This note covers announcements from December 2025 to September 2026 that appear on the vendor and standards pages we reviewed, grouped by theme. It also restates the older standards dates that the rest of the site relies on.
One of the six vendors on this site publishes a price. Four publish plan contents and limits without prices, and one has no pricing page. Here is what each says, and how to use plan limits when you ask for quotes.
Every ISO 27001 platform on this site except one describes a route to an auditor. The routes differ in who manages the audit. Whatever the route, the checks on the auditor are yours to make.
Some beliefs about ISO 27001 platforms survive because they are half true. Here are six, each checked against what the vendors on this site publish and what the standard says.
Framework counts on vendor pages range from 30+ to 200+ in this lineup. The count is a rough signal of breadth. Whether your next framework is pre-mapped and how controls are reused matters more.
Integration counts on the six vendors' pages run from 100+ to 400+, and one vendor publishes no count at all. For ISO 27001 evidence, five or six categories of integration do most of the work.
Vendor demos show the parts that look good. These fifteen questions steer the demo toward the parts an ISO 27001 auditor will test, and toward the limits that only appear in the contract.
Australian customer questionnaires often mix two frameworks. ISO 27001 questions ask whether you manage security as a system; Essential Eight questions ask how far eight specific controls go. Sorting them first makes the answers faster and more accurate.