ISO 27001 software questions: 26 answers for buyers
Twenty-six questions in five groups: ISO 27001 basics, Australia and the Essential Eight, buying and pricing, the vendors, and how this site scores. Each answer is short and links to the page that covers it in depth.
ISO 27001 basics
What is ISO 27001?
ISO/IEC 27001:2022 is the international standard that sets requirements for an information security management system. The current version is Edition 3, published in October 2022.
What does ISO 27001 certification prove?
That a certification body audited your ISMS against the standard for a stated scope and found it conforms. It certifies how you manage security, not a product.
What are the ISO 27001 clauses?
Requirements sit in clauses 4 to 10: context of the organization, leadership, planning, support, operation, performance evaluation and improvement.
What is a Statement of Applicability?
The document listing every Annex A control, whether it applies to you, why, and whether it is implemented. Auditors use it to plan testing.
How does the certification audit work?
As general guidance, certification bodies commonly run it in two stages: first a review of ISMS design and readiness, then a test of whether it works in practice, followed by periodic surveillance audits. Your certification body sets the exact plan.
Australia and the Essential Eight
What is the Essential Eight?
Eight mitigation strategies from the Australian Signals Directorate, with a maturity model first published in June 2017 and updated regularly since.
Does ISO 27001 cover the Essential Eight?
No. ISO 27001 does not require it. Many Essential Eight strategies match controls you would select for ISO 27001, but the Essential Eight asks for a specific maturity level.
Which compliance software supports the Essential Eight?
Of the six vendors here, only Vanta publishes an Essential Eight product page, with templates pre-mapped across all eight strategies.
Which vendor ranks first for Australian buyers?
There is one ranking for everyone: Scytale leads at 7.50 of 10 on our ISO 27001 weights. The Essential Eight is not scored; only Vanta publishes an Essential Eight product page, so ask each vendor directly if you need Essential Eight mapping.
Is the Essential Eight a certificate?
The ASD page we reviewed describes assessments against a maturity model using its assessment process guide, not a certificate.
Buying and pricing
How much does ISO 27001 software cost?
Only Secureframe publishes a price in this lineup: Fundamentals starts at $7,500 a year for one framework. The other five quote after a call.
Do any plans include a penetration test?
Scytale's Build DFY and Build Stronger bundles list a pen test. We did not find one on the pricing pages of the other five vendors.
Which plan limits should I watch?
Framework and headcount limits. Drata Foundation covers up to 50 FTEs and one framework; Vanta Essentials and Secureframe Fundamentals list one framework; Sprinto Foundation lists 20 questionnaires a year.
Should the auditor come from the platform vendor?
It can make scheduling easier, but you should still check the certification body's accreditation and how it relates to the vendor. For SOC 2, the AICPA has published guidance on business arrangements between CPA firms and SOC tool providers.
Do I need a platform with the most frameworks?
Only if you need them. Check that the frameworks on your roadmap are pre-mapped and how controls are reused.
The vendors
Which ISO 27001 software ranks first?
Scytale at 7.50 of 10 on our ISO 27001 weights, ahead of Secureframe (7.38) and Vanta (7.24).
What is Scytale best at?
Expert guidance and the certification path: a dedicated compliance expert with weekly meetings, and Built-In Audit with partner auditors. It scores lower on pricing transparency, integrations and the Essential Eight.
What is Vanta best at?
Integrations (400+) and the Essential Eight, where it is the only vendor here with a published product. Expert services come through partners.
What is Drata best at?
A defined start for smaller teams: Foundation covers up to 50 FTEs with one pre-mapped framework such as ISO 27001. It publishes no prices and no integration count.
What is Sprinto best at?
Framework breadth (200+ stated) and control reuse through a common control framework, with auditor network access on Foundation.
What is Scrut best at?
Named AI agents for ISMS tasks, including a Policy Architect, Risk Analyst and Internal Auditor. It has no public pricing page.
What is Secureframe best at?
Pricing transparency and ISMS coverage on its entry plan: Fundamentals starts at $7,500 a year and includes risk, policy and personnel management.
How this site scores
How are the scores calculated?
Seven criteria scored 0 to 10 from public vendor pages, combined into a weighted average with published weights. Totals and winners are computed in code.
Is the Essential Eight part of the ranking?
No. There is one ranking, on the ISO 27001 weights. We show whether each vendor publishes an Essential Eight page as a plain fact, with no points.