What is ISO/IEC 27001 certification?
- What it managesConfidentiality, integrity and availability of information, driven by a risk assessment you own.
- Who certifies to itIT and SaaS companies, BPO and GCC operations, fintech, healthcare data handlers, and anyone answering an enterprise security questionnaire.
- Why it matters in IndiaThe certificate enterprise buyers ask for alongside DPDP Act readiness and CERT-In incident reporting.
ISO/IEC 27001 is the international standard for an information security management system. The 2022 edition restructured Annex A into 93 controls across four themes, organisational, people, physical and technological, and added 11 controls covering threat intelligence, cloud services, secure coding and data leakage prevention. Certification is what turns "we take security seriously" into something an enterprise procurement team can accept.
Edition status. The transition from ISO/IEC 27001:2013 closed on 31 October 2025. Certificates still citing the 2013 edition are no longer valid, and those organisations recertify against the 2022 edition rather than transition into it.
Climate action amendment. Amendment 1:2024 added climate change to the clause 4.1 context requirement.
The Statement of Applicability is the document that gets you caught out
It is the one ISO 27001 artefact experienced buyers actually read, and the one most often written as a formality. It must list all 93 Annex A controls, state whether each is applicable, justify every exclusion, and record implementation status. Excluding a control because it is inconvenient, rather than because it genuinely does not apply, is a major nonconformity, and it is visible to anyone who reads the document.
Who needs ISO/IEC 27001?
Certification is almost always triggered by a specific buyer requirement rather than an internal decision. These are the segments where it comes up.
| Segment | What usually triggers it |
|---|---|
| SaaS and software product companies | Enterprise security reviews and data processing agreements |
| IT services, BPO and GCC operations | Client contractual requirements and cross-border data handling |
| Fintech, lending and payment businesses | Partner bank and regulator expectations on information security |
| Healthtech and health data processors | Sensitive personal data handling and customer due diligence |
| E-commerce and marketplace platforms | Payment and customer data exposure at scale |
| Any vendor answering a security questionnaire | The certificate answers most of the questionnaire on its own |
The auditable clauses of ISO/IEC 27001:2022
What each clause actually demands, and what an auditor will ask to see against it.
| Clause | Title | What it requires |
|---|---|---|
| 4 | Context of the organisation | Internal and external issues, interested parties and their requirements, and the certification scope in writing. Since the 2024 climate amendment you must also determine whether climate change is a relevant issue. |
| 5 | Leadership | Top management accountability, a signed policy, and roles and responsibilities assigned and communicated. Auditors interview leadership directly, and delegation to a quality manager is a finding. |
| 6 | Planning | Risks and opportunities, measurable objectives, and documented plans setting out what will be done, by whom, with what resources and how results are evaluated. |
| 7 | Support | Resources, competence, awareness, communication, and control of documented information including version control, access and retention. |
| 8 | Operation | Operational planning and control of the processes that deliver your security requirements, plus performing the information security risk assessment at planned intervals and when significant change occurs, and implementing the risk treatment plan. Clause 8 is where the Annex A controls stop being a spreadsheet. |
| 9 | Performance evaluation | Monitoring and measurement, internal audit covering every clause by independent auditors, and a management review with all required inputs. |
| 10 | Improvement | Nonconformity handling with root cause analysis, corrective action, verification of effectiveness, and continual improvement of the system. |
What ISO/IEC 27001 actually gets you
Unblocks enterprise deals
The certificate is what procurement and legal teams accept in place of auditing you themselves, which shortens security review cycles measurably.
Structures DPDP readiness
The asset inventory, access control, supplier and incident processes are the same machinery the Digital Personal Data Protection Act obligations run on.
Incidents get handled, not improvised
Annex A 5.24 to 5.28 give you a defined response path, which matters when CERT-In reporting timelines apply.
Cloud and supplier risk gets owned
The 2022 edition added an explicit cloud services control, so shadow SaaS surfaces during the asset exercise.
Secure development becomes evidence
Secure coding, environment separation and change control become records you can show, not claims you make.
Travels internationally
An accredited certificate is recognised through the IAF arrangement, so an overseas customer does not need to audit you.
Documented information ISO/IEC 27001 requires
The records an auditor will ask for, and the clause behind each one.
| Document or record | Why the auditor wants it |
|---|---|
| ISMS scope statement | Clause 4.3, defining which parts of the business, which locations and which systems are covered. Buyers read this line first. |
| Information security policy and topic-specific policies | Clause 5.2 and Annex A 5.1, approved by top management and communicated. |
| Risk assessment methodology and results | Clause 6.1.2, with consistent, repeatable criteria for likelihood, impact and acceptance. |
| Risk treatment plan | Clause 6.1.3, mapping each treated risk to the controls that address it and naming the owner. |
| Statement of Applicability (SoA) | Clause 6.1.3 d. The defining ISO 27001 document: all 93 Annex A controls listed, each included or excluded with justification and implementation status. |
| Asset inventory and acceptable use | Annex A 5.9 to 5.11, covering information, hardware, software and cloud services. |
| Access control records | Annex A 5.15 to 5.18, including joiner, mover and leaver evidence, which is the most commonly failed control. |
| Supplier security and cloud service records | Annex A 5.19 to 5.23, including the new control on cloud service security. |
| Incident management records | Annex A 5.24 to 5.28, with evidence of response, lessons learned and evidence handling. |
| Business continuity and ICT readiness | Annex A 5.29 to 5.30, plus test records. |
| Secure development records | Annex A 8.25 to 8.31, including secure coding and separation of environments. |
| Internal audit reports and management review minutes | Clauses 9.2 and 9.3, mandatory before stage 2. |
How to get ISO/IEC 27001 certified
Nine stages. The last two are set by ISO/IEC 17021-1 and are the same for every standard, which is why a second certification costs far less than the first.
Gap analysis against the standard
We audit what you already do against every auditable clause of ISO/IEC 27001 and hand back a gap register, not a sales document. Most organisations are already meeting 40 to 60 percent of the requirements without having written them down.
Scope, context and risk
Fix the certification scope in writing, the sites, processes and exclusions it covers, then build the clause 4 context, interested parties and the risk register that the auditor will trace everything else back to.
Documented information
Policy, objectives, process maps, procedures and the records each clause requires. We supply working templates and adapt them to how you actually operate, because an auditor tests the system you run, not the one you filed.
Implementation and training
Roll the system out across the departments in scope and run awareness training, plus competence training for the people who will hold specific responsibilities. Keep attendance and competence records; they are audited.
Internal audit
A full internal audit covering every clause and every process in scope, by someone independent of the work being audited. Findings are logged as nonconformities and closed with corrective action, and this evidence is mandatory before a certification body will proceed.
Management review
Top management formally reviews performance against the standard's required inputs: audit results, objectives, nonconformities, feedback and improvement opportunities. Minutes are a stage 1 audit deliverable.
Stage 1 audit (readiness)
The certification body reviews your documentation, confirms the scope, checks your internal audit and management review are real, and identifies what it will focus on in stage 2. Findings here are usually fixable in days.
Stage 2 audit (implementation)
An on-site or remote audit of the system in operation: interviews, records and evidence sampled against each clause. Major nonconformities must be closed before a recommendation for certification; minors are closed within an agreed window.
Certificate issued, then maintained
The certification body issues a certificate with a three-year cycle. Surveillance audits follow in years one and two, and a recertification audit before the third anniversary. Miss a surveillance audit and the certificate can be suspended or withdrawn.
Check accreditation before you buy a certificate
ISO writes standards. It does not audit anyone, does not issue certificates and does not permit its logo to be used on one, so any certificate that presents itself as issued by ISO is wrong on its face. A certificate is worth what its accreditation is worth. In India the accreditation body is the National Accreditation Board for Certification Bodies (NABCB), which operates under the Quality Council of India, accredits certification bodies against ISO/IEC 17021-1, and is a signatory to the IAF Multilateral Recognition Arrangement, which is what makes an Indian certificate acceptable abroad. Before signing, ask for the certification body's accreditation number, confirm the standard and scope are inside its accredited scope, and verify the certificate on the accreditation body's directory or on IAF CertSearch. A certificate issued in 24 hours with no audit is not a certificate a tender committee, an OEM or an enterprise security review will accept.
Start with a ISO/IEC 27001 gap analysis
A free consultation with an IncorpX certification specialist: what you already meet, what is missing, an honest timeline, and what the audit will cost.
What ISO/IEC 27001 costs
Two separate costs, paid to two different parties. Anyone quoting a single all-in number for an accredited certificate is quoting one of them and hoping you do not ask about the other.
| Cost | Paid to | What drives it |
|---|---|---|
| IncorpX professional fee | IncorpX | Fixed and quoted upfront. From ₹14,999 for ISO/IEC 27001, depending on scope, sites and how much of the system already exists. |
| Certification audit fee | The certification body | Audit days, calculated from effective headcount, number of sites and sector risk category under the IAF mandatory documents. |
| Surveillance audit fees | The certification body | Years 1 and 2 of the cycle. Typically a fraction of the initial certification audit. |
| Recertification audit fee | The certification body | Before the third anniversary, to issue a new three-year certificate. |
| Auditor travel and expenses | The certification body | At actuals, where the audit is conducted on site. |
The cheapest quote is usually the unaccredited one
If one quotation is dramatically below the others, the difference is almost never efficiency. It is the audit days. An accredited certification body cannot reduce audit duration below what the IAF mandatory documents require for your headcount and risk category, so a quote that undercuts that arithmetic is either not accredited for ISO/IEC 27001, or is not planning to conduct the audit it is quoting for.
Other ISO standards for your sector
Ordered by how often they are held alongside ISO/IEC 27001. Because clauses 4 to 10 are shared, a second standard is largely new operational content rather than a new system.
ISO/IEC 27001 guides and reference reading
Longer reference reading on ISO/IEC 27001 and on ISO certification generally.
Frequently asked questions about ISO/IEC 27001
13 questions answered against ISO/IEC 27001:2022 and the ISO/IEC 17021-1 certification rules as they stand in August 2026.
Get ISO/IEC 27001 certified without the guesswork
Talk to an IncorpX certification specialist for free. Accredited certification bodies, an honest timeline, and a gap analysis before you commit.

