How we assess ISO 27001 software: criteria, weights and limits
We score six ISO 27001 platforms from 0 to 10 on seven criteria, using only what each vendor publishes on its own pages, read on 29 September 2026. Totals are weighted averages computed in code from two published weight profiles.
What do we score?
We score what a buyer can verify before a sales call: what each vendor's public pages say about ISMS workflows, the route to a certification audit, who provides expert help, how many frameworks are covered and whether controls are reused, how many integrations are published, how much pricing is shown, and whether the ASD Essential Eight is supported. We do not score product quality, user interface, support response times or customer satisfaction, because we cannot verify those from public pages.
What does each score level mean?
| Criterion | Rubric |
|---|---|
| ISO 27001 and ISMS workflow coverage | 9 to 10: names ISO 27001 and describes workflows in nearly every clause area from 5 to 10. 7 to 8: names ISO 27001 or related ISO standards and describes most clause areas. 5 to 6: describes a few clause areas. 1 to 4: little described. |
| Certification path and auditor access | 9 to 10: built-in audit with partner auditors plus vendor-managed audit process. 7 to 8: auditor network or bring-your-own-auditor with audit management. 5 to 6: auditors mentioned only as partners. Below 5: not described. |
| Expert guidance model | 9 to 10: a dedicated expert who runs readiness with the customer. 6 to 7: expert help through partners or described without detail. 5 to 6: support channels only. |
| Cross-mapping and framework breadth | 9 to 10: 200+ frameworks with stated control reuse. 7.5 to 8: 70+ to 80+ with stated cross-mapping or a unified control framework. 6 to 7: 30+ frameworks, or a broad list without a count. |
| Integrations (published count) | 9: 400+. 8: 300+. 6 to 6.5: 100+ to 150+, or 'hundreds' with no count. |
| Pricing transparency | 8: a published starting price. 4 to 4.5: plan names, contents and limits published without prices. 1 to 2: no pricing page. |
| Essential Eight support | 9: a published Essential Eight product. 1: no Essential Eight page found on the pages reviewed. |
How are the weights set?
| Criterion | Weight |
|---|---|
| ISO 27001 and ISMS workflow coverage | 22 |
| Certification path and auditor access | 18 |
| Expert guidance model | 18 |
| Cross-mapping and framework breadth | 14 |
| Integrations (published count) | 14 |
| Pricing transparency | 14 |
| Essential Eight support | 0 |
| Total | 100 |
The ISO 27001 weights reflect what decides a first certification: whether the platform covers the ISMS, whether there is a clear route to the audit, and who does the work. Cross-mapping, integrations and pricing transparency matter, but less. The Essential Eight gets no weight here because ISO 27001 does not require it. We show it as a plain fact instead: whether each vendor publishes an Essential Eight page.
How is a total calculated?
Total = (sum of criterion score × weight) ÷ (sum of weights). We keep one decimal for criterion scores and show totals to two decimals, rounded half up. Rankings sort by the exact total; equal totals are shown as ties. Head-to-head winners, leaders and every 'scores higher on' statement on this site are computed from the same table, not written by hand.
| Criterion | Score | Weight | Score × weight |
|---|---|---|---|
| ISO 27001 and ISMS workflow coverage | 7.5 | 22 | 165.0 |
| Certification path and auditor access | 9.0 | 18 | 162.0 |
| Expert guidance model | 9.5 | 18 | 171.0 |
| Cross-mapping and framework breadth | 8.0 | 14 | 112.0 |
| Integrations (published count) | 6.0 | 14 | 84.0 |
| Pricing transparency | 4.0 | 14 | 56.0 |
| Essential Eight support | 1.0 | 0 | 0.0 |
| Sum | 100 | 750.0 |
750.0 ÷ 100 = 7.50
What happens when a vendor does not publish something?
If we could not find a feature on the pages we reviewed, the cell says 'Not described' or 'Not found on the pages reviewed' and the score reflects it. That is a statement about public information, not a finding that the product lacks the feature. When a vendor publishes it, we update the score and log the change on the Updates page. Where vendor pages disagree with each other (Scytale states 100+ integrations on one page and 150+ on another; Scrut states 70+ and 60+ frameworks), we use the lower figure in the score and show both.
Which claims do we not use?
We do not use vendor-stated review scores or star ratings, because the source of the rating is not always named on the vendor page. We attribute superlatives and numeric performance claims to the vendor (for example, Vanta states a 95% acceptance rate for its questionnaire suggestions; Scytale states its questionnaire reviews are shared 85% faster) and never treat them as findings.
What are the limitations?
- Public sources only: vendor websites, pricing pages and product pages, plus iso.org and cyber.gov.au for the standards.
- No hands-on testing, no trial accounts and no vendor interviews.
- Pages were read on 29 September 2026; vendors change their pages often.
- Weights are editorial choices. The cost estimator lets you set your own.
- Six vendors only. Other ISO 27001 platforms exist and are not covered.
Corrections
If a vendor fact here is out of date, the vendor's current public page is the reference. Corrections are logged with a date on the Updates page.
Common questions
Do you test the products?
No. Every score comes from public vendor pages. We say so on every ranking page.
Why is the Essential Eight weighted at 0 in the main ranking?
ISO 27001 certification does not require it. It is not part of any total. We show whether each vendor publishes an Essential Eight page, and only Vanta does.
Can vendors pay to change their scores?
No. Scores change only when a vendor's public pages change, and every change is dated on the Updates page.
Who writes this site?
The Clause Desk at ISO 27001 Compare, published by Alegria Media and Consulting Ltd.