ISO 27001 Documentation
ISO 27001 documentation that stays current: SoA, risk register, clauses 4-10.
A living ISO 27001:2022 management system, not a spreadsheet kit. The risk register generates the Statement of Applicability automatically. Every control is linked to the risks it treats, with justifications your auditor can read. $500/mo flat, unlimited users.
14-day trial · no card required · $500/mo after trial
Kits vs a living ISMS
ISO 27001 documentation kits are spreadsheets and templates you download once, fill in, and save as PDFs. They work, but the day you complete the kit it starts to go stale.
GapLedger is a living management system. The risk register generates the Statement of Applicability, which stays current as risks and controls change. Audits, reviews, and nonconformities are tracked over time, not lost in a folder of static files.
SoA generated from the risk register
The Statement of Applicability is not a separate document you maintain by hand. Every control is linked to the risks it treats, and the SoA is generated automatically. When a risk changes or a control is updated, the SoA reflects it immediately.
Your auditor will ask for the SoA. They will also ask how you justified each control. With GapLedger, both answers are in the same document: the risk register and the generated SoA, with justifications visible for every decision.
Clauses 4-10, not just Annex A
ISO 27001 is 93 Annex A controls plus 18 management requirements in clauses 4 through 10. Most documentation kits focus on the controls and leave the management clauses for you to figure out.
GapLedger includes all 111 items: the 93 controls and the 18 management requirements. Internal audits (clause 9.2), management reviews (clause 9.3), nonconformities and corrective actions (clause 10.1) are all tracked in the system, not bolted on later.
The full ISO 27001 ISMS
If you want the complete ISO 27001 software platform, read ISO 27001 software. That page covers the whole product: risk register, Statement of Applicability, CAPA log, internal audits, management reviews, and the one-click audit pack.
$500/mo flat. Unlimited users.
Or $5,400/yr and save 10%. No per-employee tax, no renewal surprises, cancel anytime.
Frequently asked questions
Can I use a spreadsheet kit until Stage 1?
Yes. Many organizations start with a spreadsheet kit and move to GapLedger when they are ready to maintain the ISMS long-term. The risk register and Statement of Applicability you build here will be what you defend at Stage 2 and every surveillance audit after.
What is the difference between a kit and GapLedger?
A kit is a set of templates and spreadsheets you download, fill in, and save as PDFs. GapLedger is a living management system that stays current as your ISMS changes. The SoA is generated from the risk register, not maintained as a separate document.
Does GapLedger certify us?
No. GapLedger is compliance management software, not a certification body. Certification decisions rest with your accredited auditor.
What does Core include?
Full ISO 27001:2022 (93 Annex A controls plus 18 clause 4-10 requirements), unlimited users, risk register, Statement of Applicability, CAPA log, internal audits, management reviews, and the one-click audit pack. $500/mo or $5,400/yr.