ISO 27001:2022 · flat-priced

ISO 27001, without the enterprise price tag.

GapLedger runs your whole ISMS in plain English: risk, controls, Statement of Applicability, audits and reviews. It emails you before anything lapses. One flat price, unlimited users, no forced integrations.

$500/mo flat · unlimited users · cancel anytime

ISMS readinessSoA 68% complete

ISMS Management

71%

Organizational (A.5)

84%

Technological (A.8)

46%

Reminder · from GapLedger
“Your annual access-rights review (A.5.18) is due in 5 days.”

We keep you on track

Learning ISO 27001 is the hard part. So we lead you through it.

Guided setup, plain-English control guidance, and a running “what needs your attention” list so you always know the next move. Risk reviews, access reviews, audits and management reviews arrive as reminders through the year, which is how the certification you earned stays earned.

Risk assessment review12d overdue
Access rights reviewdue in 5d
Internal auditon track

The product

A real ISMS, not a spreadsheet.

Documentation-first. No agents to install and no integrations to wire up. You end up with an information security management system you can keep current, and defend when someone asks.

Plain-English controls

Every ISO 27001 requirement in plain language: the 93 Annex A controls and the 18 management clauses (4–10), 111 in all, each with guidance. No security degree required.

Risk → Statement of Applicability

A built-in risk register (qualitative or ISO 27005 depth) alongside the controls it informs, and the SoA your auditor will ask for, generated in one click.

The whole management system

Nonconformities and corrective actions, internal audits, management reviews. This is the part of an ISMS a control checklist leaves out.

One-click audit pack

Export SoA, risk register, CAPA log, audit history, and evidence index in a single PDF the morning your auditor arrives.

We nudge you before it lapses

Drills, reviews, and due dates turn into reminders, so a lapsed control is something you catch in advance instead of the week your auditor arrives.

Multi-scope & multi-framework

Run one org-wide ISMS or several at once, for different sites, subsidiaries or product lines. Manage multiple standards side by side and reuse the same evidence across all of them.

Frameworks

One platform, every standard.

Start with ISO 27001 and add whatever standards your customers ask for. Run them side by side and reuse the same evidence across frameworks, so one piece of proof counts everywhere it applies. Each add-on is a flat monthly price, shown on its card below. Nothing is charged per employee, and annual billing saves 10 percent. See full pricing.

All 93 Annex A controls plus the 18 clause 4–10 requirements (111 in total)

$500/mo (Core plan)

Security, Availability, Confidentiality, Processing Integrity

+$150/mo

NIST CSF 2.0

Included

All six Functions, Govern through Recover. Comes with Core.

Included with Core

ISO/IEC 27701:2019

Add-on

Privacy / PIMS — controller & processor, GDPR-aligned

+$150/mo

Cyber Essentials

Add-on

UK NCSC baseline — five technical controls

+$99/mo

ISO 9001:2015

Add-on

Quality management — clauses 4–10, incl. the 2024 climate amendment

+$150/mo

ISO 22301:2019

Add-on

Business continuity — BIA, strategies, plans and exercising

+$150/mo

Need a standard you don't see? Tell us.

Pricing

One flat price. Everyone included.

The price is on this page. No per-employee tax, no renewal surprises, no “book a demo to see the price.”

Core

$500/mo

or $5,400/yr — save 10%

  • ✓ Full ISO 27001:2022 — 93 Annex A controls + 18 clause requirements
  • ✓ NIST CSF 2.0 included
  • ✓ Unlimited users
  • ✓ Risk register + SoA + audits + reviews
  • ✓ One-click audit pack
  • + Add SOC 2 later — it reuses your ISO 27001 evidence
  • ✓ Cancel anytime
Start free

Practice — for consultants & MSPs

$1,000/mo

Core plus the multi-client console. One flat price however many clients you carry. Learn more.

  • ✓ Unlimited client organizations
  • ✓ Portfolio dashboard — every client's readiness at a glance
  • ✓ Provision a client ISMS in one minute
  • ✓ Client-visible audit trail of everything you do
  • ✓ Your own ISO 27001 ISMS included
Start free — 2 clients in trial

Built to be trusted

We run our own controls against ourselves.

Enforced multi-factor auth · strict tenant isolation · write-once evidence + append-only audit trail · encryption at rest · least-privilege throughout. Read more.