Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How does ShipReady Metrics support ISO 27001 evidence?
Last verifiedShipReady Metrics records ISO/IEC 27001-mapped evidence, shows Annex A crosswalk density, and holds policies and risks you already own. It does not certify you. This page is not legal advice, does not determine YOUR obligations, does not start a clock, and does not file.
Product-mapping guide, last verified 10 September 2026. Only shipped behaviour. ISO 27001 is a voluntary standard, not a law. Clauses 4–10 remain yours to run. An IAF-MLA accredited certification body still issues the certificate. Coverage is not a pass.
What this page is, and what it is not
Audience: an evaluator or customer who wants capability versus responsibility stated without marketing fog.
This page is not legal advice and not audit advice. It does not determine YOUR obligations, does not start a clock, and does not file with a certification body. Last verified 10 September 2026.
ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.
Capability compared with responsibility
Each row is shipped behaviour mapped to a clause or control theme — not a promise that the clause is met. Last verified 10 September 2026. Not legal advice.
| SRM surface | What it actually does | Clause/control it relates to | Kind of text |
|---|---|---|---|
| 24-framework library (ISO/IEC 27001) | Lists ISO 27001 among in-product frameworks so you can mark it in-scope. | Scoping input toward Clause 4 — you still write the ISMS scope. | ShipReady Metrics recommendation / shipped behaviour. |
| Annex A crosswalk to about 72 canonical controls | Maps Annex A themes into the product’s control set. Not all 93 controls are claimed as fully modelled. | Annex A (93 controls / four themes) via Clause 6.1.3 SoA thinking. | Shipped behaviour. Coverage, not a pass. |
| Crosswalk-density honesty layer | Shows how thick or thin the mapping is. Thin density stays visible. | Planning / SoA honesty — not a certification score. | Shipped behaviour. Not an auditor's opinion. |
| Evidence collection | Records control-mapped artifacts from connectors and manual rows. | Supports Clause 7.5 documented information and operating records for selected Annex A controls. | Shipped behaviour. Not a binder export. |
| Evidence review / met-verdict overlay | A named human accepts a manual row as met or rejects it as a gap, with a timestamp. | Supports human judgment required around Clauses 9–10 and operating effectiveness. | Shipped behaviour. Not Stage 2. |
| Obligation map | Shows frameworks you marked in-scope. The mark is yours. | Related to Clause 4 context / interested-party pressure — not a legal opinion. | Shipped behaviour. Does not determine YOUR obligations. |
| Policies library | Stores YOUR policies. Does not draft an information security policy for you. | Related to Clause 5 documented policy if you put that file there. | Shipped behaviour. |
| Cyber risk register | Stores YOUR risk records. Does not perform the Clause 6 assessment by itself. | Related to Clause 6 risk assessment and treatment. | Shipped behaviour. |
Legal requirement, regulatory guidance, best practice, or our recommendation
A product surface is not a kind of law. Last verified 10 September 2026. Not legal advice.
| Statement | Which kind of authority | What it does not mean |
|---|---|---|
| ISO/IEC 27001:2022 remains a voluntary certification standard. | Certification standard. | Does not make this product a certification body. |
| Only an IAF-MLA accredited body issues a recognised certificate (ISO/IEC 17021-1, ISO/IEC 27006). | Accreditation arrangement. | Does not let a green dashboard substitute. |
| Keep a named human verdict on manual evidence. | Industry best practice, also how this product behaves. | Does not create a forensic chain of custody. |
| Treat density as coverage, never as a pass. | ShipReady Metrics recommendation. | Does not produce an auditor's opinion. |
| Use the product to assemble artefacts; use the body to certify. | ShipReady Metrics recommendation. | Does not start a clock and does not file. |
What you still own
You still own: ISMS scope, leadership, risk methodology, the SoA (necessary controls, inclusion, Annex A exclusions, implementation status), internal audit, management review, corrective actions, the accredited body relationship, and Stage 1 / Stage 2. A readiness assessment remains best practice, not a mandatory clause, and this product does not replace it. Last verified 10 September 2026. Not legal advice.
Checklist
This is the checklist artifact for an honest evaluation. Last verified 10 September 2026. Not legal advice.
- Have we written “does not issue certificates” on the evaluation scorecard?
- Do we treat crosswalk density as coverage, not a pass?
- Can we name which Clauses 4–10 artefacts still live outside the product?
- Is a named human assigned to evidence review?
- Have we refused to call the product an auditor's opinion or a downloadable evidence binder?
- Is the next step an IAF-MLA accredited body, not another dashboard colour?
What to do now
These steps do not file and do not start a clock.
- Mark ISO 27001 in-scope only if a buyer or programme actually needs it.
- Read the auditor-evidence and controls-explained pages so the SoA stays yours.
- Read how to get certified before you book Stage 1.
- Walk signed-in app → Compliance with a sceptic who will look for over-claims.
- Re-verify ISO and IAF sources; last verified 10 September 2026.
Where this shows up in ShipReady Metrics
Only shipped behaviour is described here. ShipReady Metrics does not issue certificates, does not produce an auditor's opinion, and is not a downloadable evidence binder.
If you already have a session: signed-in app → Compliance is the home of evidence collection, evidence review (met-verdict), the obligation map, the policies library, the cyber risk register, and the ISO 27001 / Annex A crosswalk with density. Human judgment plus an accredited certification body remain required.
Readiness indicators in the product are internal. They are not certification.
Primary sources (last verified 10 September 2026)
ISO/IEC 27001:2022; ISO/IEC 27002:2022 as guidance. Product behaviour is described from shipped Compliance surfaces, not from a future roadmap. Not legal advice.