Casestudy
How PlantNXT Achieved
ISO 27001:2022 Certification with Structured Evidence Management

Industry
AI Service
PlantNXT overcame one of the biggest ISO 27001 certification challenges: collecting the right evidence from the right teams at the right time. With WhizzC, PlantNXT created a structured evidence-management process, coordinated stakeholders and successfully achieved ISO/IEC 27001:2022 certification.
Quick answer: How did PlantNXT achieve ISO 27001 certification?
PlantNXT achieved ISO/IEC 27001:2022 certification by working with WhizzC to map controls to its real operating practices, identify the evidence required for each control, coordinate evidence owners and review submissions before the audit. Strong participation from PlantNXT’s leadership and operational teams helped keep decisions, clarifications and certification activities moving.
About PlantNXT
PlantNXT is an industrial SaaS and plant operations technology company. As its operations and customer expectations grew, the company needed a structured information security management system that could demonstrate how security controls worked in practice, not only how they were documented.
ISO/IEC 27001:2022 certification would give customers and stakeholders independent assurance that PlantNXT followed a systematic approach to managing information security risks.
The challenge: ISO 27001 evidence was spread across people and processes
Understanding the ISO 27001 requirements was only the beginning. PlantNXT also had to prove that its controls were implemented and operating consistently.
That meant collecting relevant evidence from different teams, connecting each submission to the correct control and resolving missing or unsuitable documentation before the certification audit.
Without a coordinated process, common problems could have slowed the journey:
Evidence owners may not know exactly what an auditor expects.
Documents can be distributed across teams, inboxes and systems.
A submitted file may exist but may not adequately prove that a control operates.
Clarifications can remain blocked when ownership is unclear.
Gaps discovered late can place the certification schedule at risk.
PlantNXT needed more than a checklist. It needed a clear evidence workflow with ownership, review and regular follow-up.
Why evidence collection matters in an ISO 27001 audit
An ISO 27001 auditor does not assess policies alone. The organisation must also demonstrate that its information security management system is implemented and operating.
Depending on the control and scope, evidence may include access reviews, risk assessments, training records, incident procedures, vendor assessments, policy approvals, asset records and operational logs. The evidence must be relevant, current and connected to the organisation’s actual way of working.
For PlantNXT, the challenge was therefore not simply creating more documents. It was ensuring that the right evidence reached the right control and was reviewed before the audit.
The solution: A structured evidence-readiness process with WhizzC
WhizzC worked alongside PlantNXT to turn evidence collection into a managed certification workflow.
1. Mapping controls to real operating practices
Instead of relying on generic templates alone, WhizzC helped connect ISO 27001 requirements to PlantNXT’s existing teams, systems and processes. This made it clearer where controls already existed and where further action was required.
2. Defining the evidence required
For each applicable control, the teams identified what evidence was needed, who owned it and what an audit-ready submission should demonstrate. This reduced uncertainty for stakeholders responsible for providing documents and records.
3. Assigning ownership and coordinating stakeholders
PlantNXT treated certification as an organisation-wide priority rather than a side project owned by one person. Its single point of contact, operational stakeholders and leadership team remained engaged throughout the process.
This involvement helped WhizzC obtain clarifications quickly and kept open actions from remaining blocked.
4. Reviewing evidence before the audit
WhizzC reviewed evidence for relevance and readiness before it became part of the audit process. Missing context, outdated records and control gaps could therefore be identified earlier, when there was still time to address them.
5. Maintaining a steady certification rhythm
Structured follow-ups gave the teams visibility into completed, pending and blocked activities. PlantNXT could focus attention on priority items instead of relying on a last-minute evidence chase.
The outcome: ISO 27001:2022 certification achieved
PlantNXT successfully achieved ISO/IEC 27001:2022 certification.
Across an estimated 4–6-month readiness journey, WhizzC helped coordinate approximately 8–12 stakeholders and organise more than 150 evidence items. The structured approach helped the teams surface documentation gaps early, respond to clarifications faster and maintain momentum through the certification audit.
PlantNXT’s contribution was central to the result. Active participation from its SPOC, operational teams and leadership enabled faster decisions and helped prevent evidence requests from becoming prolonged bottlenecks.
The engagement was also recognised by PlantNXT, reflecting a partnership that extended beyond completing a checklist.
“WhizzC helped us bring structure to our ISO 27001 evidence process, coordinate stakeholders and stay prepared throughout the certification journey.”
What other SaaS companies can learn from PlantNXT
PlantNXT’s experience demonstrates that successful ISO 27001 certification depends on three practical habits:
Give every control and evidence request a clear owner. Shared responsibility without ownership usually creates delays.
Review evidence before the audit. A document is not automatically valid evidence simply because it exists.
Keep leadership involved. Timely decisions and escalations are essential when certification work crosses several teams.
The most effective certification programmes make evidence collection part of ongoing operations rather than a one-time activity performed immediately before an audit.