ISO 13485 & MDSAP Ready
Editable Word & Excel
ISO 13485 / MDSAP / FDA QMSR
Used by 100+ quality teams
ISO/IEC 27001:2022 · ANNEX A · NIS-2
ISO 27001 Documentation Kit
An information security management system ready to adopt: 21 procedures and policies, 18 forms and registers, and the Statement of Applicability with all 93 controls mapped.
€590
VAT calculated at checkout
42 files · 21 procedures · 18 templates
Editable Word and Excel files
Four ways an ISO 27001 project goes wrong
The first is writing the scope statement before the context and the interested parties have been worked through: written first, it describes the company and not the boundary of the system. The second is choosing controls from Annex A and then writing risks to justify them, which produces a Statement of Applicability that nothing supports.
The third is a system that has documents and no records. A certification audit samples evidence from a period, and a system that started operating three weeks before the audit cannot produce it. The fourth is letting the person who runs the system audit it, when the standard requires objectivity.
None of these are hard problems. They are the consequence of reading ISO/IEC 27001 as a list of documents to write rather than as a set of processes that have to run and leave records.
- 42 files
- 21 procedures and policies
- 10 forms
- 8 registers
- 93 controls mapped
- Word and Excel
Scope
What the kit covers
The kit covers the management system clauses, the risk process and the Annex A controls, each in a procedure of the same structure with the forms and registers it produces.
01
The management system
Clauses 4 to 10: manual and scope, policy, objectives and planning of changes, documented information and communication, competence and awareness, legal and contractual requirements, internal audit, management review, nonconformity and improvement.
02
Risk and the Statement of Applicability
Risk criteria, assessment and treatment, with the risk register, the assessment record and the Statement of Applicability listing the 93 controls of Annex A, each mapped to the procedure that implements it.
03
The operational controls
Twelve procedures for the Annex A controls: operational planning, assets and classification, access control, operations security, vulnerabilities, secure development, physical security, human resources, suppliers and cloud, incidents, continuity, logging and monitoring.
Contents
42 files: 21 procedures and policies with their forms and registers
Audience
Who the kit is for
- Organizations seeking ISO/IEC 27001 certification
- Software and service companies asked for ISO/IEC 27001 by their customers
- Entities within the scope of NIS-2 that need the Article 21 measures documented
- Information security managers building a first management system
- Consultants implementing ISO/IEC 27001 for a client
The kit assumes you can adapt a procedure to your organization and set the parameters it leaves to you: risk appetite, classification levels, deadlines, recovery objectives. It has no medical device content. It does not replace the standard, and you need your own copy.
What is included
What you get when you buy
- 21 procedures and policies in Word, in one layout
- 10 forms in Word, one for each record the procedures produce
- 8 registers in Excel, including the risk register and the asset inventory
- Statement of Applicability with the 93 Annex A controls, each mapped to its procedure
- Master Index with the clause map, the Annex A control map and a NIS-2 mapping
- README with the implementation sequence in five phases
- Glossary of information security terms
- Free updates when the kit is revised
Questions
Before you buy
Do I need to buy the standard as well?
Yes. The kit implements ISO/IEC 27001:2022 but does not reproduce it. The Statement of Applicability gives a short reminder of each control’s subject; the exact control text is taken from your copy of the standard.
Which edition of the standard does it follow?
ISO/IEC 27001:2022, with the 93 controls of the 2022 Annex A. The context analysis includes the determination on climate change introduced by the 2024 amendment.
Does it cover ISO 13485 as well?
No. This kit has no medical device content. A manufacturer that needs both standards in one system uses the ISO 13485 + ISO 27001 Integrated Documentation Kit.
Is the kit suitable for a small organization?
Yes. The README assumes a small organization with an Information Security Manager who gives the system one day a week, and it says which three decisions to take before editing any document.
How long does implementation take?
The README sets out five phases. The first three, up to the approved risk treatment plan and Statement of Applicability, take about nine to thirteen weeks. Three to six months of operation before the certification audit is realistic, because the audit samples records from a period.
Does it make us compliant with NIS-2?
No. The Master Index maps the measures of Article 21 to the documents of the kit and says where the coverage is partial. A mapping shows overlap, not equivalence: it reduces the work, it does not replace the assessment.
In which format are the documents?
Procedures and forms are Word files; registers and the Statement of Applicability are Excel files. Everything is editable, with bracketed placeholders for your company name, roles and dates.
Do I get updates when the kit changes?
Yes. When the kit is revised, you receive the updated files at no additional cost.
Can the kit be used in more than one company?
Yes. For use across several companies, for example by a consultant with several clients or a group with several legal entities, get in touch and we will arrange a multi-licence purchase.
Does the kit guarantee certification?
No. Certification depends on operating the processes and keeping the records. The kit defines the processes, gives you the forms and tells you what a certification auditor reads first.
ISO 27001 Documentation Kit
42 files: 21 procedures and policies, 10 forms, 8 registers, the Glossary and the Master Index for ISO/IEC 27001:2022, in editable Word and Excel.
€590.00

