Skip to content
Back to Blog
·9 min read·compliance

ISO 27001 Certification India: Step-by-Step 2022 Roadmap

Learn the complete ISO 27001 certification India roadmap: 6 phases from gap to certificate, built for Indian startups navigating DPDP and RBI requirements.

BR

Bachao.AI Research Team

Cybersecurity Research

Check DPDP Compliance

Compliance risk for Indian SMBs

Non-compliance with the DPDP Act 2023 carries penalties up to ₹250 crore. This post explains what's at stake and what action to take.

ISO 27001:2022 is an international information security standard that provides a structured six-phase implementation roadmap: gap assessment, risk assessment, ISMS documentation, controls implementation, internal audit, and external certification. For Indian organisations, this roadmap leads to a certified Information Security Management System (ISMS) — one that satisfies enterprise procurement requirements, DPDP Act 2023 "reasonable security safeguards" obligations, and RBI IT Framework expectations simultaneously. Most Indian startups complete the journey in six to twelve months from a low baseline. This guide covers every phase — from gap assessment to receiving your certificate — with the specific documentation, decisions, and common pitfalls your team needs to know before you begin.

Why ISO 27001 Certification Is Now a Business Requirement for Indian Companies

Indian enterprises increasingly require ISO 27001 certification as a vendor prerequisite before signing contracts. Sectors under regulatory scrutiny — banking, fintech, healthcare, and defence supply chains — either demand it outright or use it as a shortlisting criterion. Beyond procurement, the Digital Personal Data Protection Act (DPDP) 2023 expects organisations to implement "reasonable security safeguards," and an ISO 27001-certified ISMS is the most defensible evidence that your organisation meets that standard. The DPDP compliance page covers how the two frameworks align.

Certification is also a forcing function. Startups that go through the ISO 27001 process discover configuration drift, undocumented access privileges, and asset inventories that nobody maintained. The audit is uncomfortable precisely because it is thorough — and that thoroughness is the point.

USD 2.35 millionAverage cost of a data breach in India (IBM Cost of a Data Breach 2024)
68%Breaches in 2024 that involved a human element (Verizon DBIR 2024)

The cost of a single breach now exceeds the total investment most startups would spend on a fully certified ISMS. The ROI case is not complicated.

What Changed from ISO 27001:2013 to 2022

The 2022 revision reorganised the standard significantly. Annex A collapsed 14 security domains and 114 controls into 4 themes and 93 controls. Nothing was dropped from a security standpoint — controls were consolidated — and 11 new controls were added to address modern threats, including threat intelligence, cloud service security, data masking, web filtering, and secure coding.

ThemeControlsRepresentative Areas
Organizational37Information security policies, supplier relationships, incident management, business continuity
People8Personnel screening, training, remote work security, disciplinary process
Physical14Physical entry controls, equipment maintenance, clean desk, secure disposal
Technological34Endpoint protection, web filtering, data masking, threat intelligence, vulnerability management
The standard also strengthened alignment with other ISO management systems (ISO 9001, ISO 14001), making integrated systems easier to run. Organisations certified under the 2013 version had until October 31, 2025 to transition. If you are starting fresh, you certify against the 2022 version from day one.
pie title ISO 27001 2022 Annex A Control Distribution "Organizational Controls" : 37 "People Controls" : 8 "Physical Controls" : 14 "Technological Controls" : 34

The Six-Phase ISO 27001 Certification Roadmap for India

graph TD A[Gap Assessment] --> B[Risk Assessment] B --> C[Risk Treatment Plan] C --> D[Statement of Applicability] D --> E[ISMS Policies and Procedures] E --> F[Controls Implementation] F --> G[Internal Audit] G --> H[Management Review] H --> I[Stage 1 Document Audit] I --> J[Stage 2 Certification Audit] J --> K{Audit Outcome} K -->|Certified| L[Certificate Issued] K -->|Minor Nonconformity| M[Corrective Action] M --> J L --> N[Annual Surveillance Audit] N --> O[Recertification at Year 3] style A fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style B fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style C fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style D fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style E fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style F fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style G fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style H fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style I fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style J fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style K fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style L fill:#1e3d2f,stroke:#10B981,color:#e2e8f0 style M fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 style N fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style O fill:#1e3d2f,stroke:#10B981,color:#e2e8f0

Phase 1 — Gap Assessment

A gap assessment maps your current security controls against ISO 27001:2022 Annex A. The output is a prioritised list of missing or incomplete controls, estimated remediation effort, and a realistic timeline to readiness. This phase typically takes two to four weeks. Do not skip it — teams that jump straight to documentation consistently underestimate scope and stall mid-project when implementation takes far longer than planned.

Run a free VAPT scan as a productive companion to your gap assessment — it gives you empirical data on your technical exposure before you begin designing your ISMS, and the findings feed directly into your risk register.

Phase 2 — Risk Assessment and Treatment

ISO 27001 is risk-based. You must identify your information assets, assess threats and vulnerabilities against each, assign likelihood and impact scores, and produce a risk register. The risk treatment plan then documents your decision for each identified risk: mitigate, accept, transfer, or avoid.

⚠️
WARNING
A common failure at Stage 2 audits is a risk register that has not been updated since the initial assessment. Auditors expect to see evidence that your organisation reviews and updates the register at defined intervals — typically at least annually and after significant changes to systems, processes, or the threat landscape. A static risk register is treated as a nonconformity.

The risk methodology does not have to be complex, but it must be consistent and documented. Choose a scoring scale, apply it uniformly across all assets, and maintain version history so auditors can see the register evolving over time.

Phase 3 — ISMS Design and Documentation

Clauses 6 through 10 of ISO 27001 require a specific set of documented information. The mandatory documents include:

    1. Information Security Policy
    2. Risk Assessment and Risk Treatment methodology
    3. Statement of Applicability — lists all 93 Annex A controls with justification for inclusion or exclusion
    4. Risk Treatment Plan with control implementation status
    5. Information Security Objectives
    6. Competence and training records
    7. Operational planning and control procedures
    8. Internal audit programme and audit reports
    9. Management review records
    10. Nonconformity and corrective action records
The Statement of Applicability is the document auditors scrutinise most carefully. Every excluded control must have a documented justification. Included controls must have traceable evidence of implementation. Treat the SoA as a living document — it evolves as your environment changes.

Phase 4 — Controls Implementation

Once your SoA is approved, you implement the controls you have committed to. For Indian startups, the controls that typically require the most effort are:

    1. Access control reviews and privilege lifecycle management (A.5.18, A.8.2, A.8.3)
    2. Supplier and third-party security management, including cloud providers (A.5.19 to A.5.23)
    3. Incident response procedures with tested runbooks and defined escalation paths (A.5.24 to A.5.28)
    4. Vulnerability management and documented patch cadence (A.8.8)
    5. Secure development lifecycle practices if you ship software (A.8.25 to A.8.31)
    6. Threat intelligence integration — one of the 11 new controls in 2022 (A.5.7)
Collect evidence as you implement. Screenshots, configuration exports, policy acknowledgment records, and training completion logs — all of these are evidence artefacts an auditor will request. Implementing controls without contemporaneous evidence leaves you unable to prove the work was done.

Phase 5 — Internal Audit and Management Review

Before inviting an external auditor, you must complete at least one full internal audit cycle. Internal audit is not self-assessment — it must be performed by someone independent of the area being audited. Findings are documented as conformities, observations, or nonconformities. Nonconformities require root-cause analysis and documented corrective actions with target closure dates.

The management review follows the internal audit. Senior leadership — including the founder or CTO — formally reviews ISMS performance, audit results, risk register status, and security objectives. This session must be minuted. Auditors check that management is genuinely engaged, not just signing a document.

💡
TIP
Run your internal audit at least six to eight weeks before your Stage 1 external audit. This gives your team time to close nonconformities and produce corrective action evidence before the certification auditor arrives. Auditors are not looking for a perfect organisation — they are looking for evidence that you identify and resolve problems systematically.

Phase 6 — External Certification Audit

External audits are conducted by accredited certification bodies. The audit runs in two stages.

Stage 1 — Document Review: The auditor reviews your ISMS documentation: policies, SoA, risk register, internal audit records, and management review minutes. This is typically one to two days on-site or remote. The auditor confirms your ISMS is sufficiently designed and that a Stage 2 audit is appropriate. Observations raised at Stage 1 should be addressed before Stage 2 begins.

Stage 2 — Certification Audit: The auditor verifies that your documented ISMS is actually operational. They interview staff at multiple levels, observe processes in practice, sample evidence for each applicable Annex A control, and check that your monitoring and measurement activities are producing usable data. Nonconformities found at Stage 2 — classified as major or minor — must be closed with evidence before the certificate is issued. Major nonconformities require a follow-up visit; minor nonconformities can usually be closed by submitting evidence remotely.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

Maintaining ISO 27001 Certification: What Indian SMBs Must Know

Certification is valid for three years, with annual surveillance audits in years one and two. Each surveillance audit checks that the ISMS remains operational, that previously identified nonconformities are closed, and that continual improvement activity is occurring. A recertification audit in year three restarts the three-year cycle.

The most common reason organisations lose certification is treating the ISMS as a project rather than an operating process. After the certificate arrives, some teams stop updating the risk register, let training records lapse, and skip internal audits. Surveillance auditors arrive the following year and find an ISMS that exists on paper but has not been maintained in practice. Suspension of certification follows.

Build ISMS maintenance into your regular operating calendar — quarterly risk register reviews, annual training refreshes, and scheduled internal audit cycles — rather than treating each surveillance audit as a scramble to reconstruct evidence.

ISO 27001 and India's Regulatory Landscape

ISO 27001 aligns well with India's evolving security requirements across multiple sectors. CERT-In's guidelines at cert-in.org.in expect organisations to maintain documented security frameworks with tested incident response capabilities — an operational ISMS directly satisfies this expectation. The Data Security Council of India (dsci.in) recognises ISO 27001 as a foundational standard in its security maturity assessment frameworks for Indian industry.

For fintech startups under RBI's IT Framework and healthcare companies preparing for DPDP compliance obligations, an ISO 27001 ISMS provides the governance backbone that sector-specific requirements build on. Bachao.AI, built by Dhisattva AI Pvt Ltd (a DPIIT Recognized Startup), provides automated VAPT scanning that generates the technical vulnerability evidence certification auditors specifically require under Annex A's vulnerability management and monitoring controls.

If your organisation is also preparing for DPDP compliance, the DPDP compliance page explains how an ISMS maps to the Act's data protection and accountability obligations — the two frameworks are complementary, not duplicative.

🎯Key Takeaway
ISO 27001:2022 certification takes six to twelve months for most Indian startups and is structured around six phases: gap assessment, risk assessment, ISMS documentation, controls implementation, internal audit and management review, and external certification audit. The organisations that fail at Stage 2 almost always documented their intentions but did not change their actual operating practices. Collect evidence as you implement, maintain a living risk register, run a genuine internal audit with enough lead time to close findings, and treat the ISMS as a permanent operating process — not a one-time project.

Frequently Asked Questions

How long does ISO 27001:2022 certification take for a startup in India?
For most startups beginning from a low baseline, six to twelve months is realistic. Organisations with existing security documentation and mature access controls can reach certification in as few as four to six months. The timeline depends on the number of identified gaps, the pace of controls implementation, and how quickly internal audit findings can be closed before the external audit.
What changed from ISO 27001:2013 to 2022, and what do Indian companies need to do now?
ISO 27001:2022 reorganised Annex A from 14 domains and 114 controls into 4 themes and 93 controls. Eleven new controls were added covering threat intelligence, cloud security, data masking, web filtering, configuration management, and secure coding. The standard's main clauses were also updated for better alignment with ISO 9001 and ISO 14001. For Indian companies, the transition deadline was October 31, 2025 — any new certification now starts against the 2022 version from day one.
Is ISO 27001 certification mandatory for startups in India?
ISO 27001 is not universally mandated by law, but it is increasingly required by enterprise customers as a vendor prerequisite in banking, insurance, defence supply chains, and government procurement. RBI's IT Framework and SEBI's cybersecurity circulars reference ISO 27001-aligned controls. The DPDP Act 2023 does not name the standard explicitly but requires "reasonable security safeguards," and certification is strong, defensible evidence of compliance.
What is a Statement of Applicability and why do ISO 27001 auditors in India scrutinise it so closely?
The Statement of Applicability lists all 93 Annex A controls, states whether each applies to your organisation, documents the justification for any exclusions, and records the implementation status of included controls. It is the central document linking your risk treatment decisions to specific security controls. Indian certification auditors scrutinise it closely because it is the foundation of your certification scope — a poorly maintained SoA is one of the most common reasons Indian organisations fail at Stage 2, particularly when DPDP or RBI-mandated controls are excluded without documented justification.
Does ISO 27001 certification in India require penetration testing under DPDP?
ISO 27001:2022 does not mandate a specific penetration testing frequency, but Annex A control A.8.8 requires active vulnerability management and A.5.25 covers assessment of information security events. For Indian companies, the DPDP Act 2023 requirement for "reasonable security safeguards" raises the bar — certification bodies in India expect regular technical vulnerability assessments as evidence of both ISO control effectiveness and DPDP posture. Run a free VAPT scan before your Stage 1 audit to build a baseline evidence record that maps to A.8.8 and simultaneously strengthens your DPDP compliance case.
How do we choose an accredited certification body for ISO 27001 in India?
Look for certification bodies accredited by a member of the International Accreditation Forum network — in India, the Quality Council of India is the national accreditation body. Verify the CB's accreditation directly on the QCI website before engaging. Obtain quotes from at least two or three bodies, compare their sector experience and audit team credentials, and check references from organisations of similar size and scope. Accreditation status, not brand recognition, is the primary selection criterion.
BR

Bachao.AI Research Team

Cybersecurity Research

AI-powered security research and threat intelligence from the Bachao.AI team. Covering the latest vulnerabilities, CVEs, and cybersecurity developments affecting Indian businesses.

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

See if your business is DPDP Act compliant

Free automated scan — risk score in under 2 hours. No credit card required.

Check DPDP Compliance
Find your vulnerabilitiesStart free scan →