We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Cybersecurity blog

ISO 27001 Certification in India: Process, Timeline & Cost

PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

ISO 27001 Certification in India: Process, Timeline & Cost

Most ISO 27001 projects in India do not fail at the audit. They fail six weeks before it, when someone opens the risk register for the first time since the consultant handed it over and realises it describes a company that does not exist.

The controls are ticked. The policies are signed. But the asset owners named in the documents left last year, the encryption standard says AES-256 while the actual database sits unencrypted on a shared VM, and nobody has run an internal audit because the calendar entry got deleted when the person who set it up resigned. This is the real state of a lot of certified Information Security Management Systems (an ISMS is simply the set of policies, processes and controls you use to manage information risk). Certified on paper, hollow in practice. This guide walks you through what it actually takes to get ISO 27001 in India, what it costs, how long it really takes, and where teams quietly lose control of the project.

What the certificate actually proves (and what it does not)

ISO 27001:2022 is a management-system standard, not a technical checklist. Passing it does not mean you are secure. It means you have a repeatable, documented way of deciding what to protect, deciding how to protect it, checking that the protection works, and fixing it when it does not. The auditor is testing your system, not your firewall rules.

That distinction matters because clients and regulators read the certificate differently from how the standard defines it. A BFSI client running vendor due diligence treats your certificate as a proxy for competence. The RBI, under its outsourcing and IT-governance directions, will still expect its own evidence regardless of your ISO status. So the certificate opens doors, but it does not close audits. Two documents carry the real weight: the Statement of Applicability (the SoA lists every Annex A control and whether you applied it, with justification) and your risk treatment plan. If those two are honest and current, everything else follows. If they are copied from a template, the whole thing is theatre.

The 2022 version changed the control set, and old templates still get it wrong

If a consultant hands you an SoA with 114 controls in 14 domains, they are working from the 2013 version and you should stop the engagement. ISO 27001:2022 restructured Annex A into 93 controls across four themes: Organisational, People, Physical, and Technological. It also introduced 11 genuinely new controls that trip up teams who cut and paste from older projects.

New 2022 controlWhat it forces you to actually do
5.7 Threat intelligenceConsume and act on external threat feeds — CERT-In advisories count, but you must show you triage them
5.23 Cloud services securityDocument security responsibilities across your AWS/Azure/GCP shared-responsibility boundary
8.9 Configuration managementMaintain hardened baselines (CIS benchmarks) and detect drift, not just a wiki page
8.10 Information deletionProve data is actually deleted at end of retention — relevant to DPDP erasure duties
8.11 Data maskingMask or tokenise sensitive fields in non-production environments
8.12 Data leakage preventionHave a working DLP control, not a policy that says do not leak data
8.16 Monitoring activitiesCentralised logging and alerting with defined thresholds, reviewed by a human
8.23 Web filteringControl which external sites systems and users can reach
8.28 Secure codingA secure SDLC with code review and dependency scanning, evidenced in commits

These are not paperwork controls. An auditor who knows the 2022 set will ask to see the CERT-In advisory you received last month and what you did with it. If your answer is we forward them to a mailbox nobody reads, that is a nonconformity waiting to be written up.

The seven stages, and where each one really goes wrong

The path to certification is well defined. The trouble is that teams treat the middle stages as documentation exercises and only wake up during the Stage 2 audit. Here is the sequence as it actually plays out, with the failure mode for each.

1. Scope definition

You decide which parts of the business the ISMS covers — legal entities, locations, services, systems. The classic mistake is scoping too wide to impress clients, then drowning in evidence for departments that have nothing to do with the certified service. Scope the smallest boundary that satisfies your client and regulator. You can widen it at the next surveillance audit. For an Indian SaaS firm this is usually one product, its production cloud environment, and the engineering and support teams that touch it.

2. Gap assessment

You compare where you are against the 93 controls and Clauses 4 to 10. Done properly this is uncomfortable, because it surfaces the controls you have been pretending to run. The failure mode here is a green-heavy spreadsheet produced to keep leadership calm. A gap assessment that finds everything compliant is a gap assessment that was not performed.

3. Risk assessment and treatment

This is the spine of the whole standard, and the single biggest reason audits go sideways. Clause 6.1.2 requires a defined, repeatable risk methodology. You identify risks to confidentiality, integrity and availability, assess them against a criteria you set, and decide to treat, tolerate, transfer or terminate each one. The SoA then flows from the risks, not the other way round. Teams routinely build the SoA first from a template and reverse-engineer risks to match. An experienced auditor spots this in ten minutes by asking one question: show me the risk that led you to apply control 8.24 on cryptography. If you cannot trace it, your ISMS is upside down.

4. Implementation

You put the controls in place and, critically, start generating evidence. Access reviews, backup restore tests, change tickets, training completion records, supplier assessments. Evidence only counts once it accumulates over time, which is why this stage cannot be rushed in the final month.

5. Internal audit and management review

Clauses 9.2 and 9.3 are mandatory and independently verifiable. You must run at least one full internal audit and one documented management review before the certification body will proceed. Skipping or faking these is the fastest way to a major nonconformity, because the auditor checks the dates and the attendance and the minutes. A management review with no leadership present is a finding.

6. Stage 1 audit (documentation readiness)

The certification body reviews your ISMS documentation and confirms you are ready for the real thing. It is not a formality. If your SoA, risk methodology or internal audit records are weak, Stage 1 will tell you, and you get a gap of a few weeks to fix it before Stage 2.

7. Stage 2 audit (certification)

The auditor spends days on site or remotely, interviewing people and sampling evidence to confirm the ISMS operates as documented. Findings are graded as minor or major nonconformities, or opportunities for improvement. A major nonconformity means no certificate until you close it with corrective action. Minors get a corrective-action plan and usually do not block the certificate.

A scene from a Stage 2 audit

The auditor is sitting with the DevOps lead of a Pune-based payments platform. The SoA says control 8.15 logging is applied. The policy says logs are retained for 12 months and reviewed daily. So the auditor asks to see the log review for the third Tuesday of last month. The DevOps lead pulls up a Grafana dashboard. Beautiful graphs, live metrics. The auditor nods and asks the second question: who looked at this on that Tuesday, and what did they do about the two failed root-login alerts at 02:14. Silence. The dashboard shows the data, but nobody reviews it, and there is no record of anyone acting on an alert. That is a minor nonconformity written against 8.16 monitoring, because the control exists but the process around it does not. The lesson the team took away was the one every team eventually learns: the auditor does not audit your tools, they audit your habits.

How long it really takes

Ignore anyone promising certification in 30 days. It is technically possible to buy a certificate that fast from a non-accredited body, and it is worthless the moment a serious client checks the accreditation mark. A credible timeline for a first-time Indian organisation depends mostly on your starting maturity and how much staff time you can free up.

Organisation profileRealistic timeline to certificate
Startup, 20-50 staff, cloud-native, some security hygiene3 to 4 months
Mid-size, 50-250 staff, mixed on-prem and cloud4 to 6 months
Enterprise, regulated (BFSI/health), multiple locations6 to 9 months
Low maturity, no existing policies, part-time project owner7 to 12 months

The two hidden time-sinks are almost always the same. First, evidence needs to age — an auditor wants to see three to six months of access reviews and backup tests, which you cannot fabricate retrospectively. Second, the mandatory internal audit and management review cannot happen until the ISMS has been running, which pushes the earliest honest certification date to roughly three months after go-live even for a well-run startup.

What it costs in India, without the vague ranges

Cost splits into three buckets, and only one of them is the certification body. People conflate the three and then feel misled. Here is the honest breakdown in INR for a mid-size organisation. Numbers vary with headcount, scope and location, but these are the bands practitioners actually see.

Cost componentTypical range (INR)Notes
Gap assessment / readiness1,50,000 to 5,00,000One-off; scales with scope and number of sites
Consulting / implementation support3,00,000 to 12,00,000The big variable; depends on your internal capacity
Stage 1 + Stage 2 certification audit1,50,000 to 6,00,000Paid to the certification body; priced on auditor-days
Annual surveillance audits (year 2 and 3)75,000 to 3,00,000 per yearSmaller than initial; still mandatory
Recertification (year 3)1,25,000 to 4,00,000Full re-audit of the ISMS
Tooling (GRC, SIEM, DLP, MDM)Highly variableOften the largest true cost if you lack it

Two cost traps deserve calling out. Choosing the cheapest certification body is a false economy if it is not accredited by a recognised body such as one under the International Accreditation Forum — an unaccredited certificate fails procurement checks and you pay twice. And under-scoping consulting to save money simply transfers the work to your own team at a higher hourly cost and a slower pace. The cheapest project overall is usually the one with an experienced auditor guiding it, not the one with the lowest line item.

Where ISO 27001 meets Indian regulation

ISO 27001 does not replace your statutory obligations, and treating it as a shield is a mistake. It gives you the scaffolding to meet several Indian requirements more easily, but the mapping is partial.

  • CERT-In: the April 2022 directions on incident reporting within six hours and log retention for 180 days are stricter than ISO defaults — align your incident and logging controls to CERT-In, not just to Annex A.
  • DPDP Act 2023: ISO controls 8.10 deletion, 8.11 masking and the broader privacy posture support your obligations as a Data Fiduciary, but consent, notice and grievance handling sit outside ISO and need their own treatment.
  • RBI outsourcing and cyber-security frameworks: for BFSI, ISO 27001 is often a baseline expectation, but the RBI expects its own governance evidence, board oversight and specific controls that ISO does not enumerate.
  • PCI DSS: if you handle cardholder data, ISO 27001 overlaps on roughly a third of the controls but does not substitute for the 12 PCI requirements — you run both, and you can share evidence between them.

The practical move is to build one control library and map each control to every framework it satisfies. Audit once, evidence many. Running ISO, PCI, DPDP and CERT-In as four separate projects is how teams burn out and produce four mediocre programmes instead of one strong one.

The mistakes that sink first-time certifications

After enough audits, the failure patterns become predictable. These are the ones that recur, in rough order of how often they cause trouble.

  • Template-driven SoA with no line back to a real risk — the fastest tell of a hollow ISMS.
  • Risk register written once and never revisited, so it names owners who have left and systems that were decommissioned.
  • No evidence of the mandatory internal audit or management review, or evidence dated the week before the Stage 2 audit.
  • Policies that describe controls the company does not actually operate — the AES-256 standard on the unencrypted database.
  • Scope creep that pulls in departments unrelated to the certified service, multiplying evidence for no client benefit.
  • Treating certification as a one-time event rather than a system that must keep running for surveillance audits.
  • Choosing an unaccredited certification body and discovering during a client procurement that the certificate is not recognised.
  • No named ISMS owner with real authority — the project stalls the moment its part-time champion gets pulled onto something else.

A pre-audit checklist you can actually use

Two weeks before Stage 2, run through this. If you cannot tick every item honestly, you are not ready, and it is cheaper to postpone than to collect nonconformities.

  • Every applied control in the SoA traces to at least one risk in the risk register.
  • The risk register was reviewed within the last quarter and every owner named is still employed and aware of the risk.
  • At least one full internal audit is complete, with findings logged and corrective actions tracked to closure.
  • A management review has happened with senior leadership physically present and minutes recorded.
  • You can produce three to six months of evidence for access reviews, backup restore tests, change management and training.
  • Your incident-response process meets CERT-In six-hour reporting and 180-day log retention, not just the ISO baseline.
  • Every policy describes a control that genuinely runs — walk each policy to its real-world evidence.
  • The certification body you have engaged is accredited by a recognised accreditation body, and you have checked the mark.
  • One named person owns the ISMS with the authority and time to keep it running after the certificate arrives.

The point of all this

Come back to where we started. A certificate that describes a company that does not exist is worse than no certificate, because it creates false confidence in you and in everyone who trusts it. The organisations that get real value from ISO 27001 are the ones that treat the audit as a forcing function to build habits that outlast the auditor: the log actually reviewed, the risk actually owned, the backup actually restored. Get those right and the certificate is a by-product. Get them wrong and the certificate is a liability with a nice logo.

If you would rather have senior CERT-In empanelled auditors sit in the room with your team and build an ISMS that survives Stage 2 and every surveillance audit after it, that is the work we do hands-on at CyberSigma — no templates, no theatre.

FAQs

How much does ISO 27001 certification cost in India?

For a mid-size organisation, budget roughly INR 6 to 20 lakh in the first year across gap assessment, implementation support and the Stage 1 and Stage 2 audits, plus smaller annual surveillance audit fees in years two and three. The certification body itself is usually the smallest component; consulting and any missing tooling drive most of the cost. Startups with good hygiene can land at the lower end, while regulated enterprises with multiple sites reach the higher end.

How long does it take to get ISO 27001 certified?

A realistic first-time timeline is three to four months for a cloud-native startup with some existing security hygiene, four to six months for a typical mid-size firm, and six to nine months for a regulated enterprise. The floor is set by two things that cannot be rushed: evidence needs three to six months to accumulate, and the mandatory internal audit and management review can only happen once the ISMS has actually been running.

What is the difference between ISO 27001:2013 and 2022?

The 2022 version restructured Annex A from 114 controls in 14 domains down to 93 controls across four themes — Organisational, People, Physical and Technological — and added 11 new controls covering areas like threat intelligence, cloud security, data masking, secure coding and monitoring. If a consultant is still working from the 114-control structure, they are out of date and their documentation will not pass a knowledgeable auditor.

Does ISO 27001 make me DPDP or CERT-In compliant automatically?

No. ISO 27001 gives you scaffolding that supports several Indian obligations, but it does not replace them. CERT-In requires six-hour incident reporting and 180-day log retention that are stricter than ISO defaults. The DPDP Act adds consent, notice and grievance-handling duties that sit outside ISO entirely. Map your ISO controls to each framework, but treat the statutory requirements as their own workstream.

What is the most common reason first-time ISO 27001 audits fail?

A Statement of Applicability built from a template with no traceable link to a real risk assessment. Auditors test this by picking a control and asking which risk led you to apply it. If you cannot trace the control back to a risk in your register, it signals that the whole ISMS was reverse-engineered from a template rather than built from an honest look at your actual risks.

Do I need a consultant, or can we do ISO 27001 in-house?

You can do it in-house if you have someone who genuinely understands the standard and has the authority and time to run the project. In practice, most teams underestimate the risk-methodology and evidence-discipline work and stall. A good consultant or auditor is usually the cheapest path overall because they prevent the false starts, template traps and unaccredited-body mistakes that force teams to redo work.

Naveen Kumar

Naveen Kumar

CyberSigma is a CERT-In empanelled cybersecurity firm helping Indian businesses with VAPT, ISO 27001, PCI DSS, SOC 2 and DPDP compliance — delivered by senior auditors.

Free 1-minute check
ISO 27001 Readiness Checker
See how close you are to ISO 27001 certification — free, in 5 questions.
Try it free →

Leave A Comment

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →