Record credible cause–event–consequence scenarios and compare inherent, residual and target exposure.
Build an evidence-led ISMS—not another spreadsheet.
Assess management-system requirements, understand information-security risk, justify Annex A controls and maintain a controlled Statement of Applicability in one connected workspace.
No credit card required · Save and return · Designed for evidence-led readinessGap analysis, risk and control decisions should not become disconnected records.
Connect treatment decisions to Annex A applicability, implementation evidence and accountable ownership.
Turn hundreds of detailed records into prioritised gaps, open treatment and readiness decisions.
From requirement to management decision.
Assess
Evaluate Clauses 4–10 with evidence, findings and weighted readiness.
Evaluate risk
Structure cause, event, consequence, impact and likelihood.
Select controls
Link treatment decisions directly to applicable Annex A controls.
Prove implementation
Retain ownership, evidence, status and effectiveness information.
Report
Give management a clear view of exposure, priorities and readiness.
See what the organisation can produce.
- Clause-level readiness assessment
- Structured ISMS risk register
- Interactive 5×5 heat map
- Risk-to-control treatment links
- Controlled Statement of Applicability
- Evidence and management action trail
- Executive readiness report
Choose the route that matches the work.
£20.99/month
One organisation beginning a controlled assurance workspace.
View Starter →£59/month
Connected audit, risk, SoA, evidence and improvement activity.
Start 14-day trial →£129 once
Complete a controlled SoA without a recurring platform subscription.
View standalone SoA →Your assurance information deserves clear safeguards.
Review how RPG Excellence approaches hosting, authentication, access control, privacy, retention, AI use and continuity.
Before you start.
Does this provide ISO certification?
No. RPG Excellence supports structured readiness, evidence and improvement. Accredited certification remains the responsibility of an accredited certification body.
Can we use the SoA without a full assessment?
Yes. The standalone Statement of Applicability option provides all 93 Annex A controls, rationale, implementation, evidence and residual-risk decisions.
Can assessment work be saved?
Yes. Authenticated users can save progress, return to assessments and retain controlled records.
Can risks be linked to controls?
Yes. Information-security risks can be linked to treatment controls and the relevant SoA workspace, preserving risk-to-control traceability.
