Quick answer
OptiTech implements the ISMS machinery ISO 27001:2022 requires: a living risk register linked to controls, a statement of applicability generated from your control mappings, versioned policies with review cycles and sign-off, and continuous evidence against the Annex A controls. The certification audit then runs against a program that demonstrably operates, with an auditor portal for sampling.
Covering the clauses, not just Annex A
Certification audits fail on the management clauses more often than on technical controls. OptiTech maps both:
- Risk assessment and treatment (clauses 6 and 8): the risk register scores likelihood and impact, links risks to treating controls, and keeps assessment history so you can show the process operating over time.
- Statement of applicability: generated from your control set with inclusion and exclusion justifications, updated automatically when controls change.
- Documented information (clause 7.5): policies live under version control with approvals, and employee acknowledgments are tracked.
- Performance evaluation (clause 9): dashboards and board reports give management review its required input, and internal audit findings track like any other finding.
- Improvement (clause 10): nonconformities route as findings with owners and verified fixes.
Annex A on automation
The technological controls verify continuously through integrations: access control, MFA, logging, backup, secure development settings in GitHub, and endpoint state from your MDM. Evidence lands timestamped in the append-only log, so surveillance audits sample a year of operation instead of a week of preparation.
The 2013-to-2022 transition and beyond
Framework versioning is handled in the platform: when the standard revises, the delta arrives as a managed migration with your existing controls re-mapped. And once ISO 27001 is live, adjacent certifications (ISO 27017 for cloud, ISO 27018 and ISO 27701 for privacy) activate as extensions of the same control set, not new programs.

Get a personalized walkthrough of automated compliance for your team. No commitment required.