Free · Open source · No account, no server, no tracking

Build an ISO/IEC 27001:2022 ISMS without hiring a consultant to translate it first.

Eleven documents that make up a real Information Security Management System — gap assessment, risk register, all 93 Annex A controls, audit tracking, and more — as an interactive web app, plain Markdown, or downloadable Excel and Word files. Everything runs in your browser. Nothing is uploaded anywhere.

MIT licensed · Works offline once downloaded · Your data stays in your browser's local storage
ISMS Toolkit dashboard showing progress across all 11 modules
What's inside

Eleven documents, following the PDCA cycle

Plan, Do, Check, Act — the same structure ISO/IEC 27001 itself is built on. Work through them roughly in order the first time; every later document builds on the ones before it.

01 · PLAN

Gap Assessment

A quick maturity self-check across every clause and Annex A theme.

02 · PLAN

ISMS Handbook

Scope, context, leadership commitment, roles, objectives.

03 · PLAN

Risk Register

4×4 likelihood × impact matrix, treatment decisions, residual risk.

04 · PLAN

Asset Inventory

The systems and data your risks and controls actually refer to.

05 · PLAN

Statement of Applicability

All 93 Annex A controls — applicability, status, owner, evidence.

06 · CHECK

Internal Audit & CAPA

Audit-readiness checklist plus a corrective action log.

07 · DO

Supplier Assessments

Security evaluation of vendors and third parties with data access.

08 · DO

Business Continuity & DR

Recovery objectives, continuity strategy, and a test log.

09 · ACT

Management Review

The annual top-management review record.

10 · THROUGHOUT

Document & Training Register

Version control plus a security awareness training log.

11 · ACT

ROI Analysis

A simple cost-vs-benefit view for stakeholders.

Three formats, same content

Use whichever fits how you work

🖥️

Interactive web app

A single self-contained HTML file. Fillable forms, live progress dashboard, search across all 93 controls, JSON export/import, print-to-PDF. No install, no build step.

Launch the app →
📝

Markdown templates

The same eleven documents as plain text, for version control alongside your code or publishing via MkDocs/Docsify/GitHub Pages.

Browse the docs →
📊

Excel & Word

One workbook with all eleven tabs (dropdowns, live formulas) plus a Word handbook — for anyone who'd rather just open a spreadsheet.

Download templates →