Management System Certification

ISO 27001 – Information Security Management System

The certification your enterprise customers ask for before they sign.

  • ISO 27001
  • Recognised internationally
  • Frequently certified

About ISO 27001

What is ISO 27001?

ISO/IEC 27001:2022 is the international standard for an Information Security Management System (ISMS). It requires you to establish a risk assessment methodology, identify information security risks against confidentiality, integrity and availability, select controls that treat those risks, and operate the whole thing as a governed, measured, continually improving system.

The 2022 revision restructured Annex A from 114 controls in fourteen domains into 93 controls in four themes — organisational, people, physical and technological — and introduced eleven new controls reflecting how organisations actually work now: threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering and secure coding.

A crucial point about ISO 27001: Annex A is not a checklist to be implemented wholesale. Controls are selected because your risk assessment justified them, and every inclusion and exclusion is recorded in the Statement of Applicability with reasoning. An SoA that simply marks all 93 controls "applicable" without risk justification is one of the clearest signals of a system built for the certificate rather than for security — and auditors treat it that way.

Who needs this?

  • IT services, SaaS and product companies whose enterprise customers require it in security due diligence
  • BPO, KPO and ITES organisations processing client or personal data
  • Fintech, banking, insurance and payment organisations with regulatory security obligations
  • Healthcare and health-tech organisations handling patient information
  • Data centres, cloud and managed service providers
  • Any organisation preparing for DPDP Act obligations or extending into ISO 27701 privacy certification

Why organisations certify

Key benefits of ISO 27001

What certification actually returns, stated specifically rather than generically.

Credibility

ISO 27001 is the default answer to "prove your security posture" in enterprise vendor onboarding. It replaces months of bespoke questionnaire cycles.

Market Access

Large clients, EU and US customers and government contracts frequently make certification a precondition to bidding at all.

Risk Reduction

Formal risk assessment, treatment planning and incident management measurably reduce the likelihood and blast radius of a breach.

Operational Efficiency

Asset inventories, access reviews and change control eliminate the ambiguity that causes outages and duplicated security spend.

Customer Trust

Certification is a signal customers can verify independently, which shortens sales cycles and strengthens contractual negotiating position.

Regulatory Compliance

The ISMS provides the governance backbone for India’s DPDP Act, GDPR, RBI and IRDAI security directions, and sector-specific mandates.

How it works

Our process for ISO 27001

Every stage has a defined purpose, a realistic duration and a stated output.

  1. 01

    Application & Quotation

    2–3 working days

    You submit an application form covering scope, headcount, sites and shift pattern. We review complexity, confirm audit-day allocation against accreditation rules and issue a fixed quotation.

  2. 02

    Contract & Audit Planning

    1 week

    On acceptance we appoint a lead auditor with verified technical competence for your sector, agree audit dates and share the audit plan in advance.

  3. 03

    Stage 1 — Readiness Review

    1 day (typical)

    A documentation and readiness assessment: scope confirmation, review of your management system documents, internal audit and management review evidence, and identification of anything that would block Stage 2.

  4. 04

    Stage 2 — Certification Audit

    2–5 days (scope dependent)

    On-site assessment of the system in operation. We sample processes, interview staff, examine records and raise findings graded as major, minor or opportunity for improvement.

  5. 05

    Corrective Action & Decision

    2–4 weeks

    You close out any nonconformities with root-cause analysis and evidence. An independent certification decision-maker — not the audit team — reviews the file and grants certification.

  6. 06

    Certificate Issue

    3–5 working days

    A three-year certificate is issued and your organisation is listed on our public certified-client directory for verification by your customers.

  7. 07

    Surveillance & Recertification

    Annual

    Surveillance audits at 12 and 24 months confirm the system remains effective. A full recertification audit is completed before the three-year expiry.

Preparation

Documents required

What we will ask to see. Having these ready before Stage 1 is the single biggest factor in a certification that runs to schedule.

  • Completed and signed application form
  • Certificate of incorporation / business registration
  • Organisation chart and scope statement
  • Management system manual or equivalent documented information
  • Documented processes, procedures and work instructions
  • Internal audit reports covering the full scope
  • Management review minutes
  • Records of corrective actions and continual improvement
  • Applicable legal and regulatory licences for your activity
  • Information security policy and topic-specific policies
  • ISMS scope statement with boundaries, interfaces and dependencies
  • Information security risk assessment methodology and risk register
  • Risk treatment plan with owners and target dates
  • Statement of Applicability (SoA) justifying every included and excluded control
  • Asset inventory and information classification scheme
  • Access control records: joiner–mover–leaver, privileged access, periodic access review
  • Supplier and cloud service security assessments
  • Incident register, business continuity and ICT readiness test records
  • Vulnerability assessment / penetration test reports and remediation evidence

Not sure whether your scope is right?

Scope is the single thing most often got wrong, and it appears verbatim on your certificate. We will review yours before you apply, at no charge — it costs us less than fixing it at recertification.

Talk to a specialist

Common questions

ISO 27001 — frequently asked questions

Direct answers, including where the honest answer is inconvenient for us.

Annex A was restructured from 114 controls across fourteen domains into 93 controls across four themes, with eleven genuinely new controls covering threat intelligence, cloud security, ICT readiness for continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring, web filtering and secure coding. Organisations still certified to the 2013 version were required to transition by 31 October 2025.

No. Controls are selected on the basis of your risk assessment. What is mandatory is the Statement of Applicability recording which controls apply, which do not, and why. Excluding a control is entirely legitimate when the risk assessment supports it; excluding it because it is inconvenient is not.

The standard does not name penetration testing as a mandatory control. In practice, control 8.8 on technical vulnerability management is very difficult to evidence credibly without vulnerability assessment, and most organisations in scope for ISO 27001 conduct periodic testing. What we assess is whether findings were tracked and remediated, not the test report alone.

Yes — scope is yours to define, and a narrow initial scope is often sensible. But the scope statement must be honest about boundaries, interfaces and dependencies, and the certificate will state it precisely. Customers do read the scope line; a certificate that excludes the service they are buying will not satisfy them.

ISO 27001 certifies that a management system conforms to an international standard; SOC 2 is an attestation report by a CPA firm against the AICPA Trust Services Criteria. They overlap substantially in control content. ISO 27001 is more widely recognised outside North America and results in a certificate; SOC 2 results in a report. Many organisations eventually hold both.

Question not answered here? Ask a certification specialist — we answer technical questions without requiring an enquiry first.

Talk to us

Talk to a certification expert

Tell us your scope and headcount and we will send a fixed quotation for ISO 27001 with the audit-day calculation shown.

  • Quotation within 2–3 working days
  • IAF MD 5 audit-day calculation included
  • Full three-year cycle cost, not just the first audit
  • Your details are used only to answer this enquiry

Including contractors and shift staff — this sets your audit days.

Tell us your scope, whether design is included, and any deadline you are working to.

Your details are used only to answer this enquiry. We do not sell or share them.

Next step

Ready to certify to ISO 27001?

We will scope it honestly, show you the calculation behind the price, and tell you plainly if the timeline you need is not achievable.