Certify Your Security Programme
ISO 27001 Certification and ISMS Consulting
ISO 27001 is the global benchmark for managing information security. We take you from first gap assessment to a certified ISMS, and stay with you through the audit and beyond.
Certified ISO/IEC 27001:2022 (certificate IN60432E)
See the engagement path, 6 phasesSee the full Compliance service index
Overview
ISO/IEC 27001 sets out how to run an information security management system, or ISMS: a living set of policies, controls, and risk decisions that protect your data. Certification tells customers and partners that an independent auditor checked your security and signed off. It matters because more contracts now demand it, and because the discipline genuinely lowers your risk. We help you build an ISMS that fits how you actually work, not a binder that sits on a shelf.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the ISO 27001 engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Gap Assessment. We define what your ISMS covers, then measure your current state against every clause and Annex A control. You get a clear picture of the work ahead. Activities: Define the ISMS scope and boundaries; Interview control owners across teams; Assess maturity against clauses 4 to 10; Test current state against the 93 Annex A controls; Rank gaps by effort and risk. Hands over Gap Assessment Report. Phase 2, Risk Assessment and Treatment. We run a structured risk assessment and agree how you treat each risk. This feeds your Statement of Applicability and risk treatment plan. Activities: Build the asset and risk inventory; Score risks by likelihood and impact; Agree treat, tolerate, transfer, or terminate for each; Select applicable Annex A controls; Draft the Statement of Applicability. Hands over Risk Treatment Plan and Statement of Applicability. Phase 3, Control Design and Documentation. We design the policies, procedures, and controls you need. Everything maps back to a clause or an Annex A control so nothing is orphaned. Activities: Draft the information security policy set; Write procedures for access, change, and incidents; Map every document to a clause or control; Define roles and the risk acceptance criteria. Hands over ISMS Policy and Procedure Set. Phase 4, Implementation Support. We help you roll out controls and start collecting evidence. You build the day-to-day habits that keep the ISMS running. Activities: Roll out controls across in-scope systems; Configure a compliance platform for evidence; Run security awareness training; Start access reviews and log collection. Hands over Operating Controls and Evidence Trail. Phase 5, Internal Audit and Management Review. We run an internal audit, log findings, and prepare your management review. This is your dress rehearsal before the certification body arrives. Activities: Plan and run the internal audit programme; Log nonconformities and corrective actions; Prepare management review inputs; Verify remediation before certification. Hands over Internal Audit Report and Management Review Record. Phase 6, Certification and Surveillance. We support you through Stage 1 and Stage 2 audits, then help you sustain the ISMS across annual surveillance visits. Activities: Prepare evidence for the Stage 1 documentation review; Support the Stage 2 certification audit; Close any audit findings raised; Plan annual surveillance and continual improvement. Hands over ISO 27001 Certificate. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Gap Assessment
We define what your ISMS covers, then measure your current state against every clause and Annex A control. You get a clear picture of the work ahead.
What Happens In This Phase
- Define the ISMS scope and boundaries
- Interview control owners across teams
- Assess maturity against clauses 4 to 10
- Test current state against the 93 Annex A controls
- Rank gaps by effort and risk
The Handover
Gap Assessment Report
The next phase starts from this.
Phase 01 Scoping and Gap Assessment
We define what your ISMS covers, then measure your current state against every clause and Annex A control. You get a clear picture of the work ahead.
What Happens In This Phase
- Define the ISMS scope and boundaries
- Interview control owners across teams
- Assess maturity against clauses 4 to 10
- Test current state against the 93 Annex A controls
- Rank gaps by effort and risk
The Handover
Gap Assessment Report
The next phase starts from this.
- 01
Scoping and Gap Assessment
We define what your ISMS covers, then measure your current state against every clause and Annex A control. You get a clear picture of the work ahead.
OutputGap Assessment ReportActivities
- Define the ISMS scope and boundaries
- Interview control owners across teams
- Assess maturity against clauses 4 to 10
- Test current state against the 93 Annex A controls
- Rank gaps by effort and risk
- 02
Risk Assessment and Treatment
We run a structured risk assessment and agree how you treat each risk. This feeds your Statement of Applicability and risk treatment plan.
OutputRisk Treatment Plan and Statement of ApplicabilityActivities
- Build the asset and risk inventory
- Score risks by likelihood and impact
- Agree treat, tolerate, transfer, or terminate for each
- Select applicable Annex A controls
- Draft the Statement of Applicability
- 03
Control Design and Documentation
We design the policies, procedures, and controls you need. Everything maps back to a clause or an Annex A control so nothing is orphaned.
OutputISMS Policy and Procedure SetActivities
- Draft the information security policy set
- Write procedures for access, change, and incidents
- Map every document to a clause or control
- Define roles and the risk acceptance criteria
- 04
Implementation Support
We help you roll out controls and start collecting evidence. You build the day-to-day habits that keep the ISMS running.
OutputOperating Controls and Evidence TrailActivities
- Roll out controls across in-scope systems
- Configure a compliance platform for evidence
- Run security awareness training
- Start access reviews and log collection
- 05
Internal Audit and Management Review
We run an internal audit, log findings, and prepare your management review. This is your dress rehearsal before the certification body arrives.
OutputInternal Audit Report and Management Review RecordActivities
- Plan and run the internal audit programme
- Log nonconformities and corrective actions
- Prepare management review inputs
- Verify remediation before certification
- 06
Certification and Surveillance
We support you through Stage 1 and Stage 2 audits, then help you sustain the ISMS across annual surveillance visits.
OutputISO 27001 CertificateActivities
- Prepare evidence for the Stage 1 documentation review
- Support the Stage 2 certification audit
- Close any audit findings raised
- Plan annual surveillance and continual improvement
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
TrustGrid
Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.
What Is Examined, and What it Is Measured Against
Map
Map of the ISO 27001 scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Vanta, Drata, Sprinto, Scrut, Jira, Confluence, OneTrust, Microsoft Purview. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: ISO/IEC 27001:2022, ISO/IEC 27002:2022, ISO/IEC 27001 Annex A, ISO/IEC 27005, ISO/IEC 27017, NIST CSF.
What We Run
8 tools
- Vanta
- Drata
- Sprinto
- Scrut
- Jira
- Confluence
- OneTrust
- Microsoft Purview
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
6 standards
- ISO/IEC 27001:2022
- ISO/IEC 27002:2022
- ISO/IEC 27001 Annex A
- ISO/IEC 27005
- ISO/IEC 27017
- NIST CSF
Deliverables
What You Receive
- Gap assessment report
- Statement of Applicability
- Risk treatment plan
- ISMS policy and procedure set
- Certification audit support
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
How Much Does ISO 27001 Certification Cost In India?
Indicative range: Rs 1,50,000 to Rs 5,00,000 for the consulting and implementation programme, covering gap assessment, risk assessment, control documentation, implementation support and internal audit. Where you land in that range depends on scope: the size of your organisation, how many locations and systems fall inside the ISMS boundary, and how much of the groundwork already exists. The certification body's audit fee is separate. You pay that directly to the accredited body you choose, and it is priced on organisation size and audit days, not by us. Budget for a third cost that no invoice shows: your own people's time. Control owners have to produce evidence, run access reviews and sit in auditor interviews, and that effort is usually larger than either fee. We scope all three before you commit to any of them, and we confirm a fixed price once scoping is done, never before.
What Drives The Cost Of ISO 27001 Certification?
Four things, mainly. First, scope: how many sites, business units and systems sit inside the ISMS boundary. A single office with one product is a smaller programme than a multi-location operation, and scope is the one lever you fully control. Second, headcount, because awareness training, access reviews and role definitions all scale with people. Third, your starting point: if you already run structured access control, incident handling and vendor reviews, we build on them rather than starting from zero. Fourth, your choice of certification body, since audit fees vary between accredited bodies and rise with organisation size. Scope is worth dwelling on. An ISMS covering one product and one office costs materially less to certify and to sustain than one covering the whole company, and you can widen the boundary at a later surveillance visit once the system is running. We map all four in the scoping call so the quote reflects your situation, not a template.
How long does ISO 27001 certification take?
Most organisations reach certification in three to six months, and our phases add up to that. Scoping and gap assessment takes two to three weeks, risk assessment and treatment another two to three, control design and documentation three to four, implementation support six to twelve, and internal audit and management review two to three, before the certification body runs Stage 1 and Stage 2. What moves the number is how many controls already exist and how quickly your control owners can produce evidence, not the size of the standard. A company already running change management, access reviews and logging is mostly documenting what it does. A company starting from nothing is building habits, and habits take calendar time, because an auditor wants to see them operating rather than written down. We give you a realistic timeline after the gap assessment.
What is the Statement of Applicability?
The Statement of Applicability, usually shortened to SoA, is the document that lists every Annex A control, records whether you apply it, and explains the reasoning either way. It is the bridge between your risk assessment and your control set, which is why auditors read it first and keep returning to it. An exclusion is perfectly legitimate when you can justify it, so a company with no physical office can exclude some physical security controls, but it has to say so and say why. What fails an audit is an SoA claiming controls you cannot evidence, or one written once and never revisited after the environment changed. We build yours from the risk treatment plan so every inclusion traces back to a risk you actually identified, and we keep it current across the surveillance cycle.
What is the difference between Stage 1 and Stage 2 audits?
Stage 1 is a documentation and readiness review. The auditor checks that your ISMS exists on paper: scope, policies, risk assessment, Statement of Applicability, internal audit records and management review minutes. It usually surfaces gaps you still have time to close. Stage 2 is the certification audit proper and it tests whether the controls operate in practice. The auditor samples evidence, interviews control owners, and looks for the distance between what your policy says and what your teams actually do. Findings are raised as minor or major nonconformities, and a major one has to be closed before the certificate issues. The two stages are usually separated by a few weeks so you can respond to Stage 1. We run an internal audit and management review first, which is the dress rehearsal, so Stage 2 holds no surprises.
How many controls does ISO 27001 have?
ISO/IEC 27001:2022 lists 93 controls in Annex A, reorganised into four themes: organisational, people, physical and technological. That is down from the 114 controls across 14 domains in the 2013 version, and eleven of the 93 are new, covering areas such as threat intelligence, information security for cloud services, data masking and secure coding. The count matters less than people expect. You are not required to implement all 93. You are required to consider each one, decide whether it applies to your risks, and record that decision in the Statement of Applicability. The mandatory part sits outside Annex A altogether, in clauses four to ten: context, leadership, planning, support, operation, performance evaluation and improvement. Organisations that treat Annex A as a shopping list and skip the clauses are the ones that struggle at Stage 2.
Keep Moving Through Compliance
Service 1 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27701Extend your ISMS into a privacy information management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- HIPAAProtect health information and meet HIPAA requirements.
- SOC 2Earn a SOC 2 report your customers can trust.
- CCPAMeet California's consumer privacy requirements.
- GDPRMeet Europe's data protection standard with confidence.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.