ISO 27001 (ISMS) Certification
ISO 27001 certification shows clients that you protect their data through an information security management system (ISMS) audited by an accredited certification body. The current edition is ISO/IEC 27001:2022; older 2013 certificates had to move across by 31 October 2025.
What it is
ISO/IEC 27001 is the international standard for an information security management system. It asks you to find your information risks, decide how to treat each one and keep checking that the controls work. You end up with policies, a risk register, a Statement of Applicability, internal audits and management review.
The current edition, ISO/IEC 27001:2022, was published on 25 October 2022 by ISO and the IEC. Amendment 1 of 2024 added climate action changes. An independent certification body issues the certificate. In India, NABCB under the Quality Council of India accredits these bodies against ISO/IEC 17021-1.
Who it applies to
ISO 27001 is voluntary under Indian law, though contracts often demand it. The Digital Personal Data Protection Act, 2023 requires every data fiduciary to take reasonable security safeguards, which an ISMS helps you show.
You build or host software
SaaS companies, app developers, hosting and cloud service providers, including young firms with Startup India recognition. Enterprise and overseas clients often ask for it in their vendor security review. Picture a small Faridabad software house whose first US client sends a long security questionnaire; the certificate answers much of it.
You process someone else’s data
BPOs, KPOs, payroll and back-office service providers, and call centres. Here is the catch: your client’s data sits on your systems, so your weak password policy becomes their risk. Think of a Faridabad payroll processor holding salary and bank data for several employers.
You bid for tenders or large contracts
Government and PSU tenders (including some on the GeM portal), bank and insurance vendor panels, and large corporate contracts often list ISO 27001 as an eligibility or scoring condition.
Why it matters
Pass vendor security reviews faster
Procurement teams can tick a whole block of their checklist once they see an accredited certificate.
Build DPDP evidence as you go
The DPDP Rules, 2025 were notified on 13 November 2025. Most data fiduciary duties start 18 months later. Rule 6 lists safeguards such as encryption, masking, access control and logs kept for one year; an ISMS gives you the records to show them.
Handle incidents with a plan
The DPDP Rules require a detailed breach report to the Data Protection Board within 72 hours. An ISMS gives you an incident process before you need one.
What changed with ISO 27001:2022
Work with 93 controls in four themes
Annex A now has 93 controls, down from 114, grouped into four themes: organisational, people, physical and technological.
Cover the eleven new controls
New controls include threat intelligence, information security for cloud services, data masking, data leakage prevention, monitoring activities and secure coding.
Retire any 2013 certificate
The transition period closed on 31 October 2025. A certificate still showing ISO/IEC 27001:2013 is no longer valid. Check what your vendors send you too.
Documents required
About your organisation
- Certificate of incorporation or registration, and GST registration
- Organisation chart and list of locations
- Services, data types and key IT systems
- Contracts with cloud and IT suppliers
ISMS core documents
- Scope of the ISMS
- Information security policy and objectives
- Risk assessment and risk treatment plan
- Statement of Applicability (SoA)
Evidence the system runs
- Asset inventory and access-control records
- Security awareness training records
- Incident log and backup test records
- Internal audit report and management review minutes
How it works
Fix the scope
We agree which locations, teams and systems the certificate covers. An honest, tight scope keeps the audit manageable.
Run a gap check
We compare your current practice with clauses 4 to 10 and the Annex A controls of ISO/IEC 27001:2022, and give you a written gap list.
Assess risks and write the SoA
Your team lists information assets, rates each risk and picks a treatment. We sit with them through it. The Statement of Applicability records which Annex A controls apply and why.
Put controls and records in place
We draft the policies, procedures and registers. Your IT team or vendor makes the technical changes. Technical penetration testing, if needed, goes to a specialist firm.
Hold the internal audit and management review
Both are needed before certification. We help plan the audit and minute the review.
Choose the body and face Stage 1 and Stage 2
We help you compare accredited certification bodies; you contract with the body directly. Stage 1 checks readiness; Stage 2 checks the system in operation. We help close findings.
Keep it running
We track surveillance dates, update the risk register when your systems change and keep the ISMS in step with your DPDP duties. For ISO 9001 or other standards, see our ISO certification support.
Timelines
Plan for a three-year cycle
The certificate is valid for three years. Under ISO/IEC 17021-1, the cycle starts on the date of the certification decision.
Book the first surveillance within 12 months
No later than 12 months after the certification decision, then at least once each calendar year except the recertification year.
Recertify before expiry
Finish recertification before expiry. After expiry, the body can restore within six months if pending work is done; otherwise at least a Stage 2 is repeated.
What happens if the system lapses
The body suspends your certificate
Under ISO/IEC 17021-1, the body must suspend certification if you do not allow surveillance or recertification audits on time, or fail certification requirements. A suspension normally lasts no more than six months before withdrawal or a scope cut.
Client contracts come under strain
Many service agreements require a valid certificate. Losing it can trigger a client audit or stop a renewal.
DPDP penalties remain a separate risk
Under the Schedule to the DPDP Act, failing to take reasonable security safeguards under Section 8(5) can attract a penalty of up to ₹250 crore. A certificate is not a legal shield, but a working ISMS helps you show the safeguards you took.
Frequently asked questions
Is ISO 27001 certification mandatory in India?
No, ISO 27001 is voluntary and no Indian law makes it compulsory by itself. It becomes necessary when a contract, tender or vendor panel asks for it. Separately, the DPDP Act, 2023 requires reasonable security safeguards for personal data, and an ISMS helps you show them. We help you work out whether your contracts actually need the certificate before you start.
Which version of ISO 27001 applies now?
ISO/IEC 27001:2022 is the current edition, published on 25 October 2022, with Amendment 1 of 2024 adding climate action changes. The transition from the 2013 edition ended on 31 October 2025, so 2013 certificates are no longer valid. If you hold an old certificate, you need a fresh certification to the 2022 edition. We map your old documents to the new Annex A, so little earlier work is lost.
How many controls are in ISO 27001:2022 Annex A?
Annex A of ISO/IEC 27001:2022 has 93 controls, grouped into four themes: organisational, people, physical and technological. The 2013 edition had 114; the 2022 edition added 11 new ones, such as threat intelligence and secure coding. You do not have to apply every control; your Statement of Applicability records which ones apply and why. We help you justify each choice.
Who issues the ISO 27001 certificate?
An accredited certification body issues it after auditing your ISMS; ISO and the government do not. In India, NABCB under the Quality Council of India accredits certification bodies against ISO/IEC 17021-1. Before you sign with any body, check that its accreditation covers ISO/IEC 27001. We check this for you before you commit.
How long is an ISO 27001 certificate valid?
It is valid for three years from the certification decision, as long as surveillance audits happen on time. The first surveillance audit must fall within 12 months of the certification decision, then at least once every calendar year. Recertification before expiry starts a new cycle. We track these dates and remind you well ahead.
Does ISO 27001 make us DPDP compliant?
No, ISO 27001 alone does not make you DPDP compliant, but it covers much of the security side. The DPDP Rules, 2025, notified on 13 November 2025, require safeguards like encryption, access control and logs kept for one year, and breach reporting to the Board within 72 hours. Consent, notices and data-principal rights sit outside ISO 27001. We help you link your ISMS records to these duties.
Do we need a technical team to get certified?
You need someone who manages your IT, staff or vendor, but not a large security team. Much of the work is policies, risk decisions and records; access reviews and backups stay with your IT side. Penetration tests go to a specialist firm. We handle documents and audit liaison so your team can keep working.
What happens in the Stage 1 and Stage 2 audits?
The first certification audit always runs in two stages under ISO/IEC 17021-1. Stage 1 reviews your scope, documents, risk assessment and Statement of Applicability, and checks readiness. Stage 2 tests whether the controls actually work, through interviews, records and sampling. Any non-conformities must be addressed to the body’s satisfaction before it decides on certification. We prepare your team for both stages.
Can a small startup get ISO 27001?
Yes. ISO 27001 applies to organisations of any size, and a small team with a cloud-based setup can be certified. What matters is an honest scope and a system you actually run. In practice, many early-stage SaaS companies take it to land their first enterprise client. We size the documents to your team, so a ten-person startup is not asked to behave like a bank.
What it costs
Our fee plus the government fee that applies to your case, quoted before you commit. Tell us the situation and we will price it exactly.
There is no government fee for ISO 27001 certification. The certification body charges its own audit fee, based mainly on your headcount within scope, number of sites and complexity. Penetration testing, if your clients require it, is billed separately by the testing firm.
Ready to begin?
Tell us what data you handle and who is asking for the certificate, and we will plan your ISO 27001 project from scope to Stage 2.