NIS2 aantoonbaar op orde

Voer acties één keer uit en toon direct compliance aan voor meerdere normen.
ISOPlanner™ zet de vier plichten uit de Cyberbeveiligingswet om in taken, eigenaren en bewijs.
Alles in uw eigen Microsoft 365-omgeving
✓ Risicobeoordeling en maatregelen op één plek
✓ Werk samen aan NIS2 in uw eigen omgeving
✓ Structureer bewijsvoering en rapportage integraal
✓ Voorbereiding op ISO 27001 en multi-compliance

Bekijk direct hoe ISOPlanner™ u helpt te voldoen aan NIS2.

ISOPlanner™ wordt vertrouwd door 600+ bedrijven

Ondersteuning voor 50+ normen
ISOPlanner™ Supports These ISO 27001 Versions

Van Verplichting naar Aantoonbaar op Orde

Een verplichting zegt wat u moet doen. Grip laat zien of het ook nog gebeurt. Hieronder staat naast elke NIS2-verplichting het mechanisme dat die verplichting op orde houdt: een eigenaar, een status en bewijs dat ontstaat terwijl het werk gebeurt, in uw eigen Microsoft 365-omgeving.

Uw verplichting

Hoe ISOPlanner™ helpt

Zorgplicht

Scope is set once, and every asset, risk and control inherits it, so nothing sits outside the boundary unnoticed.

Meldplicht

A pre-built policy set mapped to the clauses, each with an owner and a review date. You approve, we track it.

Bestuurdersaansprakelijkheid

A risk register linked to the assets already in your Microsoft 365, so analysis starts from your estate, not a blank sheet.

Toezicht

Generated from your risk decisions, so every included control has a reason and every exclusion has a recorded justification.

Implement the Annex A controls

All 93 controls pre-loaded across the four themes, each carrying an owner, a status and its evidence.

Keep evidence that the system runs

Evidence collects from Microsoft 365 as people work. No screenshot folder, no evidence sprint in the six weeks before the audit.

Audit yourself and review at management level (clause 9)

Both scheduled in the annual plan, with findings, actions and minutes held against the clause they answer.

Correct what fails and improve (clause 10)

Findings become tracked actions with owners and dates, and the closure record is what the next surveillance audit asks to see.

How ISOPlanner™ Helps You Control ISO 27001

ISOPlanner™ structures your ISO 27001 programme inside Microsoft 365, from initial implementation through to certification and ongoing compliance. 600+ organisations across 15 countries run their ISMS this way.

Pre-built framework

ISOPlanner™ includes a complete ISO 27001 framework with all 93 Annex A controls pre-mapped, structured, and ready to assign to your team from day one. No blank documents. No manual control translation. When you are ready to expand, ISOPlanner™ supports 50+ international standards from the same environment.

1
Embedded ML
API Calling ML
2

AI Assistant

The AI Assistant reads your active controls and generates specific, actionable tasks for the right team members. ISO requirements become owned work items, not documents someone has to interpret. For most organisations, it reduces or eliminates the need for external consultants throughout implementation.

Risk Management

Identify, assess, and document information security risks using a configurable scoring model. Risks are treated, accepted, or transferred with a full audit trail. The risk register lives in SharePoint and is accessible to auditors at any time, without exports or last-minute preparation.

3
ML Platform
API Calling ML
4

Automated Evidence Collection

ISOPlanner™ automates evidence collection for two of the most frequently tested ISO 27001 controls: Microsoft Entra ID MFA Check, which verifies multi-factor authentication status across your user base, and Microsoft Secure Score, which pulls  your current score and maps it directly to relevant ISO 27001 controls. Manual evidence gathering for these controls is eliminated entirely.

Audit Planning

Schedule internal and external audits directly in ISOPlanner™. Prepare evidence packages, track open findings, and coordinate auditor access to your SharePoint documentation. Nothing is assembled at the last minute.

5
ML Platform
Gehost in EU-icoon
100% gehost in de EU
Kickstart your 27001 Certification

Instant 27001: The Guaranteed Three-Month Route

Instant 27001 is developed by an independent ISO 27001 specialist and ISOPlanner™ partner with deep implementation experience. It is a complete, practice-based ISMS built from real certification work,  reviewed by auditors, and delivered directly into your ISOPlanner™ environment.

From day one, your system is fully configured. Controls mapped, requirements structured, and your compliance program ready to run. No setup from scratch.

Instant Lives in ISOPlanner™

Everything is pre-configured inside ISOPlanner™. Your controls, risks, and documentation are structured and connected from the start. You work directly in ISOPlanner™ and SharePoint, no parallel systems, no rebuilding from a folder structure.

1
Embedded ML
API Calling ML
2

Full Pre Filled ISO 27001 Content

To help you out very quickly to get the right structures turned into documentation. Instant 27001 helps you with starting with 85% done and delivers content you just needs to ammend slightly to get it right into production, getting it ready for an auditor, fast.

100% First-Time Certification

Every organisation that has gone through Instant 27001 passed their first certification audit. Backed by a money-back guarantee if your stage 1 audit fails.

3
Embedded ML

Need more info on how Instant 27001 works?

Check out Instant 27001
Answered

Frequently Asked Questions

01.

What is the scope of an ISO 27001 Information Security Management System?

ISO 27001 Clause 4.3 requires organisations to define the scope of the ISMS by considering internal and external issues, interested party requirements, and interfaces and dependencies. The scope document sets the boundary of the ISMS, specifying which parts of the organisation, systems, and locations are covered. A clear scope is a prerequisite for certification. ISOPlanner™ includes a scope definition template that guides you through the Clause 4 context analysis step by step.

02.

What is the Statement of Applicability (SoA) and why is it required?

The Statement of Applicability is a mandatory document under ISO 27001 Clause 6.1.3 that lists all 93 Annex A controls, states whether each is applicable or excluded, and provides the justification. The SoA bridges risk assessment and control implementation, and is always the first document auditors request. In ISOPlanner™ you can generate and maintains the SoA as controls are implemented and risk treatment decisions are recorded.

03.

How does the ISO 27001 risk assessment process work?

ISO 27001 Clause 6.1 requires identifying information security risks, analysing and evaluating their likelihood and impact, and producing a risk treatment plan that addresses accepted risks. Organisations must define their own risk assessment methodology and apply it consistently. ISOPlanner™ provides a built-in risk register and treatment plan that walks you through the full risk process and links each risk to the relevant Annex A controls.

04.

What is the difference between corrective action and continual improvement in ISO 27001?

Corrective action (Clause 10.1) addresses identified nonconformities: finding root causes, implementing fixes, and verifying effectiveness. Continual improvement (Clause 10.2) is an ongoing commitment to enhance the ISMS over time, driven by monitoring results, internal audits, and management reviews. ISOPlanner™ provides a nonconformity register for corrective actions and an annual improvement plan linked to management review outputs.

05.

How long does ISO 27001 certification typically take?

For most organisations starting from scratch, the full journey takes six to twelve months: gap assessment, risk assessment, control implementation, internal audit, management review, and a two-stage certification audit. Organisations with strong existing security practices or an ISO 9001 base can move faster. ISOPlanner™ accelerates the process with pre-built templates, automated evidence collection, and a structured implementation roadmap.

06.

What happens at an ISO 27001 management review?

ISO 27001 Clause 9.3 requires top management to review the ISMS at planned intervals. The review must cover ISMS performance, risk assessment results, audit findings, stakeholder feedback, incidents and nonconformities, and opportunities for improvement. Auditors look for direct evidence of management engagement. ISOPlanner™ includes a management review template that captures all required inputs and outputs in a single session.

07.

How does ISOPlanner™ support ongoing ISO 27001 compliance after certification?

Certification is not a one-time event. ISOPlanner™ keeps your ISMS active between audits by automating evidence collection across all 93 Annex A controls, scheduling internal audit cycles, tracking corrective actions and their deadlines, and generating management review inputs. Surveillance audits are required in years 1 and 2, with recertification in year 3. ISOPlanner™ ensures your ISMS stays audit-ready throughout the full three-year cycle.