Skip to content

Implementing ISO 27001 without a dedicated tool: what are the limitations compared with a specialized platform?

Why does managing ISO 27001 become challenging in practice?

Obtaining ISO 27001 certification involves documenting dozens of processes, monitoring risks over time, and providing evidence that the Information Security Management System (ISMS) is actually working in practice. Many organizations start this process using the tools they already have at their disposal: an Excel spreadsheet with multiple tabs, a shared calendar for deadlines, and a few shared folders for documentation.

This approach may work for a while, particularly during the initial implementation of the ISMS. However, as soon as the program needs to operate across all stakeholders and its various activities, the limitations become increasingly difficult to ignore.

Can ISO 27001 really be managed with Excel and a calendar?

In practice, yes — at least initially. But experience shows that this type of setup is difficult to maintain over time. Multiple files eventually circulate in parallel, versions diverge, and no one knows exactly who changed what or when. Deadline reminders have to be managed manually, increasing the risk of missing important actions. Above all, a spreadsheet cannot centralize supporting evidence or provide granular access management based on each person’s role (owner, approver, auditor).

These are precisely the elements — traceability, change history and access management — that ISO 27001 auditors examine closely. An ISMS based on scattered files is harder to defend during an audit, even when the underlying documentation is technically correct.

Why does Data Guardians only carry out tool-supported implementations?

At Data Guardians, we have made a clear choice: we no longer support ISO 27001 implementations without a dedicated platform. This is not a matter of principle, but rather the result of hands-on experience. We have seen too many organizations spend months working with Excel files that eventually become unmanageable, with outdated risk assessments, scattered audit evidence and a monitoring workload that falls on a single person who is often already overwhelmed.

A specialized tool changes the equation: it centralizes document management and monitoring, automates deadline management, records every action in an audit trail and provides a real-time overview. This is what turns a compliance requirement into a genuinely managed system.

What is the DGRC platform and why is it suited to ISO 27001?

DGRC is the governance, risk and compliance platform operated by Data Guardians. It was designed from the outset to support frameworks such as ISO 27001, NIST, the Swiss FADP (LPD), the GDPR and the Cyber-Safe label, while also adapting to an organization’s own management system.

In practical terms, DGRC provides a dashboard with customizable indicators, a structured risk analysis engine, and detailed activity management, with owners and approvers assigned to each task. Every document, decision and change remains traceable and accessible over time — exactly what an ISO 27001 auditor needs to verify.

What areas does DGRC cover?

The strength of DGRC lies in its modular and scalable architecture. The platform adapts to an organization’s level of maturity rather than imposing a single way of working:

The first level provides the foundation: it enables organizations to define and track security objectives, consolidate audit results, manage security routines and monitor key performance indicators.

The second level builds on this foundation with a structured view of the organization’s resources: asset inventory, supplier inventory, document inventory and risk assessments.

The third level completes the solution with features dedicated to demonstrating compliance and driving continuous improvement: Swiss FADP/GDPR compliance, ISO 27001 compliance, ISO 42001 compliance and Cyber-Safe label compliance, implementation of Privacy & Security by Design principles, exception registers, incident and non-conformity management, as well as continuous improvement management.

This tiered approach allows an organization to start simply and then expand its use of the platform as its security program matures, without ever having to change tools.

Do you still need Excel once DGRC is in place?

No. Once the platform has been deployed, spreadsheets and other generic project management tools no longer need to be used to manage ISO 27001 compliance. Everything they were previously trying to handle in a fragmented way — task tracking, inventories, document management and reporting — is natively centralized in DGRC, with the added traceability and access management capabilities that these tools lacked.

What are the risks of implementing ISO 27001 alone, without experience or a dedicated tool?

This is often where the difficulties begin. An organization embarking on ISO 27001 alone, without having previously managed this type of project and without a tool to structure it, faces two challenges simultaneously: it has to understand the requirements of the standard while implementing them, and it is doing so with monitoring and management tools that are not suited to the actual workload involved.

In this context, several recurring pitfalls tend to emerge:

  • Documentation is produced but never updated, which becomes apparent as soon as the first surveillance audit takes place;
  • Risk assessments are carried out once and then abandoned due to the lack of a review process;
  • A person is appointed as project manager without having either the practical experience or the theoretical knowledge required;
  • There is a gap between what the organization believes it has implemented and what it can actually demonstrate to the auditor.

This is precisely the type of situation our consulting approach aims to prevent. Our consultants have led numerous certification projects and understand the actual expectations of certification bodies. If your team is preparing to embark on this journey alone, discussing your plans with us beforehand can often help you avoid months of rework. We would be happy to discuss your project with you; contact us to get in touch.

Is DGRC recognized by auditors in French-speaking Switzerland?

Yes. The platform is now well known among auditors operating in French-speaking Switzerland, which facilitates discussions during certification audits. The existence and relevance of the various modules, the structure of the evidence and the traceability of decisions are familiar to them, helping to streamline the overall audit process.

Can DGRC be connected to existing security tools?

Yes. DGRC can be integrated with various security tools used by organizations, including the Microsoft ecosystem, which is widely used by Swiss companies. These integrations make it possible to automatically feed certain information into the platform instead of entering it manually, reducing administrative workload and limiting tracking errors.

Should you choose SaaS or on-premises deployment?

Both options are available. DGRC can be used in SaaS mode, hosted by Data Guardians in highly available Swiss data centers, or installed directly within the client’s infrastructure for organizations that want to retain control over the hosting of their data.

In both cases, the platform’s security is built on the same foundations: encryption of data at rest and in transit, two-factor authentication, single sign-on (SSO), automated daily backups and regular penetration testing carried out by independent experts. DGRC is also developed by a company that is itself ISO 27001 certified, ensuring that these security standards are applied from the very design stage of the platform.

In summary

Managing an ISO 27001 program with Excel and a calendar does not allow an organization to effectively build and continuously improve its ISMS, as this approach will quickly reach its limits: lack of traceability, limited access management and scattered documentation.

A platform such as DGRC addresses these limitations through a modular and scalable architecture, recognized by auditors, integrable with your existing tools and available both as a SaaS solution and for on-premises hosting.

If you are considering ISO 27001 certification, request a demo to see how DGRC and Data Guardians’ consulting support can structure your project from the outset.

Share this article:

Privacy Policy Summary

This site uses cookies so that we can provide you with the best possible user experience. Cookie information is stored in your browser and performs functions such as recognizing you when you return to our website and helping our team understand which sections of the site you find most interesting and useful.

To learn more, please see our privacy policy.