56 of the 93 Annex A controls enforced and evidenced, and 66 of the standard's 223 clauses.
The standard has two halves. The management system, clauses 4 to 10, is scope, leadership, risk process, internal audit and management review, and it is predominantly process and judgement. The other half is Annex A, 93 controls, and that is where a platform carries the load or does not. Akku enforces and evidences 56 of them.

Annex A divides into four themes, and Akku's weight is where you would expect it.
The six in the physical theme are device and media controls: working in secure areas, clear desk and clear screen, security of assets off-premises, storage media, equipment maintenance, and secure disposal or reuse of equipment.
Of the 237 actionable requirements in the standard, 113 can be addressed by a system rather than by a person. Akku covers 67 of them. The next system on the list is a document management system at 20, and no security product on the list covers more than 2. Covering the rest means 18 separate platforms.
Several clauses are supported by more than one module, which is why these add to 186 mapping points across 66 clauses.
| Module | Clauses | Count |
|---|---|---|
| DLP | 6.1.2 c) 1), 6.1.3 d), 6.2 d), 7.5.3 b), 7.5.3 c), 8.1, 8.3, 9.1, 9.3.2 d) 2), 9.3.2 d) 4), A.5.1, A.5.7, A.5.9, A.5.10, A.5.12, A.5.13, A.5.14, A.5.23, A.5.25, A.5.26, A.5.28, A.5.29, A.5.31, A.5.32, A.5.33, A.5.34, A.5.36, A.6.4, A.6.7, A.7.6, A.7.7, A.7.9, A.7.10, A.8.1, A.8.3, A.8.4, A.8.7, A.8.12, A.8.15, A.8.16, A.8.20, A.8.23, A.8.24, A.8.25, A.8.28, A.8.33 | 46 |
| UEM | 6.1.3 d), 6.2 d), 8.1, 8.3, 9.1, 9.3.2 d) 2), 9.3.2 d) 4), A.5.1, A.5.7, A.5.9, A.5.10, A.5.11, A.5.14, A.5.25, A.5.26, A.5.28, A.5.29, A.5.32, A.5.36, A.6.7, A.7.6, A.7.7, A.7.9, A.7.10, A.7.13, A.7.14, A.8.1, A.8.7, A.8.8, A.8.9, A.8.10, A.8.15, A.8.16, A.8.19, A.8.20, A.8.23, A.8.24, A.8.32 | 38 |
| IAM | 6.1.3 d), 6.2 d), 8.1, 8.3, 9.1, 9.3.2 d) 2), 9.3.2 d) 4), A.5.1, A.5.3, A.5.7, A.5.11, A.5.15, A.5.16, A.5.17, A.5.18, A.5.19, A.5.22, A.5.23, A.5.25, A.5.26, A.5.28, A.5.33, A.6.7, A.8.1, A.8.2, A.8.3, A.8.4, A.8.5, A.8.15, A.8.16, A.8.18, A.8.24, A.8.25, A.8.31, A.8.34 | 35 |
| IGA | 6.1.3 d), 6.2 d), 8.1, 8.3, 9.1, 9.3.2 d) 2), 9.3.2 d) 4), A.5.3, A.5.9, A.5.11, A.5.15, A.5.16, A.5.18, A.5.19, A.5.22, A.5.23, A.5.28, A.8.2, A.8.3, A.8.4, A.8.15, A.8.25, A.8.31 | 23 |
| MDM | 6.1.3 d), 6.2 d), 8.1, 8.3, 9.1, 9.3.2 d) 2), 9.3.2 d) 4), A.5.1, A.5.9, A.5.10, A.5.11, A.5.26, A.5.36, A.6.7, A.7.6, A.7.9, A.7.14, A.8.1, A.8.9, A.8.10, A.8.15, A.8.32 | 22 |
| PAM | 6.1.3 d), 8.1, 8.3, 9.1, 9.3.2 d) 2), A.5.17, A.5.19, A.5.22, A.5.26, A.5.28, A.5.29, A.8.2, A.8.5, A.8.15, A.8.16, A.8.18, A.8.20, A.8.24, A.8.31, A.8.34 | 20 |
Each control produces a named report rather than a screenshot taken the week before the audit. The SSO Activity Report covers A.5.15, A.5.23, A.8.4 and A.8.15. The Access Recertification Report covers A.5.16, A.5.18 and A.5.22 alongside four management-system clauses. The Audit Log Export covers ten, from A.5.28 through A.8.32. Twenty-six of Akku's reports carry ISO clause mappings, each with fixed columns and a date range you set.
Ask us for the full clause-level mapping against your Statement of Applicability.
The certificate lasts three years and the controls have to still work in year two. Surveillance audits find drift: a review cycle that slipped, or a leaver whose access stayed open.
Akku Cybersecurity Solutions is itself certified to ISO/IEC 27001.