Frameworks · Global standards

ISO 27001:2022 compliance, run as a living system

ISO 27001:2022 is the international standard for information security management systems. It defines an Annex A control set across organisational, people, physical and technological themes, operated as a continuous management system with internal audit and certification.

Who it applies to

Any organisation that manages information risk. In India and the GCC it frequently serves as the base layer beneath sector mandates like SEBI CSCRF, RBI CSF and DPDP.

What it demands

ISMS operation

Scope, risk assessment, statement of applicability, objectives and continual improvement.

Annex A controls

93 controls across organisational, people, physical and technological themes.

Internal audit

Planned internal audits with findings tracked to corrective action.

Management review

Periodic leadership review of performance, risks and improvements.

How Compli-Once runs it

  • 1

    The full Annex A set modelled with owners, evidence and a computed implementation rate.

  • 2

    The crosswalk quantifies how much of CSCRF, RBI CSF and DPDP your ISMS already satisfies.

  • 3

    Internal audits and the certification audit run on one finding and CAPA surface.

What you already satisfy

ISO 27001:2022 overlaps with frameworks you may already run. The crosswalk quantifies existing coverage on day one, before you plan a single task.

Implement once, satisfy many

Access control
ISO 27001 A.5.15SOC 2 CC6.1SEBI CSCRF PR.AARBI CSF Access Mgmt
Incident response
ISO 27001 A.5.24SOC 2 CC7.3SEBI CSCRF 6-hour report
Change management
ISO 27001 A.8.32SOC 2 CC8.1PCI DSS v4 6.5

In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.

Illustrative, computed live per tenant in the platform.

Frequently asked questions

How much of SEBI CSCRF does ISO 27001 cover?

In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by an existing ISO 27001 programme. Your exact figure is computed by the crosswalk from your control state.

Can we run surveillance audits in Compli-Once?

Yes. Certification, surveillance and internal audits all run as engagements on the same surface, with scoped evidence requests and findings tracked to closure.

Is the 2022 revision supported?

Yes. The library carries ISO 27001:2022 with the 93-control Annex A. Mappings from 2013 controls are available for organisations mid-transition.

How is the statement of applicability maintained?

Applicability is recorded per control with justification. It recomputes as controls change, so the SoA is always current rather than rebuilt before each audit.

You're done. We're not.

The audit ends. The readiness doesn't. See it on your own data.