ISO/IEC 27001:2022

ISO 27001 Compliance Automation

ISO/IEC 27001:2022 is the global standard for information security management. TigerGate automates the technical Annex A controls — access, cryptography, operations, communications, acquisition — so your ISMS has continuous evidence instead of quarterly screenshots.

What Changed in ISO 27001:2022

The 2022 revision condensed Annex A from 114 controls across 14 clauses into 93 controls across 4 themes. The four themes:

  • Organizational (37 controls) — policies, roles, supplier relationships, incident response.
  • People (8 controls) — screening, terms of employment, awareness.
  • Physical (14 controls) — perimeter, equipment, cabling, secure disposal.
  • Technological (34 controls) — authentication, cryptography, logging, secure development.

TigerGate automates the full Technological theme plus parts of Organizational (supplier & threat intelligence) and People (identity management).

Annex A Technological Controls Covered

A.8.1–A.8.3: Device & Identity

User endpoint posture, information access restriction, privileged access management via CIEM.

A.8.9–A.8.13: Configuration & Protection

Configuration management (CSPM across AWS/Azure/GCP), information deletion, data masking, data leakage prevention, backup.

A.8.15–A.8.17: Logging & Monitoring

Centralized logging, monitoring activity, clock synchronization — via eBPF runtime + cloud log validation.

A.8.19–A.8.25: Secure Development

Installation of software on operational systems, networks security, secure development life cycle — SAST, SCA, secrets scanning in CI/CD.

A.8.26–A.8.28: Application Security

Application security requirements, secure system architecture, secure coding — via code security + attack path analysis.

A.8.29–A.8.34: Testing & Change

Security testing in development, outsourced development, separation of environments, change management — covered by TigerGate CI/CD gates.

Stage 1 and Stage 2 Audit Readiness

The ISO 27001 certification process has two stages:

  • Stage 1 (documentation review): the auditor confirms your ISMS documentation exists and is coherent — scope, policies, risk assessment, Statement of Applicability.
  • Stage 2 (certification audit): the auditor samples evidence of operation — proof that controls are actually running.

TigerGate drops directly into Stage 2 as the operational evidence source. Statement of Applicability generation is handled by your GRC platform (Vanta, Drata, Secureframe) with TigerGate feeding the control status.

ISO 27001 and SOC 2 Together

Running both ISO 27001 and SOC 2 is common for international SaaS. The frameworks overlap significantly — most technical controls satisfy both. TigerGate maps a single scan to both framework's controls, and GRC platforms (Vanta, Drata) handle the policy overlap. See SOC 2 compliance.

Transitioning from ISO 27001:2013 to ISO 27001:2022

Transition audits (available until October 2025) remap your existing controls to the 93-control structure. TigerGate's control mappings include both 2013 and 2022 clause references, so historical evidence remains valid during the transition window.

ISO 27001 FAQ

Typically 6-12 months for a first-time certifier: scope definition, risk assessment, ISMS build-out, Stage 1 (3-4 weeks before Stage 2), then Stage 2 certification audit. Recertification every 3 years with annual surveillance.
No — only an accredited certification body (CB) can issue the certificate. TigerGate provides the technical evidence that supports your certification; the CB audits and issues.
SOC 2 is a US attestation (AICPA) focused on service organization controls for customers. ISO 27001 is an international certification focused on an organization's information security management system. Both are commonly carried together for international B2B SaaS.
Yes — TigerGate feeds Vanta and Drata's ISO 27001 control monitoring. One technical scan, mapped automatically to the right Annex A control in your GRC tool.
A.8.29 (security testing in development/acceptance) requires some form of security testing. Automated SAST/DAST + annual pen testing is the common pattern. See how TigerGate's automated scanning combines with external pen testing.

Automate ISO 27001 Today

Free tier. Vanta and Drata integration included. First Annex A evidence report inside the trial.