Skip to main content
CERT-In Empanelled — Since 2008 with continuous certification

ISO 27001 Consulting and Certification Services in India

End-to-end ISMS implementation, gap assessment, internal audit, and certification body coordination from a team that is ISO 27001 certified itself. Get audit-ready with structured processes, not just documentation.

2022
Edition
93 Controls
Annex A Coverage
6,700+
Assessments
Since 2008
CERT-In Empanelled

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

Where it actually binds

One Indian regulator names ISO 27001. It is not the one buyers assume

ISO 27001 is sold in India as the thing that satisfies everybody. It is worth knowing which instrument names it, which names something else, and which never had an opinion.

InstrumentWhat it says about ISO 27001Reference
SEBI CSCRF Names the standard directly, and the position moved. The master circular of 20 August 2024 made ISO 27001 certification mandatory under PR.IP.S16 for both Market Infrastructure Institutions and Qualified REs, to be obtained within a year. The technical clarifications of 28 August 2025 then restated it for Qualified REs alone, who are now in SEBI’s words "encouraged and recommended" to certify. MIIs are unchanged. A Qualified RE still carrying this as a regulatory deadline is carrying a commercial decision instead. PR.IP.S16 · clarified 28 Aug 2025
RBI Directions, 2026 The six entity-specific Directions that replaced the 2016 Framework on 31 July 2026 name ISO 22301, the business continuity standard, at para 163, as a best practice the BCP and DR policy should adopt. The board-approved information security policy and the VA/PT cadence at para 151 are stated as obligations in the Directions’ own terms. An ISO 27001 ISMS is a common way to evidence them, and that is a mapping we make, not a mapping the text makes. Directions, 2026 · paras 151, 163
CERT-In Governs who is permitted to perform the audit, not which standard you certify against. Empanelment attaches to the auditing firm and is the precondition every Indian regulator applies to the assessment itself. Empanelment
DPDP Act, 2023 Section 8(4) obliges a data fiduciary to take reasonable security safeguards. It describes an outcome and leaves the means open, which is precisely why a certified ISMS is useful here: it is documentary evidence of a chosen, audited method instead of an assertion that safeguards were reasonable. Section 8(4) · Rules notified 2025
Enterprise procurement In practice this is what moves ISO 27001 up the priority list in India. Vendor security questionnaires, global customer onboarding, investor diligence ahead of a raise or a listing, and a large share of public tenders treat the certificate as a gate. Commercially it behaves like a requirement whatever its regulatory standing. Buyer-driven

SEBI CSCRF

What it says about ISO 27001
Names the standard directly, and the position moved. The master circular of 20 August 2024 made ISO 27001 certification mandatory under PR.IP.S16 for both Market Infrastructure Institutions and Qualified REs, to be obtained within a year. The technical clarifications of 28 August 2025 then restated it for Qualified REs alone, who are now in SEBI’s words "encouraged and recommended" to certify. MIIs are unchanged. A Qualified RE still carrying this as a regulatory deadline is carrying a commercial decision instead.

RBI Directions, 2026

What it says about ISO 27001
The six entity-specific Directions that replaced the 2016 Framework on 31 July 2026 name ISO 22301, the business continuity standard, at para 163, as a best practice the BCP and DR policy should adopt. The board-approved information security policy and the VA/PT cadence at para 151 are stated as obligations in the Directions’ own terms. An ISO 27001 ISMS is a common way to evidence them, and that is a mapping we make, not a mapping the text makes.

CERT-In

What it says about ISO 27001
Governs who is permitted to perform the audit, not which standard you certify against. Empanelment attaches to the auditing firm and is the precondition every Indian regulator applies to the assessment itself.
Reference
Empanelment

DPDP Act, 2023

What it says about ISO 27001
Section 8(4) obliges a data fiduciary to take reasonable security safeguards. It describes an outcome and leaves the means open, which is precisely why a certified ISMS is useful here: it is documentary evidence of a chosen, audited method instead of an assertion that safeguards were reasonable.

Enterprise procurement

What it says about ISO 27001
In practice this is what moves ISO 27001 up the priority list in India. Vendor security questionnaires, global customer onboarding, investor diligence ahead of a raise or a listing, and a large share of public tenders treat the certificate as a gate. Commercially it behaves like a requirement whatever its regulatory standing.
Reference
Buyer-driven

What you are buying

A management system that has to run, not a folder that has to exist

The reason ISO 27001 engagements go wrong is almost never the controls. It is that the organisation buys a document set when the standard is describing a management system: something with a scope, a risk assessment that gets revisited, owners who make decisions, evidence that accumulates, and a review cycle that runs whether or not an auditor is coming. Annex A of the 2022 edition carries 93 controls across four themes, organisational, people, physical and technological, and a registrar will test a sample of them. But the clauses that fail an audit are the management-system ones: a risk assessment methodology that was written once and never applied, a Statement of Applicability whose exclusions have no justification behind them, an internal audit programme that exists as a calendar invitation, a management review with no minutes. Those are the findings that turn into major non-conformities, because they say the system is not operating. Our engagements are built so that the ISMS is running before Stage 1 and not assembled for it, and because our team tests controls technically as well as documenting them, the evidence a registrar samples was produced by something that actually happened.

The commitment

The certificate runs three years, and the first audit is not the expensive part

Most budgets cover year one. The certificate is conditional throughout its life, and the cycle below is the one to plan against.

01 Readiness review

Stage 1

What happens
The registrar reviews the ISMS documentation, the scope statement, the risk assessment and the Statement of Applicability, and forms a view on whether the system is ready to be tested in operation.
What it is for
To surface gaps while they are still cheap. A Stage 1 that raises findings is doing its job; the failure mode is treating it as a formality and carrying the same gaps into Stage 2.
02 Certification audit

Stage 2

What happens
The registrar tests whether the ISMS operates as documented, sampling controls, interviewing owners, and tracing evidence back to the decisions it came from.
Where it is decided
On the management-system clauses more often than on Annex A. A major non-conformity here means a corrective action cycle and a further visit before the certificate is issued.
03 Surveillance

Years two and three

What happens
Narrower audits confirming the ISMS is still operating: internal audits ran, risks were reassessed, management reviewed, incidents were handled, corrective actions closed.
The common failure
An ISMS built for a date instead of for use. Surveillance is where the difference becomes visible, and a certificate can be suspended.
04 Recertification

Year three

What happens
A full audit again, against a scope that has usually moved: new products, new entities, new cloud estate, new jurisdictions. Scope drift between certification and recertification is the single most common cause of an unexpectedly large recertification quote.

Where audits are won

The Statement of Applicability is the document a registrar reads first

It records a decision for every one of the 93 Annex A controls. The decisions below are the ones that draw questions, and the reason is the same in each case: the justification is missing, not wrong.

The Statement of Applicability is the document a registrar reads first
StateWhat it meansWhat follows
Excluded, with a reason A control is recorded as not applicable and the justification names the specific fact that makes it so: no in-house development, no physical data centre, no payment card data in scope. This is the healthy case and it is entirely legitimate. Exclusions are expected; what a registrar tests is whether the stated reason survives contact with the scope.
Excluded, because it was difficult A control is marked not applicable but the scope plainly includes the thing it governs. Cryptography excluded by an organisation handling customer data; supplier security excluded by one running on four SaaS platforms. The most reliable way to fail Stage 2. It is also the easiest finding for an auditor to reach, because it is visible from the document alone before anybody is interviewed.
Included, implemented on paper A control is marked applicable and implemented, and the evidence is the policy that describes it, and not a record of it operating. Survives Stage 1 and rarely survives Stage 2. A policy demonstrates intent; an access review with dates, names and outcomes demonstrates a control.
Included, evidenced by testing A technical control is marked applicable and the evidence includes results from assessment work: vulnerability management, secure development, network security, logging. The strongest position, and usually the cheapest. Penetration testing and vulnerability assessment you already buy generate ISMS evidence directly; when the testing programme and the certification programme are procured separately, the same assurance is paid for twice.
Key
  • Holds under audit
  • Passes Stage 1, fails Stage 2
  • Fails on the document

What ISO 27001 Certification Costs in India

Two separate fee streams, a three-year cycle, and the seven things that move the number

Most quotes are hard to compare because they bundle two different things. Certification body fees are paid to an accredited registrar for the audit itself, and they are broadly standardised by auditor-days. Consulting fees are paid for getting the ISMS built and the evidence ready, and they vary enormously with how much of it already exists. A quote that does not separate the two cannot be compared with one that does. The other thing buyers routinely miss is that certification is a three-year commitment, not a one-off: a Stage 1 readiness review and a Stage 2 certification audit in year one, then surveillance audits in years two and three, then recertification. Budgeting only for year one understates the real cost by a wide margin.

Stage 1 and Stage 2 are separate audits

Stage 1 reviews documentation and readiness; Stage 2 is the certification audit proper, testing whether the ISMS actually operates. A Stage 1 that surfaces gaps is doing its job, but a failed Stage 2 means paying for the audit twice.

Surveillance audits in years two and three

The certificate runs three years and is conditional. Surveillance audits check the ISMS is still operating, and recertification at year three is a fuller exercise. Budget the cycle, not the first audit.

Scope is the single largest lever

The number of locations, legal entities, employees in scope and systems inside the ISMS boundary drives auditor-days more than anything else. A tightly drawn, defensible scope is the cheapest decision available, and it is made before anyone quotes.

Current maturity decides the consulting half

An organisation with documented policies, a working risk register and existing access reviews needs a fraction of the implementation support of one starting from nothing. This is where quotes diverge most, and where an honest gap assessment pays for itself.

Accreditation of the certification body matters

A certificate from a body accredited by a recognised authority is what enterprise procurement and global customers actually check. An unaccredited certificate is cheaper and can fail the due diligence it was bought to pass.

Running it alongside SOC 2 or CSCRF cuts the total

Access control, change management, risk assessment, vendor management and incident response do double duty across ISO 27001 and the SOC 2 Trust Services Criteria, and SEBI CSCRF evidence maps onto the same ISMS. Sequencing them as one programme rather than two avoids paying twice for the same evidence.

Technical testing you already buy is reusable

Penetration testing and vulnerability assessment results feed the ISMS evidence base directly. If your testing programme and your certification programme are procured separately with no shared evidence, you are paying for the same assurance twice.

Methodology

How a compliance engagement runs

Every engagement follows this process through Lemon, our proprietary audit management platform.

Security Brigade delivers ISO 27001 consulting through a structured, phased methodology that covers every requirement of the standard. Unlike documentation-only consultants, our technical team performs actual controls testing and evidence validation. Our proprietary platform Lemon manages the entire compliance lifecycle, generating evidence packages, tracking control implementation, and ensuring nothing falls through the cracks between assessment and certification.

Discovery
01

Scoping and Gap Assessment

Define the ISMS scope, identify applicable Annex A controls, assess current security posture against every ISO 27001 requirement, and produce a prioritised gap analysis report with clear remediation roadmap.

02

Risk Assessment and Treatment

Conduct formal information security risk assessment using a methodology aligned to ISO 27001 Clause 6.1. Identify threats, vulnerabilities, and impacts. Develop the risk treatment plan mapping each risk to specific controls.

03

ISMS Policy Suite Development

Develop the complete suite of ISMS policies, procedures, and documentation required by the standard, including the Statement of Applicability, information security policy, access control policy, incident management procedures, and asset management documentation.

Testing
04

Technical Controls Implementation

Implement and configure technical security controls across network, application, endpoint, and cloud environments. Our security team validates that controls are operational and effective, not just documented on paper.

05

Awareness and Training

Conduct security awareness training for staff and specialised training for ISMS roles including risk owners, asset owners, and internal auditors. Ensure the organisation can operate and maintain the ISMS independently.

Delivery
06

Internal Audit

Execute a formal internal audit covering all ISMS processes and Annex A controls. Identify non-conformities, observations, and opportunities for improvement. Produce audit reports that meet certification body expectations.

07

Management Review

Facilitate the management review meeting with organisational leadership, presenting ISMS performance metrics, risk treatment status, internal audit findings, and continuous improvement actions required by Clause 9.3.

08

Certification Body Coordination

Coordinate with the selected certification body through Stage 1 documentation review and Stage 2 certification audit. Manage the entire interaction including evidence submission, auditor queries, non-conformity resolution, and certificate issuance.

"We have SAP, SCADA, 200+ web apps, and factories running legacy systems. Most security firms understand IT or OT — not both. Security Brigade tested our corporate network, our plant floor, our SAP interfaces, and our cloud migration path in one engagement with one methodology. The OT findings alone justified the engagement, but the real value was having everything in a single risk register."
VP Security, Manufacturing Conglomerate
Vice President — Information Security

Read more client stories →

Continuous Compliance with ShadowMap

The audit gives you a snapshot. ShadowMap gives you the always-on view.

An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.

See the full ShadowMap platform 30-day POC available · Platform Only · Service Only · Hybrid

The platform underneath

The instrument sets the cadence. B-52 is what runs at it.

An auditor asks what evidence exists for the Annex A controls that involve testing, and how recent it is. A platform that runs continuously changes the second half of that question more than the first.

See the B-52 platform Built and run by Security Brigade

FAQ

ISO 27001 in India, answered specifically

The questions that decide scope, budget and timing. Talk to our team for the ones that depend on your estate.

Contact us
Does Security Brigade issue the ISO 27001 certificate?+
No, and no consultancy can. The certificate is issued by an accredited certification body, and ISO/IEC 17021-1 requires that body to be independent of the consulting that prepared you. That separation is the reason readiness work exists as its own discipline. We build and run the ISMS with you, perform the internal audit, prepare the evidence, and coordinate with your chosen registrar through Stage 1 and Stage 2 until the certificate is issued.
Which Indian regulator requires ISO 27001?+
SEBI is the one that names it. CSCRF made ISO 27001 certification mandatory under PR.IP.S16 for Market Infrastructure Institutions and Qualified REs alike; the technical clarifications of 28 August 2025 then softened it for Qualified REs, who are now "encouraged and recommended" to certify instead of obliged. MIIs are unchanged. Elsewhere the pressure is commercial, not regulatory: enterprise vendor assessments, global customer onboarding, investor diligence and public tenders routinely gate on the certificate, which is why for most Indian organisations the honest answer is that it is a market requirement with one regulatory exception.
How much of the work carries over to SOC 2?+
Enough to sequence them together, and the overlap sits in specific families, not in a headline percentage. Access control, change management, risk assessment, vendor and supplier management, incident response, logging and monitoring, and human-resources security do genuine double duty: the same evidence, produced once, answers both. What does not carry over is the shape: ISO 27001 certifies a management system against a standard, while SOC 2 produces a CPA firm’s report on controls you defined against the Trust Services Criteria. Run as one programme the second framework costs a fraction of what it costs run cold.
Does penetration testing form part of an ISO 27001 programme?+
In practice, yes, and registrars expect to see technical testing evidence. Annex A includes controls on the management of technical vulnerabilities and on secure development, and the standard requires security measures to be chosen on the basis of assessed risk, an argument that is difficult to make without evidence about the systems themselves. We run the testing inside the programme so results feed the ISMS evidence base directly through Lemon instead of arriving as a separate report nobody maps back.
How long does certification take?+
Three to six months to Stage 2 for most organisations, driven by current maturity far more than by size. An organisation with documented policies, a working risk register and access reviews already running is doing a gap-closure exercise. One starting from nothing is building a management system, and the honest timeline is the longer end. Scope is the other lever: locations, legal entities and systems inside the ISMS boundary drive both the timeline and the registrar’s auditor-days, and it is the cheapest decision available because it is made before anybody quotes.
What happens to the certificate if our scope changes?+
It stays valid for what it covers, which is exactly the problem when the scope statement no longer describes the business. A certificate naming one entity and one location does not cover the subsidiary acquired last year or the product built in a second cloud account, and enterprise procurement teams read the scope line. Scope changes are handled at surveillance or recertification depending on how material they are, and planning for them is cheaper than discovering at recertification that three years of drift has to be absorbed at once.

Ready to Start Your ISO 27001 Certification Journey?

Talk to our compliance team for a scoping consultation and detailed project plan tailored to your organisation.

Typically responds within 1 business day · No commitment required

Request a Scoping Call