ISO 27001 fails quietly: an SoA that can't justify its exclusions, a risk register that was clearly written the week before Stage 1, policies nobody operates. This kit is the ISMS documentation we build on advisory engagements, productized — every document structured the way certification auditors expect to see it, plus 90 days with your vCISO Agent for the “what does this clause actually want” moments in between.
Clause 4 done properly: scope statement, interested parties, and internal/external issues — written so a Stage 1 auditor nods instead of opening findings.
All 93 controls in the 2022 structure with inclusion/exclusion justification language. The single document your auditor spends the most time in.
A defensible methodology plus a working register — criteria, scoring, treatment options, and example entries scoped to real SMB environments.
Every document clauses 4–10 require — information security policy, competence, internal audit, corrective action, and the Annex A policies auditors expect to exist.
The two rituals certification lives on: audit program, audit report template, and a management review agenda with the inputs/outputs clause 9.3 demands.
Maps every clause and control to its evidence, plus a Stage 1 / Stage 2 readiness checklist so the audit holds no surprises.
A compliance agent trained on 20 years of CISO practice and on every document in this kit. Ask it how a control applies to your business, what an auditor will sample, or how to word an SoA justification — anytime. $499/mo to keep it after 90 days.
“Not applicable” with no justification is the fastest way to a nonconformity. Our SoA template includes justification language auditors accept — and flags the exclusions they never do.
Auditors can tell a register that runs the ISMS from one created the week before Stage 1. Ours is built to be operated — criteria, owners, treatment, review cadence.
Generic ISMS packs reference committees and roles a 30-person company doesn't have. Our documents are scoped to SMBs and tell you exactly what to edit.
No internal audit, no management review, no certificate. The templates make both a half-day exercise instead of a scramble.
We're shipping the Level 1 Template Pack in the coming weeks. Put your email in and we'll send one message when it's live — with a launch-day discount for early subscribers.
We're finalizing the kit content now. Early subscribers get a single launch notification when it ships. No marketing emails in the meantime.
ISMS scope varies enough by organization size and certification timeline that we price this kit after a short discovery conversation, not off a rate card. Join the waitlist and we'll scope it with you — one-time pricing, 90 days of vCISO Agent access included, and the documents are yours forever.
A compliance agent trained on 20 years of real CISO practice — and on every document in this kit. Ask it what a control means for a company your size, what a certification auditor will sample, or how to justify an exclusion in your SoA. It answers with the clause reference, not vibes — and judgment calls get routed to a human, not improvised.
Yes — ISO/IEC 27001:2022 with the 93-control Annex A structure. If you're transitioning from the 2013 revision, the kit's SoA and policy set map to the new structure, which is most of the transition work.
The kit gets your ISMS documentation to certification-grade and tells you what evidence to produce. You still have to operate the system — run the risk process, hold the management review, do the internal audit — and engage an accredited certification body for Stage 1 and Stage 2. When clients want support through the audit itself, that's our Virtual Security Team or Advisory.
Not under a standard license. If you're a consultancy or MSP wanting to distribute this to multiple companies, contact us for a partner license.