Skip to content
Framework · ISO 2022

ISO 27001

The international standard for information security management systems. Required for many enterprise deals — especially in Europe and APAC — and a strong signal of mature security operations.

93 Talarity controls mapped
Who it's for: Companies selling internationally, especially in regulated or large-enterprise B2B contexts.
Talarity coverage

Mapped, monitored, and audit-ready.

Every ISO 27001 control has a place in Talarity — with cross-mapping, automated evidence, and continuous validation.

93
Talarity controls mapped

Talarity's pre-built control library covering ISO 27001, with linked evidence, owners, and testing schedules.

Cross-maps to
SOC 2HIPAAGDPRNIST CSF

Answer once, prove everywhere. Talarity's mapping engine reuses your evidence across every framework you run.

Automated evidence
  • ISMS documentation and policy versions
  • Statement of Applicability with control justifications
  • Risk treatment plans and residual risk records
  • Internal audit reports and management reviews
  • Vendor due diligence and supplier risk records

Your ISO 27001 dashboard

Every completed ISO 27001 assessment updates this automatically — where you stand now, how that has changed, and which areas need work.

Click to enlarge
The Talarity dashboard for a completed ISO 27001:2022 assessment: the latest score, the trend across previous assessments, and a breakdown by control area
Common pain points

What gets easier with Talarity.

Pain

ISO 27001 demands a full ISMS — risk register, statement of applicability, internal audits, management reviews — not just controls.

Talarity

Talarity ships every ISMS artifact as a first-class object. Risk register quantifies in dollars; SoA generates from your control selection; internal audits and management reviews track in the platform.

Pain

External auditors ask for traceability: 'Show me how this control connects to this risk and this evidence.'

Talarity

Click any control to see its risk linkages, evidence artifacts, owner, and testing history. One click, full traceability.

Pain

The 2022 update reduced controls from 114 to 93 — but reorganized everything. Migrating from 2013 mappings is painful.

Talarity

Talarity ships the 2013 → 2022 mapping out of the box. Existing controls migrate automatically; you don't redo work.

Pain

Surveillance audits annually plus a full re-cert every 3 years — staying audit-ready year-round is expensive.

Talarity

Continuous monitoring with drift detection. If a control falls out of compliance, you know before the auditor does.

ISO 27001 — common questions

What changed in ISO 27001:2022 compared with the 2013 version?
Annex A was restructured from 114 controls in 14 domains into 93 controls in four themes — Organisational, People, Physical and Technological. Eleven controls are new, including threat intelligence, information security for cloud services, ICT readiness for business continuity, data masking, data leakage prevention, monitoring activities, web filtering and secure coding. Most existing controls were merged rather than removed, so organisations certified against the 2013 version generally remap rather than rebuild.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 certifies a management system: you prove you run an ISMS with defined scope, risk treatment, objectives and continual improvement, and an accredited body issues a certificate. SOC 2 is an attestation report written by a CPA firm describing your controls against the Trust Services Criteria, and the reader forms their own view. ISO is more common outside North America and with international buyers; SOC 2 dominates US enterprise procurement. The underlying controls overlap heavily, so most of the evidence serves both.
What is a Statement of Applicability?
The Statement of Applicability records, for every Annex A control, whether it applies to your ISMS, the justification for including or excluding it, and its implementation status. It is the document auditors work from, and it is mandatory. Because it must stay consistent with your risk treatment plan as controls change, keeping it accurate by hand is where most ISMS drift originates.
How long does ISO 27001 certification take?
Certification is a two-stage external audit. Stage 1 reviews your documentation and ISMS readiness; Stage 2 tests that the system is operating. You need the ISMS running long enough to have produced real records — internal audit, management review, risk treatment decisions — before Stage 2 is meaningful. Surveillance audits then follow annually, with recertification on a three-year cycle, so ISO is an ongoing programme rather than a one-off project.
Do we need to implement all 93 Annex A controls?
No. Annex A is a reference set, not a mandatory checklist. You select controls based on your risk assessment and justify any exclusions in the Statement of Applicability. What auditors test is whether your selection follows logically from your identified risks — an exclusion with a sound justification is acceptable, an unexplained gap is not.

Working with ISO 27001

Step-by-step walkthroughs from the Talarity library.

Ready to ship ISO 27001?

Start a 7-day trial and run this framework end-to-end on your own evidence — then buy online in-app when you're ready.