ISO 27001:2022, without the eighteen-month slog
Run a real ISO 27001:2022 control test: GRXForce's AI Evidence Agent discovers and reviews the evidence and drafts the workpaper for all 93 Annex A controls, through Stage 1, Stage 2 and every surveillance audit after.
What is ISO 27001:2022?
ISO 27001:2022 defines the requirements for an Information Security Management System (ISMS). The 2022 revision restructured Annex A into 93 controls across four themes, organizational, people, physical, and technological, and certification runs on a three-year cycle: a Stage 1 documentation review, a Stage 2 certification audit, then annual surveillance audits.
What it takes, at a glance
- A scoped ISMS with a Statement of Applicability covering all 93 Annex A controls
- Risk assessment and risk treatment methodology with documented decisions
- Mandatory documents: security policy, asset inventory, incident procedures, and more
- Internal audit and management review before your certification body arrives
- Evidence that controls operate over time, not just that they exist on paper
Your readiness checklist
- Define ISMS scope and get leadership sign-off
- Run a risk assessment and build the risk treatment plan
- Write the Statement of Applicability against all 93 Annex A controls
- Publish mandatory policies and assign control owners
- Collect operating evidence for at least one full cycle before Stage 2
- Complete an internal audit and management review
- Book Stage 1 and Stage 2 audits with an accredited certification body
How the timeline actually breaks down
Where most programs actually stand
A proper ISO 27001 gap assessment scores every one of the 93 Annex A controls against your current state, not just the ones that are easy to answer. GRXForce's readiness score gives you that view in minutes, not weeks.
Check My ISO 27001 ReadinessWhat auditors actually expect to see
- Access review logs showing quarterly re-certification, not a one-time export
- Change management tickets linked to the approvals that authorized them
- Vulnerability scan results with remediation timestamps, not just the scan itself
- Signed acknowledgment of the security policy from every employee, current year
- Vendor due-diligence records for any supplier that touches in-scope data
Where programs like yours lose time
- Treating the Statement of Applicability as a one-time document instead of a living map to real controls
- Writing policies that describe an aspirational process nobody actually follows
- Starting evidence collection the month before Stage 2 instead of from day one
- Scoping the ISMS too broadly, which multiplies the audit's cost and duration for no benefit
- Treating certification as a finish line instead of the start of the surveillance cycle
How ISO 27001:2022 compares
| Framework | Type | Typical timeline | Renewal | Best for |
|---|---|---|---|---|
| ISO 27001:2022 | Certification | 6-12 months typical | 3-year cycle + annual surveillance | Any company selling globally, especially outside the US |
| SOC 2 Type II | Attestation (CPA report) | 3-12 month observation window | Annual Type II report | SaaS companies selling to US enterprise customers |
| GDPR | Regulation | Ongoing, no certificate | Continuous | Anyone processing EU residents' personal data |
| DPDPA 2023 | Regulation | Ongoing, no certificate | Continuous | Anyone processing Indian residents' digital personal data |
| HITRUST CSF | Certification | 6-18 months by tier | 1-2 year cycle by tier | Healthcare and health-tech handling PHI |
| NIST CSF | Voluntary framework | Ongoing, self-assessed | Continuous | US federal contractors and critical infrastructure |
| PCI DSS | Industry mandate | 3-6 months typical | Annual (ROC or SAQ) | Anyone storing, processing or transmitting card data |
| SOX ITGC | Regulatory (internal controls) | Ongoing, tested annually | Annual audit cycle | US public companies and their auditors |
| HIPAA | Regulation | Ongoing, no certificate | Continuous | US healthcare providers, payers and business associates |
Run it yourself, or hand us the programme
See exactly how GRXForce runs an ISO 27001:2022 control test: the AI Evidence Agent discovers and reviews the evidence and drafts the workpaper, you make the final call.
See It Run in the Audit Engine →Frequently asked
How long does ISO 27001:2022 certification take?
It depends on your starting maturity and scope. With controls mapped from day one and evidence collection automated, most of the calendar time goes to controls operating long enough to generate evidence, GRXForce compresses everything around that.
What changed from ISO 27001:2013 to 2022?
Annex A was restructured from 114 controls in 14 domains to 93 controls in 4 themes, with 11 new controls covering areas like threat intelligence, cloud security, and data leakage prevention. Transition deadlines for existing certificates have now passed, so new audits run against 2022.
Do I need a consultant or can the platform alone get me certified?
Either path works, that's the point of GRXForce. Teams with compliance staff run the platform themselves; teams without hand the whole program to our managed service, including auditor liaison.
Also covered: SOC 2 Type II GDPR DPDPA 2023 HITRUST CSF NIST CSF PCI DSS SOX ITGC HIPAA
Find My Gaps
3 minutes. No sales pitch. Get a preliminary ISO 27001:2022 readiness score.