Launch offer
USD 579 USD 97 Save USD 482
ISO/IEC 27001:2022

Your ISMS documented
in days, not months

The full documentation set the standard requires — policies, procedures, matrices and records — as editable templates with completion guidance.

USD 579 USD 97 Save USD 482
Instant download
Editable Word and Excel
All four languages included
Ready to download
ISO27001 · v1.0
31 documents in the ISMS framework
8
Sections
4
Languages
5
Excel
Content sample
ISMS Manual
Governance and leadership
DOCX
Risk and treatment matrix
Risk management
XLSX
Statement of Applicability
Risk management
XLSX
Download from your private portal See the index →
The reality of certification

Certification is not granted for intent. It is granted for documented evidence.

You do not present a plan to the certification body: you present a management system that already exists, with approved policies, assessed risks and a Statement of Applicability that justifies every single control. Building that documentation from scratch is the work that consumes the first months of any ISO 27001 project — and it is exactly the work this toolkit hands you already done.

31

documents that make up the complete ISMS framework, from the manual to the operating procedures.

93

Annex A controls addressed one by one in the Statement of Applicability, the first document the auditor examines.

4

languages included in the same purchase: Spanish, English, Portuguese and French.

What's included

What the toolkit includes

Thirty-one documents organised into eight thematic blocks, as editable Word and Excel templates.

ISMS governance and leadership

9 documents

ISMS manual, general policy, document control, management review and the roadmap to certification.

Risk management

4 documents

Risk methodology, risk register with heat map and the complete Statement of Applicability.

Cross-cutting security policies

4 documents

Information classification, access and identity control, acceptable use and remote work, cryptography and keys.

Technology and infrastructure

3 documents

Operational security, cloud security with multi-tenant isolation and the asset inventory.

Secure engineering and development

3 documents

Secure development, coding standard with a review checklist, and change and deployment management.

People, third parties and personal data

3 documents

Personnel lifecycle, supply chain and third parties, and personal data protection.

Operational resilience

2 documents

Incident management with severity levels and deadlines, and the continuity plan with recovery objectives.

Compliance and audit

3 documents

Internal audit, legal requirements matrix by jurisdiction and a guide for handling customer audits.

All 31 documents in the ISO 27001 toolkit, one by one

The complete index, exactly as you will see it in the download portal.

ISMS governance and leadership

  • ISMS Manual
  • General Information Security Policy
  • Control of Documented Information
  • Management Review and Continual Improvement
  • Objectives, Indicators and Annual Programme
  • Roadmap to Certification
  • Implementation Guide
  • Quick Document Guide
  • Master Document Index

Risk management

  • Risk Management Methodology
  • Risk Assessment Report and Treatment Plan
  • Risk Register
  • Statement of Applicability (SoA)

Cross-cutting security policies

  • Information Classification and Handling
  • Access Control and Identity Management
  • Acceptable Use of Assets and Remote Work
  • Cryptography and Key Management

Technology and infrastructure

  • Operational and Infrastructure Security
  • Cloud Security and Multi-tenant Isolation
  • Asset Inventory

Secure engineering and development

  • Secure Software Development
  • Secure Coding and Code Review
  • Change, Environment and Deployment Management

People, third parties and personal data

  • Security Across the Employee Lifecycle
  • Supply Chain and Third-Party Management
  • Personal Data Protection

Operational resilience

  • Security Incident Management
  • Business Continuity and Recovery

Compliance and audit

  • ISMS Internal Audit
  • Legal Requirements Matrix
  • Handling Audits and Due Diligence

And the project, not just the framework

It is not just a set of templates. The Implementation Guide carries the reading path by role, the formal acts of constitution, clause-by-clause traceability to the standard and the evidence calendar; the Roadmap breaks down the nine phases from the decision to the issued certificate. They are part of the 31 documents, not extras on top.

Comparison

Write it or adapt it

The same destination by two roads. The difference is where your team starts.

From a blank page

  • Define the entire documentation structure before writing the first policy.
  • Write thirty-one documents that cross-reference one another and must stay consistent.
  • Find out mid-audit which evidence was never documented.
  • Repeat the whole exercise for every language the group needs.

With the toolkit

  • The structure is already defined and numbered across the framework's eight sections.
  • The documents already cross-reference one another, each with its own completion guide.
  • The framework covers what the standard requires documenting, from clause 4 to 10 and Annex A.
  • All four languages come with the same purchase, at no extra cost.

How it works

From payment to first download, with no human in the loop.

1

Purchase

One-off card payment, processed by Stripe. You can provide your tax ID to receive the invoice in your company's name.

2 minutes
2

Access

Within minutes you receive a personal link to your private portal. No passwords to create or remember: your email is your key.

Instant email
3

Download

Document by document, or the complete package. Editable Word and Excel files, ready to carry your organisation's name and scope.

Permanent access
Pricing

One payment. The whole framework.

No subscription, no per-user licences, no renewals.

Launch offer
USD 579 −83%

USD 97

One-off payment, taxes according to your jurisdiction

Save USD 482
31
documents
8
Sections
5
Excel
4
Languages
  • Complete documentation framework — Thirty-one documents — manual, policies, procedures, matrices and records — organised across the eight sections the standard requires.
  • Project instruments — Business case, gap analysis against the standard, phased action plan and a traceability matrix for every requirement.
  • Editable Word and Excel — No locks, no watermarks, and every document carries its own completion guide explaining what goes in each section.
  • All four languages — Spanish, English, Portuguese and French in the same purchase, with nothing more to pay as they are published.
  • Internal-use licence — For one organisation, with no expiry, no per-user licences and no renewals. Resale and redistribution are not permitted.
  • Permanent private portal — Download document by document or the full pack, as often as you like. You sign in with your email — no passwords to remember.
  • Updates to your edition — Corrections and improvements to the edition you bought appear in your portal at no extra cost.
  • Invoice with your tax details — You can enter your tax ID at checkout. The invoice is issued to your company and stays downloadable from your portal.
Get the toolkit

Secure payment with Stripe. We never store card details.

FAQ

Frequently asked questions

Does buying the toolkit certify my company?

No, and be wary of anyone who promises otherwise. Certification is issued by an accredited body after auditing your management system in operation. What the toolkit removes is the work of drafting that system from scratch: you adapt it to your scope, approve it, operate it and generate the evidence. That part remains yours.

Which documents does ISO/IEC 27001:2022 require?

The standard requires documented information for the ISMS scope (4.3), the security policy (5.2), the risk assessment and treatment process (6.1.2 and 6.1.3), the Statement of Applicability (6.1.3 d), security objectives (6.2), evidence of competence (7.2), operational planning and control (8.1), the results of risk assessment and treatment (8.2 and 8.3), monitoring and measurement evidence (9.1), the internal audit programme and results (9.2), management review results (9.3), and the record of nonconformities and corrective actions (10.2). The toolkit covers that full list, plus the procedures that support it.

What is the Statement of Applicability (SoA) and is it included?

The Statement of Applicability is the document that lists all 93 Annex A controls and, for each one, states whether it applies, why it is included or excluded, and its implementation status. It is the first document any auditor asks for, because it connects the risk assessment to the controls. Yes, it is included as an Excel template with all 93 controls already loaded and the justification structure ready to complete.

How many controls does Annex A of ISO 27001:2022 have?

93 controls, grouped into four themes: 37 organisational, 8 people, 14 physical and 34 technological. The 2022 revision reorganised the 114 controls of the 2013 edition into those four themes and introduced 11 new controls, among them threat intelligence, cloud security and web filtering. The toolkit's Statement of Applicability already lists all 93.

Does it include the risk assessment methodology and matrix?

Yes. It includes the documented methodology — acceptance criteria, likelihood and impact scales and the assessment procedure — and the Excel matrix with formulas for inherent and residual risk, plus the treatment plan. The standard does not mandate a specific method: it requires yours to be documented, repeatable and to produce comparable results. That is precisely what the template provides.

What is the difference between ISO 27001 and ISO 27002?

ISO/IEC 27001 is the auditable standard: it contains the management system requirements and is what an organisation gets certified against. ISO/IEC 27002 is a code of practice explaining how to implement each of the 93 Annex A controls, and it is not certifiable. In practice they are used together: 27001 says what must be demonstrated, 27002 suggests how. The toolkit is structured on 27001, which is what the certification body audits.

Does the toolkit follow the 2022 or the 2013 version?

The 2022 version, which is the only one in force. The transition period from ISO/IEC 27001:2013 ended on 31 October 2025: since then, no certificates are issued or maintained against the 2013 edition. If your documentation still follows the structure of 114 controls across 14 domains, it has to be rewritten around the 93 controls in 4 themes — and that is precisely the starting point the toolkit provides.

What format do the documents come in?

Editable Word (.docx) and Excel (.xlsx), with no protection or locks. Anything specific to each organisation comes as a marked placeholder, with guidance on what to write in it.

How long does it take to implement an ISMS with the toolkit?

The toolkit removes the drafting phase, usually the longest one. What it does not remove is what the standard requires you to demonstrate: that the system works. An auditor needs to see real operating evidence — records, an internal audit and at least one management review — and that requires the ISMS to have been running for a while. What the toolkit saves you is the weeks of writing thirty-one mutually consistent documents, not the evidence period.

Do I need a consultant if I buy the toolkit?

Not for drafting the documentation: that work is already done and every document carries its own completion guide. External support does help if your organisation has nobody with audit experience, if the scope spans several companies or jurisdictions, or if a client is demanding the certificate by a deadline. The toolkit reduces consulting hours; it does not always replace them entirely.

Is it also useful for SOC 2, NIS2 or other frameworks?

The toolkit is built on ISO/IEC 27001:2022 and does not replace the specific requirements of other frameworks. That said, much of the base documentation — security policy, risk management, access control, incident management, continuity, suppliers — is the same evidence SOC 2, NIS2 and similar regimes ask for. It works as a common foundation; mapping controls to each framework has to be done separately.

Can I use it for several companies or resell it?

The licence covers internal use by one organisation and its group. It does not allow reselling, redistributing or publishing the documents as your own. If you are a consultant and want to use it with several clients, write to us: there is a licence for that.

Are all four languages available from day one?

Spanish is complete from the start. English, Portuguese and French are published by domain and appear in your portal as they are released, at no extra cost and with no need to buy again. Your portal always shows what is available in each language.

Is there a refund?

As a digital product with immediate delivery, access is enabled as soon as payment is confirmed. The exact terms are in the refund policy, linked in the footer. If something is not what you expected, write to us before downloading and we will sort it out.

Another question? Write to us at toolkits@snap-compliance.com

The framework already exists. It just needs to become yours.

Download the complete ISMS framework today and start by adapting it, not writing it.

Internal-use licence for one organisation. No subscription, no renewals.