Evidence: Completed check record, dated before the start date
For the person who was handed ISO 27001
Compliance built on how you already work
An Treoraí starts from your business processes, not a list of 93 controls. Describe the way you hire, deploy and respond to incidents, and the requirements attach themselves to the steps, so evidence gathered once counts towards ISO 27001, SOC 2, GDPR and your other frameworks at the same time.
Enter your website and An Treoraí reads your public pages to draft a starting point. The full, editable analysis runs when you create your account.
- No compliance experience needed
- You approve every suggestion
- Public information only
You will not start from an empty screen
An Treoraí reads what your organisation already says publicly and drafts a starting point for you to correct, keep or discard.
- Business context
- Interested parties
- Likely priorities
- Relevant frameworks
- Initial scope
- First action
From first login to audit day
Five steps, in the order you will actually take them
Most people arrive having been told to “get us certified” and given no budget for a consultant. This is the path through.
Set your starting point
Confirm your context, scope and the people your decisions affect. An Treoraí drafts it; you correct it.
Map how you work
Walk through your real processes, hiring, access, deployment, suppliers and incidents, step by step.
See what's missing
Requirements attach to steps. Gaps appear as missing steps in a process, not as failed checkboxes.
Close gaps with guidance
Each task explains why it exists, roughly how long it takes and what it updates when you finish.
Stay ready between audits
Running the process produces the evidence. Reviews, reminders and records keep the trail current.
Processes first, frameworks as overlays
A policy nobody follows still fails the audit
Most tools ask you to implement controls and hope the business follows. An Treoraí inverts it: describe the process once, and requirements from every framework attach to the steps that satisfy them. Select a step to see what it proves.
Screening before the offer is confirmed is the evidence four different frameworks are asking for.
Evidence: Screening standard plus a sample of completed checks
Evidence: Role definition and screening record
Evidence: Verified identity held against the personnel record
The same six steps also generate your Statement of Applicability entries, your training records and your access-review trail.
One clear action at a time
You always know what to do next
Every task says why it exists, roughly how long it takes and exactly what it updates when you finish. No dashboard of 93 amber squares.
- Plain language instead of clause numbers you have to decode.
- One next action instead of a wall of partial progress.
- Controls, evidence and framework coverage update together.
Your next action
Check who can reach your production systems
Confirm that the people with access still need it, and that leavers were removed. An Treoraí has pre-filled the list from your last review.
Start the reviewDo it once, prove it everywhere
Add the evidence once. It answers every framework that asks.
Attach a quarterly access review to one control and An Treoraí connects it to each requirement it satisfies, including the security questionnaires your customers send you.
No duplicated spreadsheets. No starting again when a customer asks for SOC 2.
| Connected requirement | Framework | Coverage |
|---|---|---|
| Review of access rights | ISO 27001 · A.5.18 | Covered |
| Logical access is reviewed | SOC 2 · CC6.3 | Covered |
| Identities are managed | NIST CSF · PR.AA | Covered |
| ICT access management | DORA · Art. 9 | Covered |
| Security of processing | GDPR · Art. 32 | Covered |
Who this is built for
You did not ask for this. You still have to deliver it.
An Treoraí is made for the person who was given certification on top of an existing job, and works just as well for a team consolidating programmes that have grown apart.
Starting from nothing
First framework, no prior experience
Begin with a drafted starting point, learn each concept at the moment you need it, and work through a sequence that ends in an audit you can pass.
Get early accessAlready running a programme
Several frameworks, one set of evidence
Bring existing controls, policies and evidence across, map them to the processes that produce them, and stop maintaining the same proof in four places.
Create your accountTransparent by design
Clear enough to trust
Suggestions should make the first hour easier without hiding how a conclusion was reached. You are the one who signs the Statement of Applicability.
Every suggestion names the page or statement it came from.
Uncertain inferences are marked as uncertain, not smoothed over.
Nothing enters your programme until you keep it.
Straight answers
Before you sign up
Here is exactly where An Treoraí stands.
The process library, control catalogue, risk register, policy and management reviews, evidence, audits and reporting are built and in use. The instant analysis above is live: it reads your public pages to draft a starting point, and the full, editable version runs once you create your account.
Because a control marked "done" in a spreadsheet does not change what anyone does on Monday. When requirements sit on the steps of a process you actually run, following the process produces the evidence, and an auditor can watch it happen rather than read about it.
Auditors work clause by clause and control by control, so An Treoraí keeps both views live at once. Your team works in processes; the audit view presents the same information as Annex A controls and management-system clauses, with the evidence attached to each.
ISO 27001:2022 is fully mapped today. SOC 2, GDPR, DORA, NIS2, ISO 22301, the NIST Cybersecurity Framework and ISO 14001 are supported through shared controls, so evidence you add once counts towards each one that asks for it. You can also track a customer’s own security requirements alongside them.
Every task carries an estimate, and the roadmap totals them so you can see the commitment before you start rather than three months in. Most first-time programmes need a steady few hours a week over several months, and An Treoraí tells you honestly if your target date does not fit the hours available.
Early access
Start with the work you already do
Enter your website and we will prepare your starting point, context, interested parties, likely priorities and a first process to map, then walk you through it.
How the analysis works
A starting point you can check
When you begin, An Treoraí reads the pages your organisation already publishes, what you do, who you serve, where you operate and any security or privacy statements, and drafts a first version of your context, interested parties and likely priorities.
- Only publicly available pages are read. An Treoraí never signs in to your systems as part of this step.
- Each suggestion names its source page and carries a confidence level.
- You keep, edit or discard every item. Nothing enters your programme automatically.
- If your site says little, An Treoraí asks a few focused questions instead of guessing.
- Page content used for the analysis is retained only while you review it, then discarded.