Frameworks · ISO/IEC 27001:2022
You have already done
most of ISO 27001.
In the worked example below, twenty-four of forty-two requirements are already sitting in the registers filled for the Act. Asiri maps them across, shows you the eighteen that are left, and refuses to let you overstate the rest.
27001Certified
Forty-two requirements, one bar each
24 met
Thirteen partial, five untouched. No score, no letter grade — the state of each requirement is the only summary that survives an auditor reading it. These are one worked example's figures: not a reading of your workspace, and not a count of the standard's own clauses.
Watch it map
Every requirement lands on a record you can open
Not a policy that says it should be true — the read itself, dated, with the system it came from. This is the run happening now, one requirement at a time.
Run complete · 42 of 42 requirements read in this example
A.5.15 Access control
MetRead from your identity provider at 06:04 — the same read that answered the Act on organisational measures.
A.5.19 Supplier relationships
PartialSeven of nine suppliers papered. The two without a DPA fail here for exactly the reason they fail the Act.
A.5.24 Incident management
MetYour incident register, including both events this year and the minute each notification went out.
A.8.24 Use of cryptography
MetRead from your infrastructure, not from a policy document asserting it should be true.
A.5.7 Threat intelligence
Not startedNo record exists. Asiri says so rather than mapping it to something adjacent and calling it covered.
Scope is the whole story
A certificate is only as wide as the page behind it
The statement of applicability says which of the 93 controls were excluded, and why. That is where a serious reviewer looks — so Asiri publishes it beside the certificate instead of behind it, exclusions and all.
Upload the certificate and Asiri reads the registrar, the number and the surveillance date, then holds you to them. Miss a surveillance audit and the badge stops saying current.
Certificate · as read, not as typed
Registrar
BSI Group
Certificate no.
IS 742119
Issued
18 Sep 2024
Next surveillance
12 Sep 2026
Scope
Platform and operations
Controls excluded
2 of 93
Excluded · 2 of 93
A.8.23 web filtering and A.7.4 physical monitoring, both stated in the SoA. A reviewer who discovers an exclusion later stops believing the rest of the page.
What it buys you elsewhere
The same work, counted once
No percentage is printed here. An overlap figure is a decision, taken per requirement pair, about what counts as the same requirement said twice — and nobody has taken it, so there is nothing to publish a number from. Each card says in words what the overlap covers and what it does not cover.
ISO 27701
Certificate · extension
The privacy extension, which cannot be held without 27001 underneath it. Most of its requirements are the Act’s in different words.
NDPA 2023
Audit return · the law
Overlaps on protection, never on rights. Lawful basis and data subject rights are the Act’s alone — 27001 does not mention either.
SOC 2 Type II
Attestation · not a certificate
A CPA firm reports on a period rather than a moment. The work is largely the same; the output is not a certificate.
The wording rule
Four claims we will not print for you
A badge takes its wording from the assurance behind it. Where the assurance is thinner than the claim, Asiri writes the thinner sentence — even when you would rather it didn't.
Refused
NIST CSF certified
Nothing certifies against NIST CSF. It is a framework, not a certifiable standard, so no body exists to issue one.
Offered instead: Aligned to NIST CSF, self-declared
Refused
SOC 2 certified
SOC 2 is an attestation. The report is confidential, covers a period, and its logo window closes twelve months from the report date.
Offered instead: SOC 2 Type II report, available under NDA
Refused
GDPR certified
There is no GDPR certificate. Any badge claiming one is a self-assessment wearing a certificate’s clothes.
Offered instead: GDPR self-assessment, dated
Allowed
ISO 27001 certified
A registrar examined it and issued a certificate. Number, scope and expiry are shown, and all three can be checked with BSI.
Printed as: ISO/IEC 27001:2022 certified · IS 742119
What comes with it
Request a walkthroughScope
Statement of applicability
Which of the 93 controls apply, which are excluded and why — generated from the control records rather than typed up separately.
Evidence
Provenance on every item
Each control says whether it was read from a system, attested by a person, or evidenced by a document. A screenshot is never shown as a system read.
Cycle
Surveillance calendar
Annual surveillance and three-year recertification are dated and clocked. A lapsed surveillance stops the badge showing as current.
Gaps
Non-conformities with owners
Every gap carries a named owner and a date. Nobody signs off their own remediation.
Suppliers
A.5.19 against your real vendor list
The same supplier register the Act uses. A missing DPA fails both frameworks once, in one place.
Buyers
Certificate on your trust page
Publish the certificate, the SoA and the exclusions at three access levels — open, under NDA, or on request.
Find out how much of it you have already done
Connect one system. Asiri returns what you can already prove, what is half-done and what nobody has started — your figures, read on the day, not the example above.