ISMS Software
ISMS software is a platform for the management system, not an evidence collector.
GapLedger runs the information security management system itself: risk register, Statement of Applicability, CAPA log, internal audits, and management reviews. Not evidence automation. $500/mo flat, unlimited users.
14-day trial · no card required · $500/mo flat
ISMS vs compliance automation
ISMS software is the platform for the management system: the risk register that justifies your controls, the Statement of Applicability that documents which controls apply and why, the CAPA log that tracks nonconformities, and the audit and review history that proves the system is maintained over time.
Evidence automation is different. Tools like Vanta and Drata wire integrations to your infrastructure and collect evidence automatically. That is valuable, but it is not the same job as the management system itself.
If you are shopping for evidence automation, compare Vanta and Drata directly. If you want the management system, GapLedger is built for that. Read the Vanta alternative page.
What ISMS software includes
An information security management system is defined by ISO 27001. It includes the risk register, the Statement of Applicability, nonconformities and corrective actions, internal audits, and management reviews.
Risk register
The risk assessment justifies your controls. Qualitative or ISO 27005 depth. The register generates the Statement of Applicability automatically.
Statement of Applicability
The SoA documents which controls apply and why. Every control is linked to the risks it treats, with justifications your auditor can read.
CAPA log
Nonconformities and corrective actions. ISO 27001 clause 10.1 requires this, and a control checklist leaves it out.
Internal audits
Clause 9.2 requires internal audits at planned intervals. GapLedger tracks the schedule, findings, and close-out history.
Management reviews
Clause 9.3 requires top management to review the ISMS. GapLedger tracks the inputs, outputs, and history so the review is documented and repeatable.
Clauses 4-10
93 Annex A controls plus 18 management requirements from clauses 4 through 10. All 111 items in plain English, each with guidance.
$500/mo flat. Unlimited users.
Or $5,400/yr and save 10%. No per-employee tax, no renewal surprises, cancel anytime.
ISO 27001 software
If you searched for ISO 27001 software and landed here, read the ISO 27001 software page. That page names the standard and covers the full product.
Frequently asked questions
Does GapLedger automate evidence collection?
No. GapLedger is the ISMS itself: risk register, Statement of Applicability, CAPA log, internal audits, and management reviews. If you want evidence automation, compare Vanta or Drata instead.
What does Core include?
Full ISO 27001:2022 (93 Annex A controls plus 18 clause 4-10 requirements), unlimited users, risk register, Statement of Applicability, CAPA log, internal audits, management reviews, and the one-click audit pack. $500/mo or $5,400/yr.
Does GapLedger certify us?
No. GapLedger is compliance management software, not a certification body. Certification decisions rest with your accredited auditor.