Home/ Frameworks/ ISO 27001
Framework · ISO 27001:2022

ISO 27001 certification without the six-month implementation project.

ISO 27001:2022 is the international gold standard for information security management systems. The 2022 revision updated Annex A with 11 new controls and significant restructuring. Sentrix maintains up-to-date mappings for the 2022 revision and identifies your gap in minutes — not weeks.

93
controls in ISO 27001:2022 Annex A — all mapped to technical evidence in Sentrix
45 days
median time to close ISO 27001 gaps after Sentrix initial gap assessment
2022
revision of ISO 27001 standard with 11 new Annex A controls — Sentrix is automatically up to date
70%+
of SOC 2 controls match ISO 27001 requirements — get both certifications from one evidence program
What ISO 27001:2022 requires

ISMS. Risk assessment. Annex A. Certification audit. All covered.

ISO 27001 requires a documented management system, formal risk assessment, application of Annex A controls, and an internal audit program. The certification body will perform a two-stage certification audit (Stage 1 and Stage 2) and annual surveillance audits. Sentrix automates evidence collection, maintains the Statement of Applicability, and tracks nonconformities.

  • Clauses 4–6: context, leadership, planning — ISMS policy and risk assessment
  • Clause 7: support — documented competence, awareness, and communication
  • Clause 8: operation — risk treatment plans and operational controls
  • Clause 9: performance evaluation — internal audits, management review
  • Clause 10: improvement — nonconformities, corrective actions
  • Annex A: 93 baseline controls — evidence collected automatically for each

ISO 27001:2022 · Annex A coverage

LIVE TRACKING
A.5 Information security policies100%
A.6 Organisation of information security95%
A.8 Technological asset management▲ 87 / 93
A.9 Access control100%
A.12 Operations security92%
⚠ A.8.8: vulnerability management — 6 controls pending evidence
Full ISO 27001 capabilities

From initial gap assessment to certification — in one program.

ISO 27001:2022 gap assessment

Connect your integrations and Sentrix instantly identifies which Annex A controls are satisfied, which have partial gaps, and which need new evidence. Most organizations discover 60–70% coverage before any new work.

Statement of Applicability (SoA)

Sentrix generates and maintains your SoA automatically. As evidence arrives, the SoA updates. Your certification body gets a current document that reflects your real posture — not a six-month-old snapshot.

Nonconformity management

Track Stage 1, Stage 2, and surveillance audit nonconformities with assigned deadlines, owners, and evidence attachments. Close findings before they affect your certification status.

Risk treatment plan integration

The ISO 27001 risk treatment plan integrates directly with your Sentrix risk register. Identified risks automatically generate corresponding controls in your program.

SOC 2 and NIST crosswalk

ISO 27001 shares 70%+ of its controls with SOC 2 and NIST CSF. Sentrix automatically maps existing evidence across all active frameworks — add ISO 27001 without restarting your evidence program.

Certification body workspace

Give your certification body (BSI, Bureau Veritas, SGS, etc.) direct read-only access to Annex A-organized evidence. Reduce fieldwork time and review cycles.

Need hands-on support with your certification? See our ISO 27001 certification support service

See how many ISO 27001:2022 controls you already satisfy.

We run the gap assessment live during the demo on your real infrastructure.

ISO 27001:2022 Compliance Automation for Canadian Organizations

Sentrix accelerates ISO 27001:2022 certification for Canadian businesses by automating gap analysis, evidence collection, and ISMS documentation — compressing a process that typically takes years into a structured program measured in months.

What ISO 27001:2022 Requires

ISO 27001:2022 is the internationally recognized standard for Information Security Management Systems. The 2022 revision introduced 11 new controls and reorganized the Annex A control set into four themes: organizational controls, people controls, physical controls, and technological controls. For Canadian organizations handling sensitive data, achieving certification demonstrates to regulators, clients, and partners that information security is managed systematically and continuously improved.

The certification process requires organizations to define the scope of their ISMS, conduct a formal risk assessment, select applicable controls, produce a Statement of Applicability, implement and operate the controls, and undergo an accredited external audit. Each of these stages generates documentation and evidence that auditors will scrutinize. Without purpose-built tooling, teams spend most of their time in spreadsheets and shared drives, manually tracking control status and chasing evidence from dozens of stakeholders across the business.

Automated Gap Analysis Against ISO 27001:2022

Sentrix begins every ISO 27001 engagement with a structured gap analysis mapped directly to the 93 Annex A controls and the ten clauses of the standard. The platform presents each control requirement in plain language, allows your team to record the current state of implementation, and automatically calculates a maturity score across all four control themes. The gap report produced at the end of this assessment gives your project team and executive sponsor a clear picture of what work remains before an audit, ranked by criticality and estimated effort.

Because the gap analysis is conducted inside Sentrix rather than on a standalone spreadsheet, the findings feed directly into a remediation project plan. Tasks are assigned to owners with due dates, and progress is tracked in real time. Audit-ready evidence is attached to each control record as work is completed, so there is no separate evidence-gathering sprint before the certification audit.

ISMS Scope Definition and Risk Assessment

Defining the scope of an ISMS is one of the most consequential decisions in an ISO 27001 project. A scope that is too narrow may exclude systems that auditors expect to see; a scope that is too broad creates unnecessary work. Sentrix provides guided templates for ISMS scope statements that align with ISO 27001 Clause 4, helping Canadian organizations document the boundaries of their management system in terms auditors recognize. The platform captures the organizational context, interested parties, and information assets covered by the scope in a structured format that feeds directly into risk assessment workflows.

The Sentrix risk register supports both asset-based and scenario-based risk assessment methodologies. Risk owners record threats, vulnerabilities, likelihood ratings, and impact ratings for each identified risk. The platform calculates residual risk after controls are applied and flags risks that exceed the organization's defined risk appetite, ensuring that treatment decisions are documented and traceable throughout the audit cycle.

Statement of Applicability and Cross-Framework Mapping

Sentrix generates a draft Statement of Applicability — the document that records which Annex A controls apply to your organization, which are excluded, and the justification for each decision — directly from your risk assessment and gap analysis data. The SoA is one of the first documents an ISO 27001 auditor will request, and having it generated automatically from live control data eliminates the version-control problems that arise when it is maintained separately.

For organizations that also hold or are pursuing SOC 2 Type II, PIPEDA compliance, or provincial privacy legislation obligations, Sentrix maps ISO 27001 controls to these overlapping frameworks automatically. A single control implementation and its supporting evidence can satisfy requirements in multiple frameworks simultaneously, reducing the total compliance burden across your GRC program. Canadian organizations operating under the federal PIPEDA regime or Quebec's Law 25 benefit directly from this cross-mapping because many ISO 27001 Annex A controls address the same data protection outcomes those laws require.

Evidence Collection and Audit Readiness

Sentrix connects to the cloud infrastructure, identity providers, and SaaS applications that Canadian organizations already operate, pulling configuration evidence automatically on a scheduled basis. Policy documents, penetration test reports, training completion records, and access review logs are stored against the controls they satisfy, with timestamps and version history that give auditors a clear chain of custody. When your certification audit date arrives, the evidence package is already assembled inside the platform.

Certification in Months, Not Years

Organizations that pursue ISO 27001 certification without dedicated tooling routinely find that the project stretches beyond two years as documentation work accumulates and evidence gathering stalls. Sentrix customers in Canada have reached their Stage 2 certification audit in significantly less time by using the platform's guided workflows, automated evidence collection, and integrated remediation tracking from the first day of the project. The result is a defensible, continuously maintained ISMS rather than a documentation project that lapses between audit cycles.