Home › Frameworks › ISO 27001

ISO 27001 compliance software, EU-built and audit-ready.

All 93 Annex A controls and clauses 4-10 with descriptions, recommendations and review cadences, evidence on every control, a Statement of Applicability, read-only auditor access on Pro and a PDF audit trail (white-label on Enterprise). Free for one framework; Basic from €29 a month.

At a glance

  • A.5 Organisational: 37 controls covering policies, roles, supplier relationships, threat intelligence, incident response.
  • A.6 People: 8 controls on screening, terms of employment, awareness, disciplinary process.
  • A.7 Physical: 14 controls on perimeter, equipment, secure disposal, clear desk.
  • A.8 Technological: 34 controls on access control, cryptography, logging, vulnerability management, BCP-IT.

On this page

  1. What is ISO 27001?
  2. Who needs to comply
  3. Key ISO 27001 controls covered by Dazr
  4. What auditors look for
  5. How Dazr helps with ISO 27001

What is ISO 27001?

ISO/IEC 27001:2022. B2B SaaS companies, consultancies, financial services, healthcare and any organisation whose customers ask for an ISO 27001 certificate during procurement.

Who needs to comply

  • B2B SaaS companies whose customers require ISO 27001 in procurement
  • Managed-service providers (MSPs) and consultancies
  • Financial services and fintech preparing for DORA on top of ISO 27001
  • Healthcare organisations layering NEN 7510 onto ISO 27001

Key ISO 27001 controls covered by Dazr

A.5 Organisational37 controls covering policies, roles, supplier relationships, threat intelligence, incident response.
A.6 People8 controls on screening, terms of employment, awareness, disciplinary process.
A.7 Physical14 controls on perimeter, equipment, secure disposal, clear desk.
A.8 Technological34 controls on access control, cryptography, logging, vulnerability management, BCP-IT.

What auditors look for

A stage-1 audit is documentation review; stage-2 is evidence sampling. Dazr is built around stage-2: every control recurs with an owner, evidence, and an activity log entry on completion.

How Dazr helps with ISO 27001

Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. ISO 27001 is one of its eleven frameworks, available from the free plan. In practice that means:

  • Maintain the Statement of Applicability in the portal: applicability and justification per control, approved versions, PDF and XLSX export
  • Run quarterly access reviews, annual management reviews and risk-treatment reviews on cadence with email reminders
  • Hold the risk register with inherent and residual heatmaps, treatment options and recorded risk acceptance (from Basic)
  • Operate the incident register with regulator-notification fields
  • Hand the auditor a read-only view for stage-2 sampling, or hand them a single-PDF audit trail

Back to the full Dazr Compliance overview › | Sign up free ›

ISO 27001 questions, answered.

How many controls does the platform cover?

All 93 Annex A controls in ISO 27001:2022, plus the Clause 4-10 management-system requirements (scope, leadership, planning, support, operation, performance evaluation, improvement). Each control has a description, recommendation and default review cadence.

Is this for stage-1 or stage-2?

Both. Stage-1 is documentation review; stage-2 is evidence sampling. Dazr keeps the SoA, the risk register, the incident register, control evidence and the activity log in one place for both.

Can I keep my Statement of Applicability in Dazr?

Yes. Mark each control applicable or not with a justification and implementation status, approve a version and export it as PDF or XLSX; excluded controls drop out of your control list. You can also keep linking an existing SoA document.

Will my external auditor accept evidence kept here?

Dazr gives auditors what they typically ask for: a timestamped activity log with the responsible person, evidence on each control, time-limited read-only auditor access and exports. Whether that evidence is sufficient is always the auditor's call.

Which ISO 27001 software is suitable for SMEs in the Netherlands?

Look for four things: the full ISO 27001:2022 control set with a Statement of Applicability, a Dutch-language interface for the people who do the work, EU data storage, and a price that does not need a procurement project. Dazr Compliance covers all four: the control library (all 93 Annex A controls plus clauses 4-10) is in the free plan, the Statement of Applicability and the risk register come with Basic at €29 a month, Pro at €99 a month adds auditor access and up to five users, the portal is in Dutch, English and Italian, and data stays in the EU. If you need ESG or CSRD reporting, on-premise hosting as standard or a vendor-led implementation project, an enterprise GRC suite may suit you better.

Ready to start your ISO 27001 program?

Free for one user and one framework (ISO 27001, GDPR or NIS2). Basic €29/mo covers two of those for one user; Pro €99/mo covers five frameworks (from ISO 27001, GDPR, NIS2, NEN 7510, ISO 27701, ISO 22301 and SOC 2) for up to five users; Enterprise €499/mo adds all eleven. Self-serve via Mollie, prices excl. VAT. Custom is the only tier on a contract, priced on request.