Spreadsheets are how almost every ISMS starts, and how most audit findings happen. Where they work, where they break, and when to switch.
Almost every small-business ISMS starts life as a spreadsheet, and for good reason: spreadsheets are free, familiar and flexible. We built ISOvault after years of running ISO 27001 this way, so this comparison is written with respect for the spreadsheet era, and clear eyes about where it breaks.
| Spreadsheets and shared drives | ISOvault | |
|---|---|---|
| Cost | Free, plus significant admin time | £125/month + VAT, price for life |
| Cross-referencing | Manual links between controls, risks, assets and suppliers that break silently when anything changes | Records are linked in a database; change a supplier and every dependent risk and control updates its references |
| Version control | Filename suffixes: v2_FINAL_revised | Every version approved by a named person, dated and retained |
| Audit trail | File timestamps, and whatever anyone remembers | Every change and approval logged and exportable |
| Review reminders | Whoever remembers to check the tracker | Automatic reminders at 90, 60 and 30 days |
| Audit preparation | Days of pulling evidence from inboxes and drives | Evidence linked to controls; audit prep is a report |
| Multiple editors | Conflicting copies, overwritten cells | One workspace with per-user permissions |
| Auditor output | Native Word and Excel, but assembled by hand | Word documents generated from your live data |
If you are pre-certification, exploring whether ISO 27001 is worth pursuing, start with spreadsheets; our free templates exist for exactly that. The switching point comes when the ISMS is real: multiple people maintaining records, an audit on the calendar, and the cross-referencing between documents starting to rot.
The failure mode is never dramatic. A supplier changes, the risk register is updated, but the SoA and the asset register are not. Eighteen months later an auditor asks why the risk register references a supplier the register says was offboarded, and the answer costs you a finding and a weekend. Spreadsheets do not enforce consistency; software can.
Yes. Upload your existing risk register, asset list and supplier list and ISOvault structures them and links them to the 93 Annex A controls.
No. ISOvault generates the Statement of Applicability, risk register and supplier register as Word documents, because that is what auditors want to review.
Import your existing ISMS into ISOvault, run the AI gap analysis and generate your Statement of Applicability. 14 days free, no card required, walk away with the Word documents.