Preparing for your first certification
Not sure where to start with the requirements? Enter your industry and company size and get a complete first draft of controls, risks and documents. You learn the management system by refining that draft.
ACASOTY · Standard Compliance Management Platform
ISO 27001, ISO 27701, ISO 42001, TISAX. Work through your Statement of Applicability, risk assessment, internal audit and management review in the order the standard expects — then export the exact documents your auditor needs. AI drafts; your people review and approve.
Built for three kinds of organizations. What they share: the record has to start today, not the night before the audit.
Not sure where to start with the requirements? Enter your industry and company size and get a complete first draft of controls, risks and documents. You learn the management system by refining that draft.
Findings, corrective actions and management review records from previous audits are kept cycle by cycle. Update only what changed and re-export the documents your auditor expects, in the same format.
Upload a checklist and send suppliers a participation link. Suppliers respond and attach evidence in a dedicated portal; responses and scores are archived per assessment cycle.
The records the standard requires, in the order it requires them. Documents and screens share the same numbers — nothing is counted twice.
Three steps. The second takes the most time — and that time is what certification is really about.
Industry, size, security environment and target standard. Even before signing up, the same inputs show you draft documents and an estimated audit effort.
Drafts are generated for controls, risks, the audit programme, management review and policies. Owners revise and approve item by item, and the app counts and flags every gap that remains.
Export audit documents from approved content. Check your readiness on a single summary report first, then download the documents you need.
Only the standards you can start with today. This table updates as new standards are added.
| Code | Standard | Edition |
|---|---|---|
| ISO 27001 | Information Security | 2022 |
| ISO 27701 | Privacy Information | 2025 |
| ISO 42001 | AI Management | 2023 |
| TISAX | TISAX VDA ISA | 6.0.3 |
Pick the standards you need and your quote appears instantly. Current prices are provisional and this calculator will update once they are final.
Platform only — start right away with no setup fee · With consulting — 1-month remote consulting setup, then platform use
Size multiplier applies to standard monthly fees · multi-standard discount (2 standards 3% · 3+ standards 5%) · extra 10% off with the annual plan
3 users included · ₩30,000/mo per additional user
Prepared for you · Up to 30 employees · 3 users · Monthly billing · 12-month term · Remote support (default)
| ISO 27001 Information SecurityMonthly fee · Starts immediately | ₩300,000 |
| Monthly total (excl. VAT) | ₩300,000 |
| Annual total (12 months) | ₩3,600,000 |
| VAT 10% | ₩360,000 |
Remote support (default) · 3 users included · 12-month minimum term · certification body audit fees not included · Provisional estimate; final pricing will be confirmed separately
What teams most often ask before getting started. As of 10/2026; standards and prices come from the same values as the calculations on this page.
A web-based management platform for organizations preparing for ISO and TISAX management system certification. It records your Statement of Applicability (SoA), assets and risk assessment, evidence, internal audits and management reviews in the order the standards require, and exports 15 types of documents to submit for audit.
ISO 27001 (2022 edition), ISO 27701 (2025 edition), ISO 42001 (2023 edition), TISAX (6.0.3 edition) — 4 standards in total.
No. ACASOTY is not a certification body and does not issue certificates. Certification audits are carried out by certification bodies; ACASOTY is the tool you use to prepare the records and documents the audit requires. We do not guarantee audit outcomes.
AI drafts your Statement of Applicability, risk assessment, audit programme, management review and policies. Your owners review and approve them, and unapproved drafts never appear in audit documents. The final judgement always rests with you.
15 document types — SoA, risk assessment, audits, management review, policies and more — export as PDF, Word (DOCX) or Excel (XLSX). Every figure in a document comes from the same calculation as the on-screen totals.
Yes. Enter your company details under "Free Assessment" in the top menu to see a full set of draft documents and an estimated audit effort — no sign-up required.
The monthly fee per standard (ISO 27001 ₩300,000/mo, ISO 27701 ₩200,000/mo, ISO 42001 ₩300,000/mo, TISAX ₩400,000/mo, excl. VAT) is multiplied by a company-size factor (Up to 30 employees ×1 · 31–150 employees ×1.3 · 151+ employees ×1.6), then the multi-standard discount (2 standards 3% · 3+ standards 5%) and the 10% annual-plan discount are combined and deducted. The minimum term is 12 months; 3 users are included and each additional user costs ₩30,000 per month. Current prices are provisional — calculate yours instantly with the platform quote on the home page. Selecting ISO 27701 also selects its prerequisite, ISO 27001.
Choose "With consulting" for any standard and we run a 1-month remote initial setup before your platform subscription begins. The setup fee is charged once per standard; choose "Platform only" to start right away with no setup fee. Certification body audit fees are not included.
Yes. The buyer uploads a checklist and sends suppliers a participation link; suppliers respond and attach evidence in a dedicated portal. Responses, evidence and scores are archived per assessment cycle.
The database and server functions run in the Singapore region. Data is isolated per organization and centrally managed on the server. Uploaded files are stored in separate object storage, and download links expire after a short time.
You can delete your account yourself under Settings > My profile. Identifying information such as your email and name is destroyed immediately. Your organization's certification records belong to the organization and remain, with authorship shown as anonymous. Organization owners can download all organization data as JSON at any time.
Don't wait for the night before the audit.
Start your record today.
See a full set of draft documents from your company details — before you sign up.