I am implementing ISO 27001 in the company I work for, but the spreadsheet created by the consultancy that serves us is more based on ISO 9001 than for ISO 27001, is there another way to document this item, or would it be basically like ISO 9001?
I understand that you are referring to the list of legal requirements for ISO 27001.
Considering that, although the type of information to be gathered to fulfill requirements of section 4 (Organization Context) are basically the same for ISO 9001 to ISO 27001 (e.g., the requirement, responsible, due date, etc.), and by this, if the spreadsheet provided by your consultancy is compliant with ISO 9001, then it also complies with ISO 27001, the requirements for quality are very different from requirements for information security.
For example, for ISO 27001 the requirement would be to comply with LGPD, whereas for ISO 9001 the requirement would be to comply with some manufacturing-related regulation. So it would be better to list the legal, regulatory, and contractual requirements in separated documents for ISO 27001 and for ISO 9001.