Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How does ShipReady Metrics support ISO 27001 evidence?

Last verified

ShipReady Metrics records ISO/IEC 27001-mapped evidence, shows Annex A crosswalk density, and holds policies and risks you already own. It does not certify you. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.

Product-mapping guide, last verified 10 September 2026. Only shipped behaviour. ISO 27001 is a voluntary standard, not a law. Clauses 4–10 remain yours to run. An IAF-MLA accredited certification body still issues the certificate. Coverage is not a pass.

What this page is, and what it is not

Audience: an evaluator or customer who wants capability versus responsibility stated without marketing fog.

This page is not legal advice and not audit advice. It does not determine YOUR obligations, does not start a clock, and does not file with a certification body. Last verified 10 September 2026.

ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.

Capability compared with responsibility

Each row is shipped behaviour mapped to a clause or control theme — not a promise that the clause is met. Last verified 10 September 2026. Not legal advice.

ShipReady Metrics surfaces vs ISO 27001 (coverage, not a pass; not legal advice; last verified 10 September 2026)
SRM surfaceWhat it actually doesClause/control it relates toKind of text
24-framework library (ISO/IEC 27001)Lists ISO 27001 among in-product frameworks so you can mark it in-scope.Scoping input toward Clause 4 — you still write the ISMS scope.ShipReady Metrics recommendation / shipped behaviour.
Annex A crosswalk to about 72 canonical controlsMaps Annex A themes into the product’s control set. Not all 93 controls are claimed as fully modelled.Annex A (93 controls / four themes) via Clause 6.1.3 SoA thinking.Shipped behaviour. Coverage, not a pass.
Crosswalk-density honesty layerShows how thick or thin the mapping is. Thin density stays visible.Planning / SoA honesty — not a certification score.Shipped behaviour. Not an auditor's opinion.
Evidence collectionRecords control-mapped artifacts from connectors and manual rows.Supports Clause 7.5 documented information and operating records for selected Annex A controls.Shipped behaviour. Not a binder export.
Evidence review / met-verdict overlayA named human accepts a manual row as met or rejects it as a gap, with a timestamp.Supports human judgment required around Clauses 9–10 and operating effectiveness.Shipped behaviour. Not Stage 2.
Obligation mapShows frameworks you marked in-scope. The mark is yours.Related to Clause 4 context / interested-party pressure — not a legal opinion.Shipped behaviour. Does not determine YOUR obligations.
Policies libraryStores YOUR policies. Does not draft an information security policy for you.Related to Clause 5 documented policy if you put that file there.Shipped behaviour.
Cyber risk registerStores YOUR risk records. Does not perform the Clause 6 assessment by itself.Related to Clause 6 risk assessment and treatment.Shipped behaviour.

What you still own

You still own: ISMS scope, leadership, risk methodology, the SoA (necessary controls, inclusion, Annex A exclusions, implementation status), internal audit, management review, corrective actions, the accredited body relationship, and Stage 1 / Stage 2. A readiness assessment remains best practice, not a mandatory clause, and this product does not replace it. Last verified 10 September 2026. Not legal advice.

Checklist

This is the checklist artifact for an honest evaluation. Last verified 10 September 2026. Not legal advice.

  • Have we written “does not issue certificates” on the evaluation scorecard?
  • Do we treat crosswalk density as coverage, not a pass?
  • Can we name which Clauses 4–10 artefacts still live outside the product?
  • Is a named human assigned to evidence review?
  • Have we refused to call the product an auditor's opinion or a downloadable evidence binder?
  • Is the next step an IAF-MLA accredited body, not another dashboard colour?

What to do now

These steps do not file and do not start a clock.

  • Mark ISO 27001 in-scope only if a buyer or programme actually needs it.
  • Read the auditor-evidence and controls-explained pages so the SoA stays yours.
  • Read how to get certified before you book Stage 1.
  • Walk signed-in app → Compliance with a sceptic who will look for over-claims.
  • Re-verify ISO and IAF sources; last verified 10 September 2026.

Where this shows up in ShipReady Metrics

Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.

If you already have a session: signed-in app → Compliance is the home of evidence collection, evidence review (met-verdict), the obligation map, the policies library, the cyber risk register, and the ISO 27001 / Annex A crosswalk with density. Human judgment plus an accredited certification body remain required.

Readiness indicators in the product are internal. They are not certification.

Primary sources (last verified 10 September 2026)

ISO/IEC 27001:2022; ISO/IEC 27002:2022 as guidance. Product behaviour is described from shipped Compliance surfaces, not from a future roadmap. Not legal advice.

Frequently asked questions