Does Security Brigade issue the ISO 27001 certificate?+
No, and no consultancy can. The certificate is issued by an accredited certification body, and ISO/IEC 17021-1 requires that body to be independent of the consulting that prepared you. That separation is the reason readiness work exists as its own discipline. We build and run the ISMS with you, perform the internal audit, prepare the evidence, and coordinate with your chosen registrar through Stage 1 and Stage 2 until the certificate is issued.
Which Indian regulator requires ISO 27001?+
SEBI is the one that names it. CSCRF made ISO 27001 certification mandatory under PR.IP.S16 for Market Infrastructure Institutions and Qualified REs alike; the technical clarifications of 28 August 2025 then softened it for Qualified REs, who are now "encouraged and recommended" to certify instead of obliged. MIIs are unchanged. Elsewhere the pressure is commercial, not regulatory: enterprise vendor assessments, global customer onboarding, investor diligence and public tenders routinely gate on the certificate, which is why for most Indian organisations the honest answer is that it is a market requirement with one regulatory exception.
How much of the work carries over to SOC 2?+
Enough to sequence them together, and the overlap sits in specific families, not in a headline percentage. Access control, change management, risk assessment, vendor and supplier management, incident response, logging and monitoring, and human-resources security do genuine double duty: the same evidence, produced once, answers both. What does not carry over is the shape: ISO 27001 certifies a management system against a standard, while SOC 2 produces a CPA firm’s report on controls you defined against the Trust Services Criteria. Run as one programme the second framework costs a fraction of what it costs run cold.
Does penetration testing form part of an ISO 27001 programme?+
In practice, yes, and registrars expect to see technical testing evidence. Annex A includes controls on the management of technical vulnerabilities and on secure development, and the standard requires security measures to be chosen on the basis of assessed risk, an argument that is difficult to make without evidence about the systems themselves. We run the testing inside the programme so results feed the ISMS evidence base directly through Lemon instead of arriving as a separate report nobody maps back.
How long does certification take?+
Three to six months to Stage 2 for most organisations, driven by current maturity far more than by size. An organisation with documented policies, a working risk register and access reviews already running is doing a gap-closure exercise. One starting from nothing is building a management system, and the honest timeline is the longer end. Scope is the other lever: locations, legal entities and systems inside the ISMS boundary drive both the timeline and the registrar’s auditor-days, and it is the cheapest decision available because it is made before anybody quotes.
What happens to the certificate if our scope changes?+
It stays valid for what it covers, which is exactly the problem when the scope statement no longer describes the business. A certificate naming one entity and one location does not cover the subsidiary acquired last year or the product built in a second cloud account, and enterprise procurement teams read the scope line. Scope changes are handled at surveillance or recertification depending on how material they are, and planning for them is cheaper than discovering at recertification that three years of drift has to be absorbed at once.