risk assessments. Access reviews remain access reviews. Greypike maps completed tasks and supporting evidence across frameworks, so you leverage what you've already invested rather than restarting.
Why organizations choose Greypike
The challenge is not understanding the standard. It's making sure the work gets completed, evidence stays current, reviews happen on time, and an auditor receives a well-run programme rather than a folder.
Straightforward pricing
No sales process required to see the number. ISO 27001 is one framework, and one framework is what the subscription covers.
or $4,000 a year, saving $788
First 25 customers only. Standard pricing is higher. Founding customers keep this rate for 24 months. 12-month term, no setup fee.
Book a demoAdding SOC 2 later? See framework pricing →
Build the management system. Not another spreadsheet.
ISO 27001 requirements become assigned tasks and recurring workflows, with evidence reviewed by a dedicated compliance manager. And if you have already done the work elsewhere, you bring it with you.