Toolkit · v13 · New
ISO 27001: 2022 Complete Toolkit
Not a template pack. The complete documentation set, the step-by-step programme and the audit preparation, with 19 diagrams that show you how it all connects. Every document ISO 27001:2022 asks for, written lean enough to adopt as they stand. Then the part template vendors leave out: a twelve-week roadmap where every task names the file to open and the record it leaves, the questions auditors actually ask with model answers, a clause-by-clause evidence index, a map of what your existing tools already prove, and a full internal-audit and mock-audit pack. 57 files, or 67 with the eleven policies as separate documents, and 19 diagrams including an A3 wall poster.
£399one-off
Secure Stripe checkout · instant email delivery · price excludes VAT
- Files by edition
- 57/67
- Controls
- 93
- Diagrams
- 19
- Week plan
- 12
The difference
Most toolkits sell you documents. Documents are a third of the job.
Buy a template pack and you get 80 files and no idea what to do on Monday morning. This package answers the questions the templates leave hanging: what to do in what order, what record each step leaves, what the auditor will ask, and what your existing tools already prove.
Step by step
A twelve-week roadmap, not a folder
Every task numbered, with the file to open, the record it leaves, who does it, how long it takes, and why an auditor cares. Written for someone doing this for the first time.
Visual
19 diagrams, one of them an A3 wall poster
The whole ISMS on one page. Risk process, heat map, evidence chain, incident lifecycle, audit journey, tooling coverage. Print-quality, and licensed for your own board packs.
Audit-ready
The questions auditors actually ask
Grouped by clause and by role, each with a model answer, the trap that catches people, and exactly what to have open on screen while you answer.
Evidence
An index from requirement to proof
Every clause and control mapped to the document, the record, and the specific thing to show. Plus a 124-row clause matrix covering every requirement in clauses 4 to 10.
Your stack
Stop rebuilding records you already own
If you run Okta, Entra, Intune, Lansweeper, AWS, Google Workspace or Microsoft 365, most of the evidence already exists. The tooling map shows what each one proves and what you still have to write down.
Rehearsal
Internal audit and mock audit packs
The full internal-audit checklist clause 9.2 requires, honest options for the independence problem at small scale, and a 62-question mock audit to rehearse the interviews.
Built from 25+ accreditation programmes delivered hands-on, not assembled from a template library.
What's inside
Seven folders. Nothing missing, nothing padded.
The documents are lean enough to adopt as they stand. Everything else - the roadmap, the auditor questions, the evidence index, the tooling map, the audit preparation - exists because documents alone do not get anyone through Stage 2. Word and Excel throughout, plus print-quality diagrams. Shown as the all-in-one edition; the separate edition ships identical content with each policy as its own document.
00 - Start Here
7 files01 - Governance
4 files02 - Policies
6 files03 - Records
12 files04 - Audit Preparation
5 files05 - Diagrams (PNG)
4 files06 - Support
1 fileBuilt to pass, not to pad
- Every mandatory document and record for clauses 4 to 10 - the clause 5.2 Information Security Policy as its own approved document, and clause 6.3 planning of changes that most kits still miss
- Statement of Applicability pre-mapped across all 93 Annex A controls, each one pointing at the document section that states how it is operated, with columns for the tool that evidences it
- A 124-row clause compliance matrix: every requirement, how you meet it, where the evidence lives
- A twelve-week roadmap where every task names the file, the record and the reason an auditor cares
- The questions auditors ask, by clause and by role, with model answers and the trap in each one
- An evidence index that tells you exactly what to open on screen for every requirement
- A tooling map: what Okta, Entra, Intune, Lansweeper, AWS and the rest already prove, so you stop rebuilding records you own
- Internal audit pack, Stage 1 and Stage 2 readiness checklists, and a mock audit script to rehearse with
- 19 print-quality diagrams, one of them an A3 wall poster, licensed for your own board packs and inductions
Every document and register uses placeholder markers like [COMPANY NAME] with a find-and-replace table in the README - your details go in once, the set becomes yours.
Done for you
Want the guarantee, not just the toolkit?
The Certification Pass Programme runs the whole journey for you - toolkit implementation, records, internal audit and the certification audit itself. Book a call, we scope it and issue a proposal, and once that proposal is agreed it is guaranteed to pass the standard named in it. If you do not pass, we refund the certification body's fee for those assessment days.
FAQ
Toolkit questions
How is this different from the template packs I can buy elsewhere?+
Template packs sell you documents. The documents here are only the first third of the package. The rest is the part that actually gets you through an audit: a twelve-week roadmap where every task names the file to open and the record it produces, the questions auditors ask with model answers and the trap in each one, an evidence index telling you exactly what to put on screen for every requirement, a map of what your existing tooling already proves so you stop rebuilding records you own, an internal audit pack with the full checklist, and a mock audit script to rehearse the interviews. Plus 19 diagrams so you can see how the whole system connects rather than inferring it from 80 loose files.
Will this get us through Stage 1 and Stage 2?+
It covers every piece of documented information ISO 27001:2022 requires across clauses 4 to 10, including clause 6.3 planning of changes that many older kits still omit, plus the policies auditors ask about and every record template you need to show the ISMS operating. The Implementation Roadmap sequences it, the readiness checklists confirm it, and the Mock Audit Script rehearses the part most people are unprepared for. Certification bodies also expect roughly three months of live records before Stage 2, so the roadmap starts the records in week one rather than week ten.
Why 57 files when some vendors ship 80 or more?+
Because the policies are lean and the guidance is generous, which is the opposite of how template packs are built. The standard explicitly allows combining, so the eleven policy topics sit in one Policy Set beneath the Information Security Policy that clause 5.2 asks for, rather than scattered across separate documents an auditor has to reconcile - and if you prefer them apart, the separate edition ships those same eleven as standalone files. The file count then goes up again because of what document packs typically leave out: the roadmap, the auditor Q&A, the evidence index, the tooling map, the audit preparation pack and the diagrams. Fewer policies, far more help.
We already use Vanta, Drata or a similar platform. Is this still useful?+
Yes, and the Tooling Map has a section on exactly this. Those platforms monitor technical controls continuously and collect evidence well. What they cannot do is decide your scope, judge which risks matter to your business, write justifications that reflect your reality, hold your management review or own a control - and those are precisely what a Stage 1 auditor tests. Use this as the governance layer the platform does not provide, and point the Statement of Applicability at the platform wherever it holds the record.
What do I actually receive?+
A ZIP with seven numbered folders. Documents are editable Word files, registers are Excel, and the diagrams are print-quality PNGs plus an A3 poster as both PDF and editable Word. Every place needing your details is marked with a placeholder like [COMPANY NAME] and listed in a find-and-replace table in the README, which takes about an hour to work through for the whole package.
All-in-one or separate policies?+
Same content, same price, your choice at checkout. The all-in-one edition binds the eleven policy topics into a single Policy Set - fewer documents to version and control. The separate edition ships each policy as its own document, which is easier when different owners review different policies, or when a customer or auditor asks for one specific policy. Everything else in the package is identical.
How does the download work?+
The moment your payment clears, a download link is emailed to you. Each link is single use: it downloads the ZIP once, which is how we keep a single-company licence meaningful. Save the file somewhere safe. If a download fails or gets interrupted, you can request one replacement link from the shop and it is emailed to the same address; after that, email hello@featheron.com with your order reference and we will issue another. Links always serve the latest version.
Is it really ours to keep?+
Yes. One payment and the files are yours permanently - once downloaded they are on your machine, and the licence covers internal use by one company: edit them, adapt them, show them to your auditors, and use the diagrams in your own board packs and inductions. Updates are included, so a link issued later always serves the current version. Resale and redistribution are not permitted.
What if we want someone to run it for us, or guarantee the outcome?+
Book the free 15-minute intro call. The Certification Pass Programme covers implementation support, a pre-assessment before your certification body arrives, and accompaniment through the audit itself. We scope it on that call and issue a written proposal; once the proposal is agreed it is guaranteed to pass the standard named in it, and if you do not pass we refund the certification body's fee for those assessment days, so the audit itself does not cost you. It is quoted rather than listed because it depends on your organisation's size and the number of audit days your certification body allocates, and the full wording is on the Terms page. There is also a £150 advisory hour for a single blocker, and a £1,000 Accreditation Readiness Review for a full independent gap assessment.
Your ISMS paperwork, done this week
One payment, instant download, and your link always serves the latest version. Fill the blanks, follow the 90-day plan, walk into Stage 1 ready.
Secure Stripe checkout · instant email delivery · price excludes VAT · single-company licence ( terms )