Sooner or later, a client asks for it. A procurement team sends over a security questionnaire, an enterprise buyer makes it a condition in the contract, or a European customer wants proof you handle their data properly. ISO 27001 is the answer to all three, and for most Indian IT services companies, SaaS firms, and BPOs, it stops being optional the moment you start selling to larger organisations.
ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It doesn't prescribe specific technology. What it does is require you to identify your information security risks systematically, decide what to do about each one, document those decisions, and prove to an independent auditor that the whole thing actually runs — not just on paper.
If you're reading older guides that talk about ISO 27001:2013, ignore them. That version is dead.
ISO/IEC 27001:2022 replaced the 2013 edition in October 2022, and the International Accreditation Forum set a three-year transition window that closed on 31 October 2025. Certificates still referencing the 2013 standard are no longer valid — auditors won't recognise them, and neither will the clients asking to see them. New certifications have been issued exclusively against the 2022 version since April 2024.
If your organisation is holding a lapsed 2013 certificate, you're not doing a "transition" anymore. You're starting a fresh certification cycle against the 2022 standard, and it's worth being clear-eyed about that rather than hoping a quick upgrade audit will fix it.
The main clauses — 4 through 10, covering context, leadership, planning, support, operation, evaluation, and improvement — only got modest updates. Clause 6.3 is genuinely new, requiring that changes to the ISMS happen in a planned way rather than ad hoc. Clause 4.2 now explicitly asks which interested-party requirements will be addressed through the ISMS.
Annex A is where the real restructure happened. The old 114 controls across 14 domains became 93 controls across four themes:
Eleven controls are entirely new, and they're the part most organisations actually have to build from scratch — threat intelligence, information security for cloud services, ICT readiness for business continuity, physical security monitoring, configuration management, information deletion, data masking, data leakage prevention, monitoring activities, web filtering, and secure coding.
Each control now also carries attributes — control type (preventive, detective, corrective), security properties (confidentiality, integrity, availability), and cybersecurity concepts (identify, protect, detect, respond, recover) — which makes mapping against frameworks like SOC 2 or NIST CSF far less painful than it used to be.
ISO 27001:2022 requires specific documented information. These are the ones auditors will ask for:
The Statement of Applicability is where most first-time applicants lose time. It isn't a tick-box exercise — every exclusion needs a defensible reason tied back to your risk assessment, and auditors probe this harder than almost anything else.
For a small to mid-sized organisation starting from a reasonable baseline, plan for 4 to 8 months from gap analysis to certificate. Companies with existing security maturity sometimes move faster; organisations starting from scratch, or with a wide multi-site scope, routinely take longer.
The part that's hardest to compress is the evidence trail. Auditors want to see the ISMS operating over a period, not switched on the week before Stage 2.
Certification body fees — priced on headcount, scope, and number of sites. For a small Indian company this often lands in the ₹1.5 lakh to ₹5 lakh range across the three-year cycle, including surveillance audits.
Implementation and consulting — gap analysis, documentation, risk assessment, internal audit, and preparation support, which varies with how much you build in-house.
If someone offers an ISO 27001 certificate in two weeks for a flat fee with no audit, that certificate is worthless. Confirm your certification body is accredited under NABCB in India or a member of the IAF.
Most organisations don't fail ISO 27001 because their security is bad. They fail because the Statement of Applicability doesn't tie back to the risk assessment, the internal audit was done as a formality, or the eleven new 2022 controls were never properly implemented.
LegalDev's approach starts with an honest gap analysis, builds ISMS documentation around how your business genuinely operates, runs your internal audit properly, prepares your team for auditor interviews, and stays with you through Stage 1 and Stage 2 — and beyond, through the surveillance cycle.
No. The transition period set by the International Accreditation Forum ended on 31 October 2025. Certificates referencing the 2013 version are no longer recognised, and all new certifications are issued against ISO/IEC 27001:2022.
The main clauses changed only modestly, with a new Clause 6.3 on planned changes. Annex A was restructured from 114 controls across 14 domains into 93 controls across four themes — Organisational, People, Physical, and Technological — including 11 entirely new controls.
Typically 4 to 8 months for a small or mid-sized organisation, depending on your starting security maturity and how wide your ISMS scope is.
Three years, with surveillance audits usually conducted annually and a full recertification audit at the end of the cycle.
No, it isn't a legal requirement. It's driven by commercial demand — enterprise clients, overseas buyers, and tender processes frequently require it.
The central ISMS document listing all 93 Annex A controls, stating whether each applies and justifying every inclusion or exclusion against your risk assessment.
Legally, yes. Practically, most first-time applicants underestimate the risk assessment and Statement of Applicability, ending up with nonconformities that delay certification.
ISO 27001 certifies a management system and results in a certificate. SOC 2 is an attestation report by a CPA firm, more common with US buyers. The underlying controls overlap substantially.
Nonconformities are raised, and you're given a window to close them with corrective action evidence. Major nonconformities can require a follow-up audit visit.
Not entirely. It gives you the security governance framework that supports GDPR's security obligations, but GDPR also covers lawful basis and data subject rights it doesn't address.
Check that it's accredited by NABCB in India, or any IAF member internationally. An unaccredited certificate won't be accepted by clients who verify it.