ISO 27001 Software

ISO 27001:2022 software that runs the ISMS, $500/mo flat.

A real ISO 27001:2022 ISMS: risk register, Statement of Applicability, CAPA log, internal audits, and management reviews. Not evidence automation. $500/mo flat, unlimited users, cancel anytime.

14-day trial · no card required · $500/mo after trial

What you are actually buying

111 items total: the 93 Annex A controls plus the 18 clause 4-10 management requirements. Each in plain English, with guidance.

Risk register

Qualitative or ISO 27005 depth. Your risk register justifies your controls and generates the Statement of Applicability your auditor will ask for.

Statement of Applicability

The risk register generates the SoA automatically. Every control is linked to the risks it treats, with justifications your auditor can read.

CAPA log

Nonconformities and corrective actions. This is the part of an ISMS a control checklist leaves out.

Internal audits

Audit on a schedule, with objective auditors. Record findings, close them out, and export the history when your certification audit arrives.

Management reviews

ISO 27001 clause 9.3 requires top management to review the ISMS at planned intervals. GapLedger tracks the inputs, outputs, and history.

111 items in plain English

93 Annex A controls plus 18 clause 4-10 requirements. Each with guidance. No security degree required.

Documentation-first. No agents, no forced integrations.

You end up with an information security management system you can keep current and defend when someone asks. No agents to install, no integrations to wire up before you can start.

The risk register generates the Statement of Applicability, which is how you prove your controls are justified and not just a checklist someone filled in.

One-click audit pack

Export your Statement of Applicability, risk register, CAPA log, audit history, and evidence index in a single PDF the morning your auditor arrives. The pack is not the audit, it is what you hand the auditor so they can conduct the audit.

Multi-scope and multi-framework

Run one org-wide ISMS or several at once, for different sites, subsidiaries, or product lines. Manage multiple standards side by side and reuse the same evidence across all of them.

$500/mo flat. Unlimited users.

Or $5,400/yr and save 10%. No per-employee tax, no renewal surprises, cancel anytime. Add SOC 2 later for +$150/mo, it reuses your ISO 27001 evidence.

How we run our own controls

Enforced multi-factor auth, strict tenant isolation, write-once evidence with an append-only audit trail, encryption at rest, and least privilege throughout. Read the security page.

If comparing evidence-automation tools

GapLedger is an ISMS, not an evidence collector. If you are comparing evidence-automation tools like Vanta or Drata, read the Vanta alternative page.

Consultants and MSPs

If you manage client organizations, see ISMS software for consultants. Practice plan: $1,000/mo, unlimited clients, portfolio dashboard, 1-minute provision, your own ISMS included.

Start your 14-day trial

No card required. $500/mo after trial, or $5,400/yr and save 10%. Cancel anytime.

Frequently asked questions

Can I use a spreadsheet until Stage 1?

Yes. Many organizations start with a spreadsheet and move to GapLedger when they are ready to maintain the ISMS long-term. The risk register and Statement of Applicability you build here will be what you defend at Stage 2 and every surveillance audit after.

What about integrations?

GapLedger is documentation-first. No agents to install, no integrations to wire up before you can start. If you want evidence automation, compare Vanta or Drata instead.

Can I import an existing risk spreadsheet?

Not automatically. You will re-enter your risks into GapLedger, which is faster than it sounds because the system generates the Statement of Applicability from the risk register as you go.

Does the audit pack mean we pass?

No. The audit pack is what you hand the auditor so they can conduct the audit. Certification decisions rest with your accredited auditor, and GapLedger is not a certification body.

Does GapLedger certify us?

No. GapLedger is compliance management software, not a certification body. Certification decisions rest with your accredited auditor.

What does Core include?

Full ISO 27001:2022 (93 Annex A controls plus 18 clause 4-10 requirements), unlimited users, risk register, Statement of Applicability, CAPA log, internal audits, management reviews, and the one-click audit pack. $500/mo or $5,400/yr.