CertAssist is a compliance workspace that lays out every control for ISO 27001, SOC 2, ISO 42001, GDPR and other frameworks, tells you what evidence to collect, and gives auditors read-only access to review it. It is built by compliance consultants and runs as a web app at dashboard.certassist.io.
What is CertAssist?
CertAssist is a web-based compliance management workspace for achieving certifications such as ISO 27001:2022, SOC 2, HIPAA, PCI DSS, GDPR, ISO 42001:2023, Essential Eight, DISP, UK Cyber Essentials, CMMC and ISO 27001 Internal Audit. You pick a framework, work through laid-out controls with guidance and evidence checklists, and produce board-ready reports plus an Excel SOA your auditor can mark up. It is made by CertAssist, founded by managing director Peter Stewart, a former lead assessor.
Key Features
- One control board — every control with status, owner and evidence in a single view, grouped by theme.
- Six registers — risk, suppliers, legal, non-conformities, interest groups and ISO 27001 maintenance, with pre-populated libraries.
- Reporting dashboard — readiness percentage, weekly and monthly trend, forecast completion date from your real pace, and nightly snapshots.
- Auditor access — read-only, scoped to the assessment, with no shared logins.
- Excel SOA export — a statement of applicability your auditor can mark up.
- No integrations by design — evidence is uploaded manually, so nothing connects to production systems.
- Unlimited frameworks and assessments — add as many frameworks as you like on one plan.
- Unlimited team members and auditor accounts — no per-seat licensing.
Who is it for?
- Startups blocked on a deal: teams whose enterprise prospect or procurement department requires ISO 27001 or SOC 2 before signing.
- MSPs and consultants: advisors running compliance programmes for several clients who need one workspace per client without enterprise seat licences.
- Budget-conscious teams: organisations that received five-figure GRC quotes for integrations they did not want touching production systems.
What can you do with CertAssist?
- Get audit-ready: work controls from scope agreed through stage 2 audit with milestone tracking and gap-closing registers.
- Report to the board: share a readiness dashboard with a forecast completion date and progress history.
- Hand off to an auditor: grant scoped read-only access instead of sending a folder of screenshots.
- Run multi-client compliance: isolate each client's evidence per assessment so a client user only sees their own data.
How does CertAssist work?
- Day one: pick your framework — every control is laid out ready to work through, nothing to configure.
- Weeks 1–6: work the controls using per-control guidance, an evidence checklist and a place to store evidence.
- Weeks 6–10: close gaps using the risk, supplier, legal, non-conformity and ISO 27001 maintenance registers.
- Audit: give your auditor read-only access to a workspace built the way they read an audit.
Pricing
CertAssist is a paid subscription at $225 per month, or $2,475 per year (twelve months for the price of eleven), in USD. Every framework, unlimited team members and auditor accounts, all six registers and the reporting dashboard are included, with no add-ons. You can cancel any time and export your data whenever you want.
FAQ
Does CertAssist integrate with my cloud and identity systems?
No. CertAssist deliberately has no integrations, so nothing connects to your production systems and there is no vendor holding keys to production. Evidence is uploaded manually instead, which is slower on day one but reduces attack surface.
Will my auditor accept a CertAssist workspace?
The workspace is laid out the way auditors read an audit: control, requirement, status, evidence and owner. Auditors receive read-only access scoped to the assessment rather than a folder of screenshots, and the product w