ISO/IEC 27001:2022 Certification Consulting
Secure Minds runs ISO/IEC 27001:2022 implementations end-to-end — gap analysis against the current Annex A control set, risk assessment and treatment per Clause 6.1.2/6.1.3, ISMS documentation, internal audit under Clause 9.2, and certification-audit readiness support. This is practitioner-led work: engagements are scoped and delivered by consultants with 15+ years of hands-on ISMS implementation and audit experience, not templated toolkits.
What Changed in the 2022 Revision
Organizations still certified against ISO/IEC 27001:2013 Annex A should be planning their transition now — certification bodies require migration to the 2022 control set, and legacy 2013 certificates are being phased out on a fixed timeline by accredited CBs.
- Annex A restructured from 14 clauses / 114 controls to 4 themes / 93 controls: Organizational (37), People (8), Physical (14), Technological (34).
- 11 new controls introduced, including A.5.7 Threat Intelligence, A.5.23 Information Security for Use of Cloud Services, A.5.30 ICT Readiness for Business Continuity, A.7.4 Physical Security Monitoring, A.8.9 Configuration Management, A.8.10 Information Deletion, A.8.11 Data Masking, A.8.12 Data Leakage Prevention, A.8.16 Monitoring Activities, A.8.23 Web Filtering, and A.8.28 Secure Coding.
- Clause 4.2 and Clause 6.1.3(c) now require explicit consideration of interested-party requirements and the Statement of Applicability rationale for each control — a common non-conformity point at Stage 1 audit if not documented rigorously.
- Mandatory clauses (Clause 4–10) are unchanged in structure but reworded for alignment with Annex SL harmonized management-system language.
Our Methodology, Mapped to the Standard
| Phase | Clause Reference | What We Deliver |
|---|---|---|
| Scoping & Context | Cl. 4.1, 4.2, 4.3 | ISMS scope statement, interested-party register, applicability boundary |
| Leadership & Policy | Cl. 5.1–5.3 | Information security policy, roles/responsibilities matrix, management commitment evidence |
| Risk Assessment & Treatment | Cl. 6.1.2, 6.1.3 | Risk methodology, risk register, Statement of Applicability (SoA) mapped to all 93 Annex A controls |
| Objectives & Planning | Cl. 6.2 | Measurable security objectives tied to business risk |
| Support | Cl. 7.1–7.5 | Competence records, awareness program, documented-information control procedure |
| Operation | Cl. 8.1–8.3 | Operational control implementation, supplier/third-party risk process |
| Performance Evaluation | Cl. 9.1–9.3 | Monitoring/measurement plan, internal audit program (9.2), management review (9.3) |
| Improvement | Cl. 10.1–10.2 | Nonconformity and corrective action process, continual improvement log |
We do not deliver a documentation-only ISMS. Every control implementation is evidenced with operational artifacts a Stage 2 auditor will actually sample.
Typical Engagement Timeline
For a mid-market Indian organization (50–300 employees), certification is typically achievable in 4–6 months from kickoff: gap assessment (2–3 weeks), risk assessment and SoA (3–4 weeks), control implementation and documentation (8–10 weeks), internal audit and management review (2 weeks), Stage 1 and Stage 2 certification audit (scheduled with your chosen accredited CB).
Organizations pursuing both ISO/IEC 27001:2022 and SOC 2 Type II can rationalize a significant portion of control evidence — access control, change management, and risk assessment artifacts largely overlap between ISO Annex A and the AICPA Trust Services Criteria. We scope dual-framework engagements to avoid duplicated evidence-collection effort.
Case Study
Enabling a Bangalore-Based Financial Advisory Firm to Achieve ISO 27001 Certification with Secure Minds — full engagement writeup with scope, timeline, and outcome.
Serving Enterprises Beyond Gurugram — Bangalore, Hyderabad, Pune & Chennai
Secure Minds is headquartered in Gurugram, and the majority of our ISO/IEC 27001:2022 and GRC engagements are delivered fully remote — gap-assessment interviews, documentation review, control walkthroughs, and internal-audit support run over video and secure document exchange, with on-site visits scheduled only where physical control verification (data-centre access, badge/CCTV review, the physical-security controls under Annex A.7) requires it.
This model has already run successfully outside Delhi NCR: see our case study on taking a Bangalore-based financial advisory firm through ISO/IEC 27001:2022 certification, where the full engagement — gap assessment through Stage 2 certification audit — was delivered in 4.5 months without a Gurugram-based consultant relocating.
If your organisation is based in Bangalore, Hyderabad, Pune, Chennai, or elsewhere in India and needs ISO 27001, SOC 2, PCI-DSS, or DPDPA compliance support, the engagement model is the same one we run for Gurugram/NCR clients — a named lead consultant, a fixed engagement timeline, and on-site visits scheduled only when the control set genuinely requires physical verification.
Frequently Asked Questions
How long does ISO 27001 certification take in India?
For a mid-market company, 4–6 months from kickoff to certification audit, assuming existing security controls are reasonably mature. Organizations with limited existing controls should budget 6–9 months.
What does ISO 27001 certification cost in India?
All-in cost (consulting + certification body fees) for a mid-market Indian organization typically ranges from ₹5.5–8 lakh, split roughly between consulting fees and CB certification/surveillance-audit fees. Final cost depends on scope size, number of locations, and control maturity.
Do we need to recertify if we’re already ISO 27001:2013 certified?
Yes — accredited certification bodies require a transition audit to the 2022 Annex A control set within the CB’s published transition deadline. We can run this as a gap-only engagement rather than a full re-implementation if your 2013 ISMS is well-maintained.
Is ISO 27001 certification mandatory in India?
Not mandatory by default, but increasingly required contractually by enterprise customers, and it satisfies control-framework expectations under India’s DPDPA, 2023 for organizations processing personal data at scale.
Discuss Today to scope your ISO/IEC 27001:2022 engagement.

