For the person who was handed ISO 27001

Compliance built on how you already work

An Treoraí starts from your business processes, not a list of 93 controls. Describe the way you hire, deploy and respond to incidents, and the requirements attach themselves to the steps, so evidence gathered once counts towards ISO 27001, SOC 2, GDPR and your other frameworks at the same time.

Enter your website and An Treoraí reads your public pages to draft a starting point. The full, editable analysis runs when you create your account.

  • No compliance experience needed
  • You approve every suggestion
  • Public information only
Starting analysisReads your public site

You will not start from an empty screen

An Treoraí reads what your organisation already says publicly and drafts a starting point for you to correct, keep or discard.

  • Business context
  • Interested parties
  • Likely priorities
  • Relevant frameworks
  • Initial scope
  • First action
Public pages onlyThe analysis reads published pages. It never signs in to your systems.
Suggestions, not decisionsEvery item shows the page it came from and how confident the reasoning is.
Nothing lands without youKeep, edit or discard each suggestion before it enters your workspace.

From first login to audit day

Five steps, in the order you will actually take them

Most people arrive having been told to “get us certified” and given no budget for a consultant. This is the path through.

  1. Set your starting point

    Confirm your context, scope and the people your decisions affect. An Treoraí drafts it; you correct it.

  2. Map how you work

    Walk through your real processes, hiring, access, deployment, suppliers and incidents, step by step.

  3. See what's missing

    Requirements attach to steps. Gaps appear as missing steps in a process, not as failed checkboxes.

  4. Close gaps with guidance

    Each task explains why it exists, roughly how long it takes and what it updates when you finish.

  5. Stay ready between audits

    Running the process produces the evidence. Reviews, reminders and records keep the trail current.

Processes first, frameworks as overlays

A policy nobody follows still fails the audit

Most tools ask you to implement controls and hope the business follows. An Treoraí inverts it: describe the process once, and requirements from every framework attach to the steps that satisfy them. Select a step to see what it proves.

Process · Joining the organisationOwner: People team
What this step proves4 requirements · 4 frameworks

Screening before the offer is confirmed is the evidence four different frameworks are asking for.

A.6.1ISO 27001:2022
Screening

Evidence: Completed check record, dated before the start date

CC1.4SOC 2
Competent individuals are recruited and retained

Evidence: Screening standard plus a sample of completed checks

Art. 32(4)GDPR
Persons with access act only on instruction

Evidence: Role definition and screening record

PR.AA-01NIST CSF 2.0
Identities are established for authorised personnel

Evidence: Verified identity held against the personnel record

One step. One piece of evidence. Every framework that asks for it.

The same six steps also generate your Statement of Applicability entries, your training records and your access-review trail.

One clear action at a time

You always know what to do next

Every task says why it exists, roughly how long it takes and exactly what it updates when you finish. No dashboard of 93 amber squares.

  • Plain language instead of clause numbers you have to decode.
  • One next action instead of a wall of partial progress.
  • Controls, evidence and framework coverage update together.
Today in An TreoraíRoadmap · 38% complete

Your next action

Check who can reach your production systems

Confirm that the people with access still need it, and that leavers were removed. An Treoraí has pre-filled the list from your last review.

  • 4 questions
  • About 6 minutes
  • Guidance included
Start the review
Control recordUpdated on completion
Evidence fileSaved and dated
Framework coverageRecalculated

Do it once, prove it everywhere

Add the evidence once. It answers every framework that asks.

Attach a quarterly access review to one control and An Treoraí connects it to each requirement it satisfies, including the security questionnaires your customers send you.

No duplicated spreadsheets. No starting again when a customer asks for SOC 2.

Quarterly access reviewControl · IAM-04Evidence added once: Q2 access review
Requirements satisfied by a single access review record
Connected requirementFrameworkCoverage
Review of access rightsISO 27001 · A.5.18Covered
Logical access is reviewedSOC 2 · CC6.3Covered
Identities are managedNIST CSF · PR.AACovered
ICT access managementDORA · Art. 9Covered
Security of processingGDPR · Art. 32Covered

Who this is built for

You did not ask for this. You still have to deliver it.

An Treoraí is made for the person who was given certification on top of an existing job, and works just as well for a team consolidating programmes that have grown apart.

Already running a programme

Several frameworks, one set of evidence

Bring existing controls, policies and evidence across, map them to the processes that produce them, and stop maintaining the same proof in four places.

Create your account

Transparent by design

Clear enough to trust

Suggestions should make the first hour easier without hiding how a conclusion was reached. You are the one who signs the Statement of Applicability.

Sourced

Every suggestion names the page or statement it came from.

Confidence shown

Uncertain inferences are marked as uncertain, not smoothed over.

Approved by a person

Nothing enters your programme until you keep it.

Straight answers

Before you sign up

Here is exactly where An Treoraí stands.

The process library, control catalogue, risk register, policy and management reviews, evidence, audits and reporting are built and in use. The instant analysis above is live: it reads your public pages to draft a starting point, and the full, editable version runs once you create your account.

Because a control marked "done" in a spreadsheet does not change what anyone does on Monday. When requirements sit on the steps of a process you actually run, following the process produces the evidence, and an auditor can watch it happen rather than read about it.

Auditors work clause by clause and control by control, so An Treoraí keeps both views live at once. Your team works in processes; the audit view presents the same information as Annex A controls and management-system clauses, with the evidence attached to each.

ISO 27001:2022 is fully mapped today. SOC 2, GDPR, DORA, NIS2, ISO 22301, the NIST Cybersecurity Framework and ISO 14001 are supported through shared controls, so evidence you add once counts towards each one that asks for it. You can also track a customer’s own security requirements alongside them.

Every task carries an estimate, and the roadmap totals them so you can see the commitment before you start rather than three months in. Most first-time programmes need a steady few hours a week over several months, and An Treoraí tells you honestly if your target date does not fit the hours available.

Early access

Start with the work you already do

Enter your website and we will prepare your starting point, context, interested parties, likely priorities and a first process to map, then walk you through it.

Public information only · You approve every suggestion · No card required

Get early access