Achieve and maintain ISO 27001 certification

The certificate is won at the audit and kept in the years between. Work the controls with the standard's own numbering, let every piece of evidence carry a named owner, a date and a sign-off, and plan the whole cycle in one pass.

Unlimited users  •  Free onboarding and support  •  No commitment

An upright panel carrying a blank circular badge, with a closed loop of evidence cards running around its base and a stack of kept records beside it
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell
The ISO 27001:2022 framework in .legal, filtered to the A.8 technological controls: each control under its own id from the standard, with its coordinator, its task count, a status of planned, ongoing, completed or overdue, and an evaluation

ISO 27001 certification Meridian's audit stopped being a fortnight of reconstruction

Anders Krogh is CISO at Meridian Nordic, an energy group with entities in Denmark, Sweden and Germany and an ISO 27001 certificate that has to survive an audit every year. Winning the certificate was never the hard part. Proving twelve months later that the controls behind it had actually been performed was, because the evidence sat in mail threads and on a shared drive, and every audit was preceded by two weeks of reconstruction. Now the controls sit under ISO 27001 with the standard's own numbering, each one carrying the tasks that document it, with a named owner and a date. This year Anders prepared by reading a list instead of rebuilding one.

  • The German entity came into scope on the same framework, with its own tasks and its own owners.
  • Every piece of evidence hangs on the task it belongs to, with who closed it and when.
  • Where sign-off matters, only the person responsible can complete the task.
  • The cycle to the next audit is already planned, rather than re-planned each January.

  • Sign-off, not just a tick

    Where it matters, only the person responsible can complete the task. Everyone else can move it as far as ready for approval, and there it waits.

  • A record that outlives people

    Every task keeps its own history of status, documentation and ownership, so the first year still makes sense in the third.

  • The cycle planned once

    Frequencies in weeks, months or years, and no cap on how far ahead a deadline can sit, so nobody re-plans the same year every January.

  • One entity at a time

    A planned activity fans out into a task per group company, each with its own owner and date, so scope grows without a second framework.

An empty lattice of unfilled cells, with evidence cards scattered on separate islands around it and one figure reaching across a gap too wide

ISO 27001 certification The two weeks before the audit

Certification is a project. Keeping it is a habit, and the habit is what slips first. Most of the pain in an audit is not the controls themselves, it is proving that the controls happened.

  • The evidence exists, but it is in somebody's mailbox rather than on the control it belongs to.
  • Nobody can say which recurring checks were performed last quarter without asking four colleagues.
  • The person who did the work in year one has moved on, and the reasoning went with them.
The control A.8.1 User endpoint devices open in .legal, with the same evidence task listed once per group company beneath it, each row carrying its own deadline, its type and the company it belongs to

ISO 27001 certification Bring the next entity into scope

A certificate rarely covers the whole group on day one. When the next entity comes in, the framework is planned per company rather than copied and pasted.

  • One planned activity fans out into a separate task per group company, each with its own responsible person.
  • The same activity can run at different times in different companies, so a rollout does not force one calendar on everyone.
  • The framework above stays one framework, so the group picture and the entity picture are the same data.
An evidence task open beneath a control in .legal, showing its description and practical tips, the panel for uploading documentation or linking a policy, and an activity log switched to history with a dated assignment change on it

ISO 27001 certification Evidence with a name, a date and a sign-off

The question at an audit is rarely whether you have a policy. It is whether the control behind it was performed, by whom, and when.

  • The evidence hangs on the task under the control: the upload, the screenshot, the comment, the completion.
  • A task can be set so only the person responsible may complete it. Everyone else can move it to ready for approval, where it stands in yellow and waits.
  • Each task keeps its own history of subtask completion, status changes, documentation and who it was assigned to.
A rail of blank marker posts running past the edge of the frame, one card travelling along it and a closed loop returning at the near end

ISO 27001 certification Plan the cycle, not just this year

A certificate is kept alive by frequencies. The work that proves a control is not done once, it comes back, and the plan is where that rhythm belongs.

  • Set a recurrence in weeks, months or years, with a start date and an end date the plan respects when it generates tasks.
  • A completed task returns when its frequency expires and comes back into the plan, rather than depending on somebody remembering.
  • Deadlines can sit as far ahead as you need, so the whole cycle to the next audit is laid out in one pass.
An open framework of struts with most of its openings still empty, one figure lifting a panel into place and an empty tray in front

ISO 27001 certification What we build, and what stays yours

Two boundaries, said before the demo rather than after. We build the plan, not the filling-in.

  • You get the plan, the structure and the place the evidence goes. What the documentation says is your work, and .legal is a compliance software vendor rather than a law firm.
  • An information security management system here is the frameworks, the controls beneath them and the documentation against them. The platform records the security work, it does not scan anything, and it is not a SIEM.
  • There is one more boundary, about how the evidence actually gets collected, and it belongs on the page about running your management system day to day rather than on this one.
.legal in practice

Features for ISO 27001 certification

The standard's own ids, all the way down

At control level the ids and naming are 1:1 with ISO 27001. The ISO 27001 and ISO 27002 activities each carry their ID number from the standard automatically, and from a task you can see which framework it belongs to and open the controls it documents.

Sign-off by the person responsible

Decide per task whether approval is required. Where it is, only the responsible person can complete it, everyone else can move it to ready for approval, and it stands there in yellow until they act.

A history on every task

Each task records subtask completion, status changes, documentation and who it was assigned to. A pinned comment carries forward to the next instance of a recurring task, so last year's note is there when it comes round again.

The whole cycle, planned once

Set a recurrence in weeks, months or years, with a start date and an end date the plan respects when it generates tasks. Deadlines can sit as far ahead as you need, so a three-year cycle is planned in one pass.

One framework, an entity at a time

A planned activity fans out into a separate task per group company, each with its own responsible person, and the same activity can run at different times in different companies. A new entity comes into scope without a second framework. Delivered by the Group Companies add-on.

The control skeleton first

A framework can be created without tasks, so the control structure and the responsibilities can be stood up before anyone decides what evidence work to plan underneath them.

ISO 27001 certification Frameworks this covers

One framework, and the certificate that hangs off it.

  • icon-framework-ISO

    ISO 27001

    At the audit you work inside the standard's own structure: the Annex A point, the document hanging on it as its documentation, and the evidence tasks underneath with their dates and owners. Read the framework page for how that structure is built and kept.

    Read about ISO 27001
.legal compliance platform

Maintain your ISO 27001 certification with...

Do you need to keep the certificate alive between audits? We recommend the following module for that task.

Information Security Management

Where your security documentation and controls live, so the certification work sits next to everything else you document. The framework itself, ISO 27001, is run in the Frameworks module.

Explore Information Security Management

Frameworks

Where ISO 27001 itself is switched on and worked through: the controls under the standard's own ids, and the evidence tasks that document them.

Explore Frameworks

Group Companies (add-on)

Bring another entity into certificate scope without a second framework. A planned activity fans out into its own task per group company, each with its own owner and date.

Explore Group Companies

Our Customers

+400

companies

+10.000

users

+79.000

contracts

+14.000

processing activities

Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.
Use cases

Find the job you need done

Every use case is a real piece of compliance work, told the way it actually runs in the platform. Filter by who you are, what you work with, and which frameworks you answer to.

Book demo

12 use cases

Compliance & GRC lead

Run awareness training that reaches every colleague

Send out training and policies, chase the stragglers automatically, and prove every colleague completed it. You bring the material, we run the rails.
See awareness training
Compliance & GRC lead

Manage compliance across a group of companies

Run every company in the group from one platform, document once at group level, and still report entity by entity. Delivered by the Group Companies add-on.
See group compliance
Legal counsel

Run due diligence on your vendors

Classify a vendor on your own criteria, get the answers and documents you need with no login for them, and move the approved ones straight into contracts.
See vendor due diligence
Compliance & GRC lead

Multi-framework compliance: do the work once

Do a control once and it counts across every framework it maps to, with a simulated score on the ones you haven't started yet.
See multi-framework compliance
CISO & IT security

Get NIS2-ready without starting from scratch

Build on the ISO 27001 work you've already done, switch NIS2 on, and let a simulated score show how far ahead you already are.
See NIS2 readiness
Compliance & GRC lead

Build one risk register for the whole organisation

One register across GDPR, NIS2, AI and information security, where each risk area keeps its own matrix, scale and appetite. Delivered by the Enterprise Risk Management add-on.
See the risk register
CISO & IT security

Run your ISMS in one platform

The frameworks you answer to, the controls beneath them and the documentation that proves the work happened, all three in one module, with status updating itself from completed tasks.
See how the ISMS runs
Compliance & GRC lead

Get ready for the D-seal

D-Seal's own criteria sit in the platform under a formal agreement with D-Seal, mapped 1:1 with the level 3 criteria. Work the controls, collect the documentation, export it per task.
See the D-seal route

Frequently Asked Questions about ISO 27001 certification

How is this different from running our management system in the platform day to day?

It is the same platform, told from a different point in the year. Running your management system is the everyday work: the frameworks switched on, the controls beneath them, the tasks that document them and the annual wheel they sit in. This page is about the certificate itself, so it covers what the auditor is shown, how a control proves it was actually performed and by whom, how a new entity comes into scope, and how the work survives the twelve months to the next audit.

How the management system runs day to day

What do we actually put in front of the auditor?

Three things, in practice. The Statement of Applicability, which comes out of the ISO framework as an Excel file. The control itself, with the policy or procedure hanging on it as its documentation. And the evidence behind that control, meaning the tasks sitting under it, each one carrying who was responsible, when it was due and what was attached when it was closed. You work through ISO 27001 on its own while you do it, so the conversation stays inside the standard being audited instead of wandering into the other frameworks the same evidence happens to count towards.

What a Statement of Applicability is

Can our external auditor be given their own access to the platform?

We are not going to promise that here. Users are unlimited, external users included, but a specific role built for an external auditor is not something we have documented, so it is a question to raise on a demo rather than read as a promise on a page. What is settled is the way round it: the documentation sits structured per control, and things leave the platform as exports, so the audit does not depend on anyone getting a login.

We are certified at group level. Can we bring one more entity into scope?

Yes, and without duplicating the framework. A planned activity is scoped to the group companies it applies to and fans out into a separate task for each one, with its own responsible person, and the same activity can run at different times in different companies. So the new entity gets its own work and its own owners while the framework above stays one framework, which is what keeps the group picture and the entity picture the same data rather than two reports that have to be reconciled. One honest caveat: scheduling across companies duplicates rather than groups, so each company gets its own task, and our own advice is to name the activities clearly and uniquely so they can be told apart in a list.

Can the platform tell us whether we are compliant with ISO 27001?

No. The platform reports on the work that has been done, not on whether the standard is met, and at an audit those are two different questions. You get a status per activity line and a documentation-progress figure on a framework you have switched on, both read straight off completed evidence tasks, so when an auditor asks where a number comes from the answer is a list of tasks with dates and owners on it. There is no single overall verdict, and that is deliberate. A control whose evidence work is under way says something quite different from one that has never been started, and one combined number would hide exactly that difference.

How do we stop the work stalling the day after the certificate arrives?

By putting the rhythm into the plan rather than into somebody's memory. Each piece of evidence work carries a frequency in weeks, months or years, with a start date and an end date the plan respects when it generates tasks. A completed task returns when its frequency expires and comes back into the plan. If you ever need one piece of that work outside the platform, a task downloads as a zip holding a PDF summary plus every document uploaded to it. Deadlines are not capped at a year ahead any more, so the whole cycle to the next audit can be laid out in one pass instead of being rebuilt every January.

How do we show that a control was actually performed, and by whom?

The evidence hangs on the task under the control: the upload, the screenshot, the comment, the completion. A task can be created so that approval by the responsible person is required, and then only they can complete it while everyone else can move it to ready for approval, where it stands in yellow until they act. Each task also keeps its own history of subtask completion, status changes, documentation and who it was assigned to.

Does .legal write our documentation, or certify us?

Neither. We build the plan, not the filling-in. What you get from us is the structure the work hangs on: the controls, the evidence tasks, the owners and the dates. The content of every document those tasks produce is written by your own people, because they are the ones who know how the company actually operates. And the certificate is issued by a certification body, so the audit, its rhythm and its cost sit with them. .legal sells compliance software and does not give legal advice.

Are you ISO 27001 certified yourselves?

No, and we would rather say so than let you find out later. .legal holds ISAE 3402 and ISAE 3000, audited annually by BDO, and we work to ISO 27001 requirements without being certified in the standard. It is a fair question to ask a vendor selling you a certification tool, so ask it of everyone.

Still unsure?

Ask Johannes directly, he runs most demos personally

Book him here
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell