Cybersecurity
ISO 27001 Certification Process for Indian Companies
Affix Center · · 6 min read

More Indian companies are being asked for ISO 27001 certification by their customers, especially banks, global clients and government buyers. Yet the ISO 27001 certification process in India is often misunderstood. Some firms treat it as a documentation exercise and buy template policies. Others delay for years because the standard looks too large to start.
Both approaches cause problems. Template-only systems fail audits or collapse after the certificate arrives. Endless delay costs contracts. The practical path sits in between: build an information security management system (ISMS) that fits how your business actually works, then have it certified by an accredited body. This guide explains the process step by step for companies in Mumbai, Pune and across India.
What ISO 27001 Certification Means
ISO/IEC 27001 is the international standard for an ISMS. The current edition is ISO/IEC 27001:2022. It requires an organisation to identify its information security risks, choose controls to treat them, and run a cycle of monitoring, audit and improvement.
Annex A of the 2022 edition lists 93 controls grouped into four themes: organisational, people, physical and technological. You do not have to apply every control, but you must justify which ones apply and which do not in a Statement of Applicability.
Certificates issued against the older 2013 edition must be transitioned to the 2022 edition by 31 October 2025. If your company holds a 2013 certificate, confirm the transition audit with your certification body now.
The ISO 27001 Certification Process in India, Step by Step
The ISO 27001 certification process in India follows the same international steps as anywhere else.
1. Get management commitment
Leadership must approve the project, assign an owner and provide budget and staff time. The standard explicitly requires top management involvement, and auditors will check it.
2. Define the scope
Decide which locations, business units, processes and systems the ISMS covers. A software company might scope its product development and hosting operations at its Mumbai office. A narrow, well-defined scope is easier to certify first and can be expanded later.
3. Carry out a gap assessment
Compare current practices against the requirements of the standard and the Annex A controls. This shows how much work is needed and helps set a realistic timeline.
4. Run a risk assessment
List information assets, identify threats and vulnerabilities, and rate the risks. Then decide how to treat each one: reduce, avoid, transfer or accept. This risk assessment is the core of the ISMS.
5. Prepare the Statement of Applicability and policies
Document which controls apply, why, and how they are implemented. Write policies that reflect real practice: access control, acceptable use, supplier security, incident management, backup, business continuity and more.
6. Implement the controls
This is the longest phase. Typical work includes access reviews, multi-factor authentication, patching, logging, secure configuration, vendor assessments, awareness training and physical security.
7. Operate and collect evidence
Run the ISMS for a period so there are records to audit: training logs, access reviews, incident reports and management review minutes.
8. Conduct an internal audit and management review
An internal audit, by trained staff or an independent consultant, checks whether the ISMS works as designed. Management then reviews the results and approves corrective actions.
9. Complete the certification audit
The external audit happens in two stages. Stage 1 reviews documentation and readiness. Stage 2 tests whether the controls actually operate. If there are major nonconformities, they must be closed before the certificate is issued.
10. Maintain the certificate
Certification typically runs on a three-year cycle with surveillance audits in the intervening years and a recertification audit at the end.
Documents Auditors Will Ask For
Auditors look for evidence that the ISMS is real and working. Keep these ready and up to date:
- ISMS scope statement and information security policy.
- Risk assessment method, risk register and risk treatment plan.
- Statement of Applicability.
- Asset inventory, including hardware, software, data and cloud services.
- Access review records and joiner, mover and leaver logs.
- Training and awareness records for all staff in scope.
- Incident log and records of how incidents were handled.
- Supplier security assessments and relevant contract clauses.
- Internal audit report, corrective action log and management review minutes.
Evidence should come from normal operations. If records are created only in the week before the audit, experienced auditors usually notice.
Choosing a Certification Body
Select a certification body that is accredited for ISO 27001. In India, NABCB (the National Accreditation Board for Certification Bodies) accredits certification bodies, and bodies accredited by other recognised accreditation bodies are also used. Check that:
- The accreditation covers ISO/IEC 27001 and is current.
- The certificate can be verified on a public register.
- The auditors understand your industry.
- The body does not also offer to implement your ISMS, since that is a conflict of interest.
Be cautious of offers promising a certificate within days without an audit. Such certificates rarely satisfy informed customers.
Linking ISO 27001 with Indian Regulations
An ISMS is a good framework for meeting Indian legal and regulatory requirements, although certification alone does not prove compliance with them. Map the following into your risk assessment and controls:
- CERT-In Directions of April 2022: reporting specified cyber incidents within 6 hours, synchronising clocks and retaining ICT logs for 180 days within India.
- The Digital Personal Data Protection Act, 2023: obligations for processing personal data, including reasonable security safeguards.
- Sector regulators: RBI, SEBI and IRDAI have their own cybersecurity requirements for regulated entities.
- Customer contracts: security clauses from clients, often stricter than the law.
Our enterprise advisory team can help align your ISMS with these requirements, so one set of controls serves several obligations.
Timeline, Cost Factors and Common Mistakes
Timelines vary. A small, well-organised company with a clear scope can often be ready within a few months. Larger or more complex organisations take longer. Cost depends on:
- Scope size, number of locations and number of employees.
- Current security maturity and the size of the gaps.
- Tools needed, such as endpoint protection, logging or backup systems.
- Whether you use external consultants for implementation and internal audit.
- Certification body audit fees, which depend on audit days.
Common mistakes to avoid:
- Copying generic policies that do not match actual practice.
- Treating the risk assessment as a one-time spreadsheet.
- Leaving IT to handle everything, when HR, legal, facilities and business teams also own controls.
- Ignoring suppliers and cloud providers in the risk assessment.
- Letting the ISMS lapse between surveillance audits.
Technical controls such as vulnerability management, logging and incident response are often the hardest part. Our cybersecurity services cover these areas.
Frequently Asked Questions
How long does ISO 27001 certification take in India?
It depends on scope and current maturity. Small companies with good practices may be ready in a few months. Larger organisations usually need longer.
Is ISO 27001 mandatory in India?
No law makes it mandatory for all companies. However, many clients, tenders and regulated sectors ask for it or for equivalent controls.
How long is an ISO 27001 certificate valid?
Typically three years, with surveillance audits during that period and recertification at the end.
What is the difference between ISO 27001:2013 and 2022?
The 2022 edition restructures Annex A into 93 controls in four themes and adds new controls, such as threat intelligence and secure coding.
How Affix Center Can Help
Affix Center supports Indian companies through each stage of the ISO 27001 certification process, including gap assessments, risk assessment support, policy development, technical control implementation and internal audit readiness. We focus on an ISMS that your team can run after certification, not just a set of documents.
To plan your certification journey, speak with our team.