An ISO 27001 platform demo checklist: 15 questions to ask
By the Clause Desk · · Updated
Vendor demos show the parts that look good. These fifteen questions steer the demo toward the parts an ISO 27001 auditor will test, and toward the limits that only appear in the contract.
How do you test ISMS coverage?
1. Show how we set and record the ISMS scope. (No vendor on this site describes a scope workflow on its public pages, so expect to own this.) 2. Show a risk being added, scored, treated and reviewed, and who does each step. 3. Show the Statement of Applicability export and whether we control the justification text. 4. Show how internal audit and management review are recorded. 5. Show a failed control turning into a corrective action and being closed.
How do you test the audit route?
6. Name the certification bodies you work with and their accreditation. 7. Tell us who manages the audit timeline and who attends the audit. Scytale says it takes over full management of the audit process with your chosen auditor; Sprinto lists network auditor access or bring your own auditor; Vanta, Secureframe and Drata describe auditor networks or partners. 8. Tell us whether the plan price includes the audit fee.
How do you test the service model?
9. Name the person who will work with us, how often we meet and what they do versus what we do. Scytale describes a dedicated compliance expert with weekly meetings; Vanta and Drata describe partner networks; Sprinto's Foundation plan lists 24x5 email and in-app support. 10. Show what the AI features do today and which are marked as coming later. Scytale, for example, marks its AI Policy Generator as Coming soon.
How do you test frameworks and integrations?
11. Show our next framework pre-mapped, and one control shared between it and ISO 27001. 12. Connect to our actual identity provider, cloud account and HR system, and show the evidence each produces. Integration counts range from 100+ on Scytale's integrations page to 400+ on Vanta's, but the three or four tools you run matter more than the total. 13. If we sell into Australia, show the Essential Eight mapping and the maturity model version it follows. Vanta is the only vendor here with a published Essential Eight product.
How do you test price and limits?
14. Name the plan that fits our brief and confirm its limits in writing: frameworks, headcount, questionnaires per year. Drata Foundation stops at 50 FTEs and one framework; Vanta lists 25 or 144 questionnaires a year on Plus and Professional; Sprinto lists 20 on Foundation. 15. Tell us what happens at renewal if we add a framework or grow past a limit.
What should you send before the demo?
Send a one-page brief a few days ahead: your draft ISMS scope, headcount, the frameworks you need this year and next, your identity provider, cloud provider, HR system and device management tool, whether Australian customers ask about the Essential Eight, and your target audit date. Ask the vendor to prepare the demo on that brief rather than a generic tenant. A vendor that shows your own stack and your own next framework gives you far more to compare than one that shows a sample company.
How should you score the answers?
Write each vendor's answer next to the question during the call, and mark any answer that is a promise rather than a demonstration. After three demos, the pattern is usually clear: one vendor will show the risk and audit workflow, one will show integrations, and one will show price. Weight those against your own situation in our cost estimator.
What is the takeaway?
Bring the same fifteen questions to every demo, ask for demonstrations rather than slides, and get limits and prices in writing before you compare.
Filed under: Buying