At a Glance
- Standard: ISO/IEC 27001:2022, the global standard for Information Security Management Systems (ISMS)
- Annex A controls: 93 controls across 4 themes (Organizational, People, Physical, Technological)
- Typical timeline: 4-6 months from gap analysis to certification audit
- Engagement model: Gap analysis + remediation + internal audit + certification audit support + annual surveillance
- Indicative investment: INR 1.5L-5L for consulting depending on scope and locations (certification body audit fees separate)
- Response time: instant, no delay. Gap analysis call scheduled same or next business day after scoping
What is ISO/IEC 27001:2022?
ISO/IEC 27001:2022 is the international standard for Information Security Management Systems (ISMS). It defines requirements for establishing, implementing, maintaining and continually improving an ISMS, with 93 controls in Annex A grouped under four themes: Organizational, People, Physical and Technological. Certification is issued by an accredited certification body after a two-stage audit.
Codesecure delivers ISO 27001 as a complete implementation programme: scope definition, gap analysis against Annex A, risk assessment, Statement of Applicability (SoA), policy and procedure authoring, control implementation support, internal audit, management review and certification audit accompaniment. Our consultants are ISO 27001 Lead Implementer and Lead Auditor certified.
Why It Matters
ISO 27001 is the most widely recognised information security certification globally and is increasingly mandatory in B2B India. Enterprise customers ask for it in vendor questionnaires, government tenders treat it as a baseline, and global SaaS buyers in EU, US, APAC expect it before procurement. Without ISO 27001 you lose deals that you would otherwise win on capability.
Beyond sales enablement, ISO 27001 forces discipline: documented information security policies, risk-based controls, incident management, supplier security, business continuity, internal audit, management review. The 2022 update aligns it closely with cloud security, threat intelligence and data masking, making it more relevant to modern Indian SaaS, fintech and digital businesses.
What's Included
Codesecure's ISO 27001 programme covers the entire ISMS lifecycle:
Scope DefinitionISMS boundaries, locations, services, asset and information flow mapping
Gap AnalysisCurrent-state assessment against ISO 27001:2022 clauses 4-10 + Annex A
Risk Assessment & TreatmentAsset-based or scenario-based risk methodology, risk treatment plan
Statement of ApplicabilitySoA covering all 93 Annex A controls with applicability justification
Policy & Procedure AuthoringInformation Security Policy + 12-15 supporting procedures
Control ImplementationHands-on implementation of organizational, people and technical controls
Internal AuditFull ISO 27001 internal audit by ISO 27001 Lead Auditor with NC reporting
Management ReviewTop-management review meetings with documented minutes and decisions
Stage 1 & Stage 2 Audit SupportConsultant present during certification body audits to handle queries
Annual SurveillanceYear 2 and Year 3 surveillance preparation and audit support
Indicative Pricing
ISO 27001 consulting fees vary by ISMS scope, headcount and number of locations. Certification body audit fees are separate and charged directly by the accredited certification body (BSI, DNV, BV, TUV, etc.).
Consulting fee, India
INR 1.5L – 5L+ taxes
Fixed-fee engagement covering gap analysis, ISMS documentation, control implementation support, internal audit and certification audit accompaniment. Annual surveillance support is quoted separately and typically lower.
Request a Scoped Quote
StartupINR 1.5L – 2.5LUp to 25 staff, single location
SMBINR 2.5L – 4L25-150 staff, 1-2 locations
Mid-MarketINR 4L – 5L+150+ staff, multi-location
Get a Free ISO 27001 Gap Analysis Call
45-minute call with our Lead Implementer. Bring your current ISMS state, applicable regulations and certification target date, leave with a phased implementation roadmap. Instant response, no delay.
Book Free Gap Analysis Call
Implementation Methodology
Every ISO 27001 engagement follows a 5-phase methodology from gap analysis through certification and ongoing surveillance:
1
Gap Analysis & Scope Definition
Free 30-minute scoping call, NDA, ISMS scope decision, asset and information flow mapping, full gap assessment against ISO 27001:2022 clauses 4-10 and Annex A.
2
Risk Assessment & ISMS Build
Risk methodology selection, risk register, treatment plan, Statement of Applicability for all 93 Annex A controls, policy and procedure authoring (ISP plus 12-15 supporting documents).
3
Control Implementation & Remediation
Hands-on implementation of organizational, people and technical controls. Evidence collection. Awareness training. Incident response process. Supplier security and business continuity.
4
Internal Audit & Management Review
Full ISO 27001 internal audit by ISO 27001 Lead Auditor. Non-conformity reporting. Management review meeting with documented minutes. Corrective actions closed before stage 1.
5
Certification Audit & Surveillance
Stage 1 (documentation review) and Stage 2 (implementation audit) accompaniment by your named consultant. Annual surveillance support in Year 2 and Year 3.
What You Get
Every ISO 27001 programme ships with the same audit-ready handoff:
Gap Analysis ReportCurrent-state assessment with control-level findings and priority
Risk Register & Treatment PlanDocumented risks with treatment, owners and target dates
Statement of ApplicabilitySoA for all 93 Annex A controls with justification
ISMS Policy & Procedure PackInformation Security Policy + 12-15 supporting procedures
Internal Audit ReportFull ISO 27001 internal audit findings with corrective actions
Certification Audit SupportNamed consultant present during Stage 1 and Stage 2 audits
Programme Timeline
Most ISO 27001 programmes reach certification within 4-6 months. Instant response, no delay, gap analysis kickoff scheduled same or next business day after scoping.
Month 1
Gap Analysis & Scope
Scope definition, asset mapping, full gap assessment, risk methodology agreed.
Month 2-3
ISMS Build
Risk register, SoA, ISP and 12-15 procedures authored, controls remediation kicked off.
Month 4-5
Internal Audit
Full internal audit, management review, NC closure, evidence consolidated for certification.
Month 5-6
Certification
Stage 1 documentation review, Stage 2 implementation audit, certificate issued by accredited body.
// Frameworks & Standards We Cover
ISO/IEC 27001:2022
ISO/IEC 27002:2022
ISO 27017 (Cloud)
ISO 27018 (PII)
ISO 27701 (PIMS)
SOC 2 mapping
DPDP Act 2023
GDPR mapping
CIS Controls v8
NIST CSF mapping
Talk to an ISO 27001 Lead Implementer
30-minute call with our Lead Implementer. Discuss your ISMS scope, target certification date and current state with no sales pressure.
Schedule Free Call
Frequently Asked Questions
How long does ISO 27001 certification take?
Most Indian SMBs reach certification in 4-6 months from kickoff. Startups with a tight scope can compress to 3-4 months. Mid-market organisations with multi-location ISMS scopes typically run 6-9 months. The timeline is driven by control remediation pace, not paperwork, so engaged leadership and named control owners shorten it significantly.
What does ISO 27001 actually cost?
Consulting fees are typically INR 1.5L for startups (under 25 staff, single location), INR 2.5L-4L for SMBs (25-150 staff), and INR 4L-5L+ for mid-market with multi-location scopes. Certification body audit fees are separate and charged by accredited bodies like BSI, DNV, BV or TUV, usually INR 1L-3L for Stage 1 + Stage 2 combined. Annual surveillance fees in Year 2 and Year 3 are lower than Year 1.
What is new in ISO 27001:2022 compared to 2013?
ISO 27001:2022 restructured Annex A from 114 controls in 14 sections into 93 controls across 4 themes (Organizational, People, Physical, Technological). 11 new controls were added including threat intelligence, cloud security, ICT readiness for business continuity, data masking, data leakage prevention and configuration management. Transition deadline for existing 2013-certified organisations was October 2025.
How quickly can you start?
Instant response, no delay. We respond within an hour during business hours, send a fixed-fee scoped proposal in 24-48 hours under signed NDA, and start gap analysis the same day or next business day after sign-off.
Do you provide the certification body or only consulting?
We are the consulting partner. The certification audit must be performed by an independent accredited certification body to maintain audit independence required by ISO 17021. We recommend appropriate bodies based on your industry and geography (BSI, DNV, BV, TUV, etc.) and handle introductions, but the contract for certification is between you and the body directly.
Can ISO 27001 be combined with SOC 2 or DPDP work?
Yes, and it is usually cheaper and faster to do them together. ISO 27001 Annex A overlaps significantly with SOC 2 Trust Service Criteria and with DPDP Act 2023 reasonable security safeguards. A combined programme reuses risk assessment, policies, controls and evidence, reducing total effort by 30-40 percent versus running them serially.
Do we need to be a large company to get certified?
No. ISO 27001 is scope-driven, not size-driven. A 10-person SaaS startup can certify a scope covering only the SaaS product and supporting functions. Many of our clients are 15-50 person teams that win enterprise deals specifically because they got certified early. The standard scales down cleanly.
Ready to Get ISO 27001 Certified?
Codesecure runs the entire ISO 27001 programme: gap analysis, ISMS build, control implementation, internal audit and certification support. Free 30-minute gap analysis call, instant response, no obligation.
Get a Free Gap Analysis
See All Compliance