What is ISO 27001?
ISO/IEC 27001:2022. B2B SaaS companies, consultancies, financial services, healthcare and any organisation whose customers ask for an ISO 27001 certificate during procurement.
Who needs to comply
- B2B SaaS companies whose customers require ISO 27001 in procurement
- Managed-service providers (MSPs) and consultancies
- Financial services and fintech preparing for DORA on top of ISO 27001
- Healthcare organisations layering NEN 7510 onto ISO 27001
Key ISO 27001 controls covered by Dazr
What auditors look for
A stage-1 audit is documentation review; stage-2 is evidence sampling. Dazr is built around stage-2: every control recurs with an owner, evidence, and an activity log entry on completion.
How Dazr helps with ISO 27001
Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. ISO 27001 is one of its eleven frameworks, available from the free plan. In practice that means:
- Maintain the Statement of Applicability in the portal: applicability and justification per control, approved versions, PDF and XLSX export
- Run quarterly access reviews, annual management reviews and risk-treatment reviews on cadence with email reminders
- Hold the risk register with inherent and residual heatmaps, treatment options and recorded risk acceptance (from Basic)
- Operate the incident register with regulator-notification fields
- Hand the auditor a read-only view for stage-2 sampling, or hand them a single-PDF audit trail
Back to the full Dazr Compliance overview › | Sign up free ›