ISO 27001, finished by agents.

All 93 Annex A controls of the 2022 standard, seeded across the four themes, with the eight required policies drafted and the evidence behind them collected on a schedule.

93

controls

4

control themes

93

cross-mappings

8

policies

Your SOC 2 work already counts here.

ISO 27001 carries 93 cross-mappings into the other eleven frameworks. Fifteen land on SOC 2, fifteen on Thailand PDPA, fifteen on ISO 9001. Where a control overlaps, the evidence transfers with it and the residual gap is spelled out, so the second certification is not a second collection.

The policies, already drafted.

The policy writer drafts each document against the systems you connected, a second agent reviews it, and you approve. ISO 27001 needs 8.

  • Information Security Policy

    The top-level policy establishing security direction and management commitment.

  • Access Control Policy

    Controls for user access management, authentication and system access.

  • Asset Management Policy

    Defines inventory, classification and handling of organizational assets.

  • Cryptographic Controls Policy

    Specifies encryption standards, key management and cryptographic controls.

  • Incident Response Policy

    Procedures for managing and responding to information security incidents.

  • Business Continuity Policy

    Ensures information security continuity and redundancy.

  • Supplier Relationships Policy

    Controls for managing information security across supplier relationships.

  • Human Resources Security Policy

    Security requirements for hiring, employment and termination.

Before you start.

Which version of the standard?
ISO/IEC 27001:2022. All 93 Annex A controls are seeded across the organizational, people, physical and technological themes.
We already have SOC 2. How much of this is done?
Fifteen ISO 27001 controls map directly onto SOC 2 controls you already run. Zero2Do shows the mapping, moves the evidence across and lists what each pairing still leaves open.
Do we still need a certification body?
Yes. Zero2Do prepares the Statement of Applicability inputs, the policies and the control evidence; an accredited body runs the stage 1 and stage 2 audits and issues the certificate.

From zero to audit-ready in 30 days

Connect your systems and the ISO 27001 controls start filling in on the first heartbeat.

  1. 01

    Connect

    Point Zero2Do at your cloud, code hosting and identity provider. Nothing to install.

  2. 02

    Agents run

    On a schedule, from day one: evidence gets collected against every control in scope, policies get drafted and tests get run.

  3. 03

    Approve

    You review what the agents produced and answer the few questions only you can answer.