Identity & Access Management capability of SimpliKeys (SK), mapped to the IAM-relevant Annex A controls
Reference version: ISO/IEC 27001:2022 (incl. Amd 1:2024) · Prepared mid-2026 · Capability mapping, not a compliance attestation
Coverage of the 14 IAM-relevant controls
ISO/IEC 27001:2022 is the current edition (incorporating Amendment 1:2024 on climate action, which does not affect the IAM controls). The 2013 edition was withdrawn on 31 October 2025, so all certified organisations are now on the 2022 edition. There is no 2026 edition.
The IAM-relevant Annex A controls — access control, identity and authentication, privileged access, and the access-related logging and monitoring controls. This is NOT a full ISO 27001 mapping: the ISMS clauses (4-10) and the many non-IAM Annex A controls are out of scope here. Annex A controls are selected for your environment through your risk assessment and Statement of Applicability.
SimpliKeys is a single unified platform: the capabilities described below are facets of one system applied to each control, not separate products. It protects every identity with the same vaulting, brokering and session recording, and applies strong authentication from a configurable spectrum of factors that can be targeted per system, chained, and stepped up within a session.
Every rating below holds only to the extent of two things: (1) breadth — the scope of the environment SimpliKeys is protecting; a control is supported only where SimpliKeys sits in the access path, not for systems outside its reach; and (2) depth — how SimpliKeys is configured. The analysis assumes SimpliKeys is deployed and configured as the central authentication manager for the in-scope environment.
Entries describe summarised SimpliKeys capability under common circumstances and when appropriately configured. They do not represent verified or certified behaviour.
ISO 27001 certifies the information security management system (ISMS) as a whole — its Clauses 4-10 and the controls selected in your Statement of Applicability — not any single tool. SimpliKeys can support specific Annex A controls when appropriately configured, but it cannot make an organisation 'ISO 27001 certified.' Treat every 'Supports' as 'capability provided when appropriately configured.'
Supports
SimpliKeys provides the capability that meets this control when appropriately configured; configuration to the applicable thresholds and implementation still apply.
Partial
SimpliKeys addresses part of this control; full compliance needs additional measures, or depends on coverage or architecture beyond SimpliKeys alone.
Assists
SimpliKeys does not perform this control (it is organisational or process), but supplies information, logs, visibility, or evidence that makes it easier to complete or to demonstrate.
Out of scope / N/A
Outside SimpliKeys’ role — purely organisational, or not applicable to SimpliKeys (e.g., applies only to third-party service providers).
Filter by coverage
Conflicting duties and areas of responsibility are separated.
What SimpliKeys does
Enforces access by policy, so it can block a role from accessing an application where that access would itself breach a segregation-of-duties rule.
Customer responsibility & notes
SimpliKeys enforces SoD at the access-to-application layer. SoD within an application (conflicting transactions or actions) is the application's function unless SimpliKeys is fed application-level data and configured for it; the customer owns that configuration and the SoD ruleset.
Rules for physical and logical access are established and enforced by business and security need.
What SimpliKeys does
Is the access-control system: authenticates every request and enforces access by policy across the environment from one platform.
Customer responsibility & notes
Logical access; physical access is outside SimpliKeys. Customer defines the access rules and the assets in scope.
The full lifecycle of identities is managed with unique identification.
What SimpliKeys does
Governs the full identity lifecycle for every identity — person, non-human identity, or AI agent — with unique identification.
Customer responsibility & notes
Customer connects the identity sources and defines lifecycle rules; SimpliKeys issues and manages unique identities, including non-human and AI-agent identities.
Allocation and management of authentication information is controlled.
What SimpliKeys does
Allocates and protects authentication information, holding credentials and secrets in a vault and enforcing issuance, rotation and policy.
Customer responsibility & notes
Customer sets the credential and secret policies to its standard.
Access rights are provisioned, reviewed, modified and removed per the access-control policy.
What SimpliKeys does
Provisions, reviews, modifies and revokes access rights, and runs periodic access-review/certification campaigns from one console.
Customer responsibility & notes
Customer schedules the reviews and approves changes; SimpliKeys provisions, de-provisions and recertifies.
Security responsibilities and access remain enforced after a change.
What SimpliKeys does
Revokes access on termination or role change, driven by joiner/mover/leaver events from connected HR and source systems.
Customer responsibility & notes
SimpliKeys covers the access-revocation part. Confidentiality obligations, asset return and the HR process are organisational and remain the customer's.
Information is protected when personnel work remotely.
What SimpliKeys does
Authenticates and monitors remote access under one policy, with step-up and session recording.
Customer responsibility & notes
SimpliKeys covers remote-access authentication and monitoring; endpoint security, the working environment and broader policy remain the customer's.
Allocation and use of privileged access is restricted and managed.
What SimpliKeys does
Applies the same policy-based access control to privileged access, with the vaulting, brokering and session recording it applies to every identity.
Customer responsibility & notes
Customer identifies privileged accounts and access paths in scope; SimpliKeys vaults, brokers and records them.
Access to information and assets is restricted per the access-control policy (least privilege).
What SimpliKeys does
Enforces least-privilege access to information and assets by policy at the access layer.
Customer responsibility & notes
Customer designs the least-privilege policy. Restrictions internal to an application or data store are configured by the customer at that layer.
Read and write access to source code, development tools and libraries is managed.
What SimpliKeys does
Controls access to source-code repositories and development tools as the central authentication manager fronting them.
Customer responsibility & notes
SimpliKeys governs access to the repositories; in-repository controls (branch protection, review gates) remain the SCM tool's. Customer brings the repositories into SimpliKeys' path.
Secure authentication technologies and procedures are implemented per access restrictions.
What SimpliKeys does
Applies strong authentication from a configurable spectrum of factors — targetable per application or system, chainable, and able to step up within a session to an additional factor such as FIDO2 or biometric when a more sensitive activity begins.
Customer responsibility & notes
Customer selects the factors and the per-system authentication policy.
Logs of activities, exceptions, faults and relevant events are produced, stored and protected.
What SimpliKeys does
Records identity and access activity — every action taken on the network by any identity, whether person, non-human identity or AI agent — with session recording and device, location and keystroke detail, and forwards it to SIEM.
Customer responsibility & notes
SimpliKeys produces the identity/access logs; their long-term storage, integrity and protection across the wider environment remain the customer's.
Networks, systems and applications are monitored for anomalous behaviour and potential incidents.
What SimpliKeys does
Monitors all actions taken by any identity on the network — person, non-human identity or AI agent — with behavioural analytics and the ability to shut down a compromised session immediately.
Customer responsibility & notes
Strong fit for identity-centric monitoring across all identity types. Pure network/packet or application-internal monitoring may still use other tooling.
Utility programs that can override controls are restricted and tightly controlled.
What SimpliKeys does
Governs and records the privileged access and sessions through which such utilities are reached, brokering and recording that access.
Customer responsibility & notes
SimpliKeys controls and records the privileged access path; restricting which specific utility programs may run on a target host is a host-level control the customer owns.
Mapping reflects ISO/IEC 27001:2022 (incl. Amd 1:2024) as understood in mid-2026, reviewed control-by-control with SimpliKeys. Control text is paraphrased from Annex A, not quoted. 'Supports' = capability provided when appropriately configured; the customer configures, documents and operates its deployment, and selects applicable controls via its Statement of Applicability. Confirm against your environment and your certification body before relying on it.
30 minutes against a real environment — we’ll walk your controls line by line.
Book demo