Product · ISO 27001

One ISMS that travels — structured from day one.

What European and APAC enterprises ask for when they want a single standard that carries across jurisdictions. Veylan drafts your Statement of Applicability, structures the risk register, and maps every Annex A control to what your cloud actually does.

  • Annex A controls mapped to your configuration
  • Statement of Applicability with justifications
  • Risk register you can actually maintain
  • Shared controls reused across your other frameworks

What you get

What this looks like in your workspace

Concrete surfaces, not a feature list — each one is something you can open, review, and hand to an auditor or a buyer.

Statement of Applicability (SoA)

Auto-drafted from your stack and scope. Justifications baked in for inclusions and exclusions.

Risk register

Likelihood × impact scoring, treatment plans, owner assignment. Re-assessed continuously, not annually.

Annex A control mapping

All 93 controls in the 2022 revision. Mapped to what your AWS/GCP/Azure actually does — not a wishlist.

Management review cycle

Quarterly review packs generated automatically. Bring them to your management meeting; we keep the receipts.

Internal audit module

Schedule, scope, evidence collection, finding tracking. Your internal audit, automated.

Stage 1 + Stage 2 audit prep

Auditor portal with read-only access, evidence index, and a chase-down workflow for outstanding requests.

Questions

Common questions

One ISMS. Every market.

Free to start · No credit card · Readiness preparation, not certification

ISO 27001 — One framework that travels · Veylan