
We're currently working towards our ISO 27001 certification with Scytale guiding us through the process. What I like best are the task list and the policy templates.
The task list gives us clear direction. Instead of trying to work out what the standard requires and in which order, we can see exactly which steps come next and track our progress towards audit readiness. That keeps the project manageable alongside our day-to-day work.
The policy templates are a huge time saver. We don't have to reinvent the wheel and write every policy from scratch. We start from a solid, well-structured base and tailor it to our own organisation. That lets us spend our time on actually implementing the controls rather than on drafting documents. Review collected by and hosted on G2.com.
What I miss is a high-level overview that helps us prioritise the action items. The task list tells us what needs to be done, but it's not always clear which items matter most or which ones should come first. The Scytale team does help us with this, but sometimes the advice is simply to work through the list from A to Z. That can feel arbitrary, especially for a small team that wants to spend its limited time on the items with the biggest impact on security and audit readiness first.
A roadmap or dashboard view that groups tasks by priority, risk or dependency would make it much easier to plan our work and explain progress to management. Review collected by and hosted on G2.com.