Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Part of Compliance13 services in this practice area

Certify Your Security Programme

ISO 27001 Certification and ISMS Consulting

ISO 27001 is the global benchmark for managing information security. We take you from first gap assessment to a certified ISMS, and stay with you through the audit and beyond.

Certified ISO/IEC 27001:2022 (certificate IN60432E)

See the engagement path, 6 phasesSee the full Compliance service index

Overview

ISO/IEC 27001 sets out how to run an information security management system, or ISMS: a living set of policies, controls, and risk decisions that protect your data. Certification tells customers and partners that an independent auditor checked your security and signed off. It matters because more contracts now demand it, and because the discipline genuinely lowers your risk. We help you build an ISMS that fits how you actually work, not a binder that sits on a shelf.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the ISO 27001 engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Gap Assessment. We define what your ISMS covers, then measure your current state against every clause and Annex A control. You get a clear picture of the work ahead. Activities: Define the ISMS scope and boundaries; Interview control owners across teams; Assess maturity against clauses 4 to 10; Test current state against the 93 Annex A controls; Rank gaps by effort and risk. Hands over Gap Assessment Report. Phase 2, Risk Assessment and Treatment. We run a structured risk assessment and agree how you treat each risk. This feeds your Statement of Applicability and risk treatment plan. Activities: Build the asset and risk inventory; Score risks by likelihood and impact; Agree treat, tolerate, transfer, or terminate for each; Select applicable Annex A controls; Draft the Statement of Applicability. Hands over Risk Treatment Plan and Statement of Applicability. Phase 3, Control Design and Documentation. We design the policies, procedures, and controls you need. Everything maps back to a clause or an Annex A control so nothing is orphaned. Activities: Draft the information security policy set; Write procedures for access, change, and incidents; Map every document to a clause or control; Define roles and the risk acceptance criteria. Hands over ISMS Policy and Procedure Set. Phase 4, Implementation Support. We help you roll out controls and start collecting evidence. You build the day-to-day habits that keep the ISMS running. Activities: Roll out controls across in-scope systems; Configure a compliance platform for evidence; Run security awareness training; Start access reviews and log collection. Hands over Operating Controls and Evidence Trail. Phase 5, Internal Audit and Management Review. We run an internal audit, log findings, and prepare your management review. This is your dress rehearsal before the certification body arrives. Activities: Plan and run the internal audit programme; Log nonconformities and corrective actions; Prepare management review inputs; Verify remediation before certification. Hands over Internal Audit Report and Management Review Record. Phase 6, Certification and Surveillance. We support you through Stage 1 and Stage 2 audits, then help you sustain the ISMS across annual surveillance visits. Activities: Prepare evidence for the Stage 1 documentation review; Support the Stage 2 certification audit; Close any audit findings raised; Plan annual surveillance and continual improvement. Hands over ISO 27001 Certificate. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Gap Assessment

We define what your ISMS covers, then measure your current state against every clause and Annex A control. You get a clear picture of the work ahead.

What Happens In This Phase

  • Define the ISMS scope and boundaries
  • Interview control owners across teams
  • Assess maturity against clauses 4 to 10
  • Test current state against the 93 Annex A controls
  • Rank gaps by effort and risk

The Handover

Gap Assessment Report

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Gap Assessment

    We define what your ISMS covers, then measure your current state against every clause and Annex A control. You get a clear picture of the work ahead.

    OutputGap Assessment Report

    Activities

    • Define the ISMS scope and boundaries
    • Interview control owners across teams
    • Assess maturity against clauses 4 to 10
    • Test current state against the 93 Annex A controls
    • Rank gaps by effort and risk
  2. 02

    Risk Assessment and Treatment

    We run a structured risk assessment and agree how you treat each risk. This feeds your Statement of Applicability and risk treatment plan.

    OutputRisk Treatment Plan and Statement of Applicability

    Activities

    • Build the asset and risk inventory
    • Score risks by likelihood and impact
    • Agree treat, tolerate, transfer, or terminate for each
    • Select applicable Annex A controls
    • Draft the Statement of Applicability
  3. 03

    Control Design and Documentation

    We design the policies, procedures, and controls you need. Everything maps back to a clause or an Annex A control so nothing is orphaned.

    OutputISMS Policy and Procedure Set

    Activities

    • Draft the information security policy set
    • Write procedures for access, change, and incidents
    • Map every document to a clause or control
    • Define roles and the risk acceptance criteria
  4. 04

    Implementation Support

    We help you roll out controls and start collecting evidence. You build the day-to-day habits that keep the ISMS running.

    OutputOperating Controls and Evidence Trail

    Activities

    • Roll out controls across in-scope systems
    • Configure a compliance platform for evidence
    • Run security awareness training
    • Start access reviews and log collection
  5. 05

    Internal Audit and Management Review

    We run an internal audit, log findings, and prepare your management review. This is your dress rehearsal before the certification body arrives.

    OutputInternal Audit Report and Management Review Record

    Activities

    • Plan and run the internal audit programme
    • Log nonconformities and corrective actions
    • Prepare management review inputs
    • Verify remediation before certification
  6. 06

    Certification and Surveillance

    We support you through Stage 1 and Stage 2 audits, then help you sustain the ISMS across annual surveillance visits.

    OutputISO 27001 Certificate

    Activities

    • Prepare evidence for the Stage 1 documentation review
    • Support the Stage 2 certification audit
    • Close any audit findings raised
    • Plan annual surveillance and continual improvement

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

TrustGrid

Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the ISO 27001 scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Vanta, Drata, Sprinto, Scrut, Jira, Confluence, OneTrust, Microsoft Purview. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO/IEC 27001 Annex A, ISO/IEC 27005, ISO/IEC 27017, NIST CSF.

What We Run

8 tools

  • Vanta
  • Drata
  • Sprinto
  • Scrut
  • Jira
  • Confluence
  • OneTrust
  • Microsoft Purview

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

6 standards

  • ISO/IEC 27001:2022
  • ISO/IEC 27002:2022
  • ISO/IEC 27001 Annex A
  • ISO/IEC 27005
  • ISO/IEC 27017
  • NIST CSF
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Gap assessment report
  • Statement of Applicability
  • Risk treatment plan
  • ISMS policy and procedure set
  • Certification audit support

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

What It Costs

Indicative Ranges, Before You Ask

Every figure below is an indicative range, not a quote. Where you land in it depends on scope, and we confirm a fixed price only once scoping is done.

  • Indicative rangeDepends on scope

    ISO 27001 certification

    ₹1.5 lakh to ₹8 lakh

    Range as of 18 September 2026

    What sets the figure

    • The total to reach certification: our implementation programme plus the accredited certification body's Stage 1 and Stage 2 audit, which you contract and pay directly
    • Where you land is scope: the locations, systems and people inside the ISMS boundary, and how much of the groundwork already exists
    • A single office with one product sits near the bottom; a multi-location operation starting from nothing sits near the top
    • Your own team's time producing evidence sits outside the figure, and is usually larger than either fee

Indicative ranges in INR; the final quote depends on scope, and each range is dated on its own card.

Get a Fixed Price for Your Scope

Tell us what is in scope and when you need it. You get a written scope and a fixed price, not a band.

Request an Assessment

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

How Much Does ISO 27001 Certification Cost In India?

Indicative total: ₹1.5 lakh to ₹8 lakh to reach certification, covering both parts of the bill. The first is our consulting and implementation programme: gap assessment, risk assessment, control documentation, implementation support and internal audit. The second is the accredited certification body's Stage 1 and Stage 2 audit, which you contract and pay directly, and which is priced on organisation size and audit days rather than by us. Where you land between the two ends is scope: how many locations, systems and people sit inside the ISMS boundary, and how much of the groundwork already exists. A single office with one product sits near the bottom of the range; a multi-location operation starting from nothing sits near the top. Budget for a third cost no invoice shows, which is your own people's time producing evidence, running access reviews and sitting in auditor interviews. We scope all three before you commit, and confirm a fixed price once scoping is done, never before.

What Drives The Cost Of ISO 27001 Certification?

Four things, mainly. First, scope: how many sites, business units and systems sit inside the ISMS boundary. A single office with one product is a smaller programme than a multi-location operation, and scope is the one lever you fully control. Second, headcount, because awareness training, access reviews and role definitions all scale with people. Third, your starting point: if you already run structured access control, incident handling and vendor reviews, we build on them rather than starting from zero. Fourth, your choice of certification body, since audit fees vary between accredited bodies and rise with organisation size. Scope is worth dwelling on. An ISMS covering one product and one office costs materially less to certify and to sustain than one covering the whole company, and you can widen the boundary at a later surveillance visit once the system is running. We map all four in the scoping call so the quote reflects your situation, not a template.

How long does ISO 27001 certification take?

Most organisations reach certification in three to six months, and our phases add up to that. Scoping and gap assessment takes two to three weeks, risk assessment and treatment another two to three, control design and documentation three to four, implementation support six to twelve, and internal audit and management review two to three, before the certification body runs Stage 1 and Stage 2. What moves the number is how many controls already exist and how quickly your control owners can produce evidence, not the size of the standard. A company already running change management, access reviews and logging is mostly documenting what it does. A company starting from nothing is building habits, and habits take calendar time, because an auditor wants to see them operating rather than written down. We give you a realistic timeline after the gap assessment.

What is the Statement of Applicability?

The Statement of Applicability, usually shortened to SoA, is the document that lists every Annex A control, records whether you apply it, and explains the reasoning either way. It is the bridge between your risk assessment and your control set, which is why auditors read it first and keep returning to it. An exclusion is perfectly legitimate when you can justify it, so a company with no physical office can exclude some physical security controls, but it has to say so and say why. What fails an audit is an SoA claiming controls you cannot evidence, or one written once and never revisited after the environment changed. We build yours from the risk treatment plan so every inclusion traces back to a risk you actually identified, and we keep it current across the surveillance cycle.

What is the difference between Stage 1 and Stage 2 audits?

Stage 1 is a documentation and readiness review. The auditor checks that your ISMS exists on paper: scope, policies, risk assessment, Statement of Applicability, internal audit records and management review minutes. It usually surfaces gaps you still have time to close. Stage 2 is the certification audit proper and it tests whether the controls operate in practice. The auditor samples evidence, interviews control owners, and looks for the distance between what your policy says and what your teams actually do. Findings are raised as minor or major nonconformities, and a major one has to be closed before the certificate issues. The two stages are usually separated by a few weeks so you can respond to Stage 1. We run an internal audit and management review first, which is the dress rehearsal, so Stage 2 holds no surprises.

How many controls does ISO 27001 have?

ISO/IEC 27001:2022 lists 93 controls in Annex A, reorganised into four themes: organisational, people, physical and technological. That is down from the 114 controls across 14 domains in the 2013 version, and eleven of the 93 are new, covering areas such as threat intelligence, information security for cloud services, data masking and secure coding. The count matters less than people expect. You are not required to implement all 93. You are required to consider each one, decide whether it applies to your risks, and record that decision in the Statement of Applicability. The mandatory part sits outside Annex A altogether, in clauses four to ten: context, leadership, planning, support, operation, performance evaluation and improvement. Organisations that treat Annex A as a shopping list and skip the clauses are the ones that struggle at Stage 2.

Keep Moving Through Compliance

Service 1 of 13 in this practice area