Skip to content
ASIRI

Frameworks · ISO/IEC 27001:2022

You have already done
most of ISO 27001.

In the worked example below, twenty-four of forty-two requirements are already sitting in the registers filled for the Act. Asiri maps them across, shows you the eighteen that are left, and refuses to let you overstate the rest.

ISO
27001
Certified
A.5.15 Access controlA.5.19 Two suppliers unpaperedA.8.24 CryptographyA.5.7 Threat intelligence · not started

Forty-two requirements, one bar each

24 met

Thirteen partial, five untouched. No score, no letter grade — the state of each requirement is the only summary that survives an auditor reading it. These are one worked example's figures: not a reading of your workspace, and not a count of the standard's own clauses.

Met · 24Partial · 13Not started · 5

Watch it map

Every requirement lands on a record you can open

Not a policy that says it should be true — the read itself, dated, with the system it came from. This is the run happening now, one requirement at a time.

Run complete · 42 of 42 requirements read in this example

01

A.5.15 Access control

Met

Read from your identity provider at 06:04 — the same read that answered the Act on organisational measures.

02

A.5.19 Supplier relationships

Partial

Seven of nine suppliers papered. The two without a DPA fail here for exactly the reason they fail the Act.

03

A.5.24 Incident management

Met

Your incident register, including both events this year and the minute each notification went out.

04

A.8.24 Use of cryptography

Met

Read from your infrastructure, not from a policy document asserting it should be true.

05

A.5.7 Threat intelligence

Not started

No record exists. Asiri says so rather than mapping it to something adjacent and calling it covered.

Scope is the whole story

A certificate is only as wide as the page behind it

The statement of applicability says which of the 93 controls were excluded, and why. That is where a serious reviewer looks — so Asiri publishes it beside the certificate instead of behind it, exclusions and all.

Upload the certificate and Asiri reads the registrar, the number and the surveillance date, then holds you to them. Miss a surveillance audit and the badge stops saying current.

Certificate · as read, not as typed

Registrar

BSI Group

Certificate no.

IS 742119

Issued

18 Sep 2024

Next surveillance

12 Sep 2026

Scope

Platform and operations

Controls excluded

2 of 93

Excluded · 2 of 93

A.8.23 web filtering and A.7.4 physical monitoring, both stated in the SoA. A reviewer who discovers an exclusion later stops believing the rest of the page.

What it buys you elsewhere

The same work, counted once

No percentage is printed here. An overlap figure is a decision, taken per requirement pair, about what counts as the same requirement said twice — and nobody has taken it, so there is nothing to publish a number from. Each card says in words what the overlap covers and what it does not cover.

ISO 27701

Certificate · extension

The privacy extension, which cannot be held without 27001 underneath it. Most of its requirements are the Act’s in different words.

NDPA 2023

Audit return · the law

Overlaps on protection, never on rights. Lawful basis and data subject rights are the Act’s alone — 27001 does not mention either.

SOC 2 Type II

Attestation · not a certificate

A CPA firm reports on a period rather than a moment. The work is largely the same; the output is not a certificate.

The wording rule

Four claims we will not print for you

A badge takes its wording from the assurance behind it. Where the assurance is thinner than the claim, Asiri writes the thinner sentence — even when you would rather it didn't.

Refused

NIST CSF certified

Nothing certifies against NIST CSF. It is a framework, not a certifiable standard, so no body exists to issue one.

Offered instead: Aligned to NIST CSF, self-declared

Refused

SOC 2 certified

SOC 2 is an attestation. The report is confidential, covers a period, and its logo window closes twelve months from the report date.

Offered instead: SOC 2 Type II report, available under NDA

Refused

GDPR certified

There is no GDPR certificate. Any badge claiming one is a self-assessment wearing a certificate’s clothes.

Offered instead: GDPR self-assessment, dated

Allowed

ISO 27001 certified

A registrar examined it and issued a certificate. Number, scope and expiry are shown, and all three can be checked with BSI.

Printed as: ISO/IEC 27001:2022 certified · IS 742119

What comes with it

Request a walkthrough

Scope

Statement of applicability

Which of the 93 controls apply, which are excluded and why — generated from the control records rather than typed up separately.

Evidence

Provenance on every item

Each control says whether it was read from a system, attested by a person, or evidenced by a document. A screenshot is never shown as a system read.

Cycle

Surveillance calendar

Annual surveillance and three-year recertification are dated and clocked. A lapsed surveillance stops the badge showing as current.

Gaps

Non-conformities with owners

Every gap carries a named owner and a date. Nobody signs off their own remediation.

Suppliers

A.5.19 against your real vendor list

The same supplier register the Act uses. A missing DPA fails both frameworks once, in one place.

Buyers

Certificate on your trust page

Publish the certificate, the SoA and the exclusions at three access levels — open, under NDA, or on request.

Find out how much of it you have already done

Connect one system. Asiri returns what you can already prove, what is half-done and what nobody has started — your figures, read on the day, not the example above.