ACASOTY · Standard Compliance Management Platform

Your entire certification journey,
in one place.

ISO 27001, ISO 27701, ISO 42001, TISAX. Work through your Statement of Applicability, risk assessment, internal audit and management review in the order the standard expects — then export the exact documents your auditor needs. AI drafts; your people review and approve.

1

Scope

Built for three kinds of organizations. What they share: the record has to start today, not the night before the audit.

Preparing for your first certification

Not sure where to start with the requirements? Enter your industry and company size and get a complete first draft of controls, risks and documents. You learn the management system by refining that draft.

Facing a surveillance or recertification audit

Findings, corrective actions and management review records from previous audits are kept cycle by cycle. Update only what changed and re-export the documents your auditor expects, in the same format.

Running supplier security assessments

Upload a checklist and send suppliers a participation link. Suppliers respond and attach evidence in a dedicated portal; responses and scores are archived per assessment cycle.

2

Features

The records the standard requires, in the order it requires them. Documents and screens share the same numbers — nothing is counted twice.

2.1
Statement of Applicability (SoA)
Record applicability, justification and implementation for every control. AI writes the first draft; people edit and approve it in a bulk review view. Nothing reaches your audit documents until it is approved.
2.2
Assets & risk assessment
Register assets and rate them for confidentiality, integrity and availability. Manage the risk treatment plan and residual risk in the same table, with bulk import from Excel.
2.3
Evidence management
Upload a file and link it to the relevant controls. When the auditor asks "show me the evidence", answer straight from the control view.
2.4
Internal audit & management review
Record audit programmes, findings, corrective actions and management review cycles. Completed cycles are locked and can only be changed when reopened.
2.5
Audit package
Export 15 document types — SoA, risk assessment, audits, management review, policies and more — as PDF, Word or Excel. Every figure comes from the same calculation as the on-screen totals.
2.6
Supplier assessments
Buyers publish a checklist; suppliers answer in the portal. Owners are reminded as deadlines approach, and responses, evidence and scores are archived per cycle.
3

How it works

Three steps. The second takes the most time — and that time is what certification is really about.

  1. 3.1

    Enter your organization profile

    Industry, size, security environment and target standard. Even before signing up, the same inputs show you draft documents and an estimated audit effort.

  2. 3.2

    Draft · review · approve

    Drafts are generated for controls, risks, the audit programme, management review and policies. Owners revise and approve item by item, and the app counts and flags every gap that remains.

  3. 3.3

    Export the audit package

    Export audit documents from approved content. Check your readiness on a single summary report first, then download the documents you need.

4

Supported standards

Only the standards you can start with today. This table updates as new standards are added.

CodeStandardEdition
ISO 27001Information Security2022
ISO 27701Privacy Information2025
ISO 42001AI Management2023
TISAXTISAX VDA ISA6.0.3
5

Platform quote

Pick the standards you need and your quote appears instantly. Current prices are provisional and this calculator will update once they are final.

Standards (select one or more · choose consulting per standard)

Platform only — start right away with no setup fee · With consulting — 1-month remote consulting setup, then platform use

Company size
Billing

Size multiplier applies to standard monthly fees · multi-standard discount (2 standards 3% · 3+ standards 5%) · extra 10% off with the annual plan

3 users included · ₩30,000/mo per additional user

QUOTATION

Prepared for you · Up to 30 employees · 3 users · Monthly billing · 12-month term · Remote support (default)

Provisional
ISO 27001 Information SecurityMonthly fee · Starts immediately₩300,000
Monthly total (excl. VAT)₩300,000
Annual total (12 months)₩3,600,000
VAT 10%₩360,000
Total₩3,960,000

Remote support (default) · 3 users included · 12-month minimum term · certification body audit fees not included · Provisional estimate; final pricing will be confirmed separately

Start with this quote
6

Frequently asked questions

What teams most often ask before getting started. As of 10/2026; standards and prices come from the same values as the calculations on this page.

What is ACASOTY?

A web-based management platform for organizations preparing for ISO and TISAX management system certification. It records your Statement of Applicability (SoA), assets and risk assessment, evidence, internal audits and management reviews in the order the standards require, and exports 15 types of documents to submit for audit.

Which certification standards are supported?

ISO 27001 (2022 edition), ISO 27701 (2025 edition), ISO 42001 (2023 edition), TISAX (6.0.3 edition) — 4 standards in total.

Does ACASOTY issue certificates?

No. ACASOTY is not a certification body and does not issue certificates. Certification audits are carried out by certification bodies; ACASOTY is the tool you use to prepare the records and documents the audit requires. We do not guarantee audit outcomes.

What is AI used for, and who is responsible for the result?

AI drafts your Statement of Applicability, risk assessment, audit programme, management review and policies. Your owners review and approve them, and unapproved drafts never appear in audit documents. The final judgement always rests with you.

In what formats can I download audit documents?

15 document types — SoA, risk assessment, audits, management review, policies and more — export as PDF, Word (DOCX) or Excel (XLSX). Every figure in a document comes from the same calculation as the on-screen totals.

Can I try it before signing up?

Yes. Enter your company details under "Free Assessment" in the top menu to see a full set of draft documents and an estimated audit effort — no sign-up required.

How is the platform fee calculated?

The monthly fee per standard (ISO 27001 ₩300,000/mo, ISO 27701 ₩200,000/mo, ISO 42001 ₩300,000/mo, TISAX ₩400,000/mo, excl. VAT) is multiplied by a company-size factor (Up to 30 employees ×1 · 31–150 employees ×1.3 · 151+ employees ×1.6), then the multi-standard discount (2 standards 3% · 3+ standards 5%) and the 10% annual-plan discount are combined and deducted. The minimum term is 12 months; 3 users are included and each additional user costs ₩30,000 per month. Current prices are provisional — calculate yours instantly with the platform quote on the home page. Selecting ISO 27701 also selects its prerequisite, ISO 27001.

Can I get consulting as well?

Choose "With consulting" for any standard and we run a 1-month remote initial setup before your platform subscription begins. The setup fee is charged once per standard; choose "Platform only" to start right away with no setup fee. Certification body audit fees are not included.

Can I use it for supplier security assessments?

Yes. The buyer uploads a checklist and sends suppliers a participation link; suppliers respond and attach evidence in a dedicated portal. Responses, evidence and scores are archived per assessment cycle.

Where is my data stored?

The database and server functions run in the Singapore region. Data is isolated per organization and centrally managed on the server. Uploaded files are stored in separate object storage, and download links expire after a short time.

What happens to my data if I delete my account?

You can delete your account yourself under Settings > My profile. Identifying information such as your email and name is destroyed immediately. Your organization's certification records belong to the organization and remain, with authorship shown as anonymous. Organization owners can download all organization data as JSON at any time.

Don't wait for the night before the audit.
Start your record today.

See a full set of draft documents from your company details — before you sign up.