ISO/IEC 27001 asks for an information security management system: a defined scope, risk assessment and treatment, a Statement of Applicability and proof that it works. Teddy's agents build each part from your real systems, and a compliance engineer takes you through the certification audit.

ISO/IEC 27001:2022 is a management system standard. Clauses 4 to 10 set the requirements for the ISMS. Annex A lists 93 reference controls that you compare your risk treatment against. Here is what each part asks for and where it lives in Teddy.
Determine internal and external issues, interested parties and their requirements, and the boundaries of the ISMS.
Top management demonstrates commitment, establishes the information security policy and assigns roles, responsibilities and authorities.
Assess information security risks, select a treatment for each and set information security objectives, measurable where practicable.
List the necessary controls, justify every inclusion and exclusion against Annex A and state whether each control is implemented.
Organizational, people, physical and technological controls. Those you declare applicable must be implemented, and their operation shown with evidence.
Monitoring and measurement, internal audits and management reviews at planned intervals, corrective action and continual improvement.
Customers ask for the certificate, but ISO 27001 has its own logic. Most teams lose months working out what the clauses mean for their company before they fix anything.
The Certification Agent turns each requirement into a task with an owner and a due date.
Teddy suggests which controls you need and why. You make the final call.
The Evidence Agent collects records from your systems, with date and source.
The SoA lives in an Excel file on version twelve, the policies come from a template pack, and the consultant bills by the hour. You ask ChatGPT for a scope statement, but it knows nothing about your systems. Teddy reads your real setup and builds the SoA, risks and policies from it.
Katrin · CEOThe enterprise deal needs the certificate by Q2. Where are we?
ConsultantInvoice for 38 hours attached. SoA draft follows next week.
Jonas · EngineeringWhich of the 93 controls do we actually need?
AuditorPlease send the Statement of Applicability before Stage 1.
Mia · OperationsThe template pack says “insert company name” 40 times.
Teddy's agents do the work clause by clause. You make the decisions, and a compliance engineer is there when the auditor arrives.
Teddy asks about your company, locations and systems and drafts the ISMS scope and a plan to the certificate. You adjust it, then approve.
Teddy assesses every Annex A control against what you actually run, builds the risk register and drafts the Statement of Applicability with a justification for each inclusion and exclusion.
No template pack. The Policy Agent drafts each policy from your setup, so what is written matches what your team does.
The Evidence Agent pulls proof from connected tools on a schedule. When the auditor samples records, they are already there.
Controls you already run for SOC 2, TISAX® or NIS2 count for ISO 27001 too. Teddy maps every framework onto one control set and shows only what is new.
Ask in plain language what a clause means for you. Teddy answers from your live ISMS and does the work. For the certification audit, our compliance engineers are at your side.
Ask TeddyWhat does Clause 6 mean for us? Which controls can we exclude, and why? Teddy knows the standard and your setup.
Agents do the workScope, risks, SoA, policies and evidence arrive ready for your approval, each with its source.
Our team backs you upCompliance engineers help you choose a certification body and join you through Stage 1 and Stage 2.
No. An accredited certification body audits your ISMS and issues the certificate. Teddy builds and runs your ISMS and measures your evidence. We help you find a certification body, and a compliance engineer goes through the audit with you.
Stage 1 reviews your documented information, such as scope, policy, risk assessment and the Statement of Applicability, and checks whether you are ready for Stage 2. Stage 2 evaluates whether the ISMS, including the applicable controls, is implemented and effective.
A lot. Teddy maps both frameworks onto one control set, so evidence collected once counts for both. The gap audit shows what ISO 27001 adds, such as the Statement of Applicability, internal audit and management review.
The certificate is valid for three years. Surveillance audits take place at least once a year, and a recertification audit before expiry renews it. Teddy keeps running gap audits and collecting evidence, so each audit is routine, not a project.
Start with a gap audit against Annex A on your own systems.
Reviewed by Sven Moritz, former CISO · October 2026
From kickoff to certificate. Most of the time goes into documentation and closing gaps.
Ready for Stage 1. Scope and plan in the first session, SoA and risk register from your real systems, evidence collected from day one.
Auditors check whether it changed when the business did: a new cloud provider, a new office, a new product. Risk assessment and treatment are among the clauses with the most nonconformities.
Both are required before Stage 2. Auditors want real findings and real decisions, not a signed template.
Auditors ask an engineer how access is granted and compare it with the written procedure. Not following your own procedures is a classic nonconformity, and template policies make it more likely.