ISO/IEC 27001:2022 · Early access

Prove your ISO 27001 controls — continuously, not once a year.

Certification is a three-year cycle, not a single audit. ZTZK keeps your controls proven between visits, so each audit reviews a signed record instead of a fresh scramble.

The basics

ISO 27001, explained.

For teams selling into Europe and global enterprises.

What it is

ISO/IEC 27001 is the international standard for an information security management system (ISMS) — the policies, processes and controls an organization uses to manage security risk. The 2022 edition includes a reference set of controls grouped into four themes.

Who asks for it

It’s the security credential international and European buyers most often ask for. An accredited certification body issues the certificate after a two-stage audit; it lasts three years, with surveillance audits every year.

How ZTZK solves it85

ZTZK turns 85 controls into checkable rules, runs technical checks continuously and records manual controls with the owner’s sign-off — so your ISMS is proven between audits, not rebuilt for each one.

Outcomes

What ZTZK proves for ISO 27001.

Proven between audits

Checks run continuously, so the evidence trail is already in place when each surveillance visit comes around.

Automated where it can be

Technical controls are checked in code and infrastructure. Organizational and people controls — policies, training, supplier reviews — are captured with human sign-off and signed like everything else.

Traceable to your SoA

Evidence maps to the controls in your Statement of Applicability, so an auditor can follow the thread from declaration to proof.

Scope

All four control themes

The 2022 edition groups its controls into four themes. ZTZK covers each — some checked automatically, some recorded with human sign-off.

Organizational
Policies, roles, supplier relationships, incident management and business continuity.
People
Screening, awareness and training, and responsibilities during and after employment.
Physical
Secure areas, equipment and storage media.
Technological
Access, cryptography, logging, secure development, configuration and network security.

How it runs

ISO 27001, step by step.

  1. Step 01

    Scope the ISMS

    Map your applicable controls to the systems, teams and documents that satisfy them.

  2. Step 02

    Keep it running

    Technical checks run continuously; manual controls prompt their owner and record the sign-off.

  3. Step 03

    Audit from the record

    Certification and surveillance auditors verify the signed trail directly.

The certification cycle

Stage 1, stage 2 — then every year after.

Initial certification, annual surveillance audits and recertification all ask the same question: is the ISMS still working? With ZTZK the answer is a continuous, signed record — not evidence rebuilt for each visit.

FAQ

ISO 27001 questions, answered

Does ZTZK replace our certification body?

No. An accredited certification body still audits your ISMS and issues the certificate. ZTZK supplies evidence they can verify independently.

How does ZTZK fit surveillance audits?

Evidence is collected continuously, so the record between audits is already signed and in place. Surveillance visits review an existing trail rather than a fresh collection effort.

Can ZTZK handle organizational controls, or only technical ones?

Both. Technical controls are checked automatically. Organizational, people and physical controls are recorded with the owner’s sign-off, and that record is signed to the same ledger.

Does ISO 27001 evidence carry over to SOC 2 or HIPAA?

Yes. Controls are mapped across frameworks, so evidence gathered for ISO 27001 counts wherever the same control applies.

Request access

Prove your ISO 27001 controls.

We're onboarding a small number of early teams. Tell us about your ISO 27001 program and we'll show you evidence that stands up on its own.

We use your email only to reply to your request. Privacy policy

✓ Request received. We'll be in touch.