ISO/IEC 27001:2022 · Early access
Prove your ISO 27001 controls — continuously, not once a year.
Certification is a three-year cycle, not a single audit. ZTZK keeps your controls proven between visits, so each audit reviews a signed record instead of a fresh scramble.
The basics
ISO 27001, explained.
For teams selling into Europe and global enterprises.
ISO/IEC 27001 is the international standard for an information security management system (ISMS) — the policies, processes and controls an organization uses to manage security risk. The 2022 edition includes a reference set of controls grouped into four themes.
It’s the security credential international and European buyers most often ask for. An accredited certification body issues the certificate after a two-stage audit; it lasts three years, with surveillance audits every year.
ZTZK turns 85 controls into checkable rules, runs technical checks continuously and records manual controls with the owner’s sign-off — so your ISMS is proven between audits, not rebuilt for each one.
Outcomes
What ZTZK proves for ISO 27001.
Proven between audits
Checks run continuously, so the evidence trail is already in place when each surveillance visit comes around.
Automated where it can be
Technical controls are checked in code and infrastructure. Organizational and people controls — policies, training, supplier reviews — are captured with human sign-off and signed like everything else.
Traceable to your SoA
Evidence maps to the controls in your Statement of Applicability, so an auditor can follow the thread from declaration to proof.
Scope
All four control themes
The 2022 edition groups its controls into four themes. ZTZK covers each — some checked automatically, some recorded with human sign-off.
- Organizational
- Policies, roles, supplier relationships, incident management and business continuity.
- People
- Screening, awareness and training, and responsibilities during and after employment.
- Physical
- Secure areas, equipment and storage media.
- Technological
- Access, cryptography, logging, secure development, configuration and network security.
How it runs
ISO 27001, step by step.
- Step 01
Scope the ISMS
Map your applicable controls to the systems, teams and documents that satisfy them.
- Step 02
Keep it running
Technical checks run continuously; manual controls prompt their owner and record the sign-off.
- Step 03
Audit from the record
Certification and surveillance auditors verify the signed trail directly.
The certification cycle
Stage 1, stage 2 — then every year after.
Initial certification, annual surveillance audits and recertification all ask the same question: is the ISMS still working? With ZTZK the answer is a continuous, signed record — not evidence rebuilt for each visit.
FAQ
ISO 27001 questions, answered
Does ZTZK replace our certification body?
No. An accredited certification body still audits your ISMS and issues the certificate. ZTZK supplies evidence they can verify independently.
How does ZTZK fit surveillance audits?
Evidence is collected continuously, so the record between audits is already signed and in place. Surveillance visits review an existing trail rather than a fresh collection effort.
Can ZTZK handle organizational controls, or only technical ones?
Both. Technical controls are checked automatically. Organizational, people and physical controls are recorded with the owner’s sign-off, and that record is signed to the same ledger.
Does ISO 27001 evidence carry over to SOC 2 or HIPAA?
Yes. Controls are mapped across frameworks, so evidence gathered for ISO 27001 counts wherever the same control applies.
Request access
Prove your ISO 27001 controls.
We're onboarding a small number of early teams. Tell us about your ISO 27001 program and we'll show you evidence that stands up on its own.
We use your email only to reply to your request. Privacy policy
✓ Request received. We'll be in touch.