Trusted by 650+ Clients

McDonald's
Ernst & Young
Sopra Steria
BDO
Wipro
L&T
Airtel
ASTEMO
McDonald's
Ernst & Young
Sopra Steria
BDO
Wipro
L&T
Airtel
ASTEMO
McDonald's
Ernst & Young
Sopra Steria
BDO
Wipro
L&T
Airtel
ASTEMO

Overview: ISO 27001 Framework

ISO/IEC 27001 is a globally recognized standard for building and managing an effective Information Security Management System (ISMS). It helps organizations identify risks, protect sensitive data, and strengthen security across systems, processes, and third-party information.

Issued By
ISO/IEC 27001:2022, Including Amendment 1:2024
Annex A Controls
93, Across 4 Themes
Mandatory Clauses
4 To 10
Audit Structure
Stage 1 (ISMS Documentation) + Stage 2 (ISMS Implementation)
Certificate Validity
3 Years, With Annual Surveillance Audits In Years 2 And 3
Typical Timeline
3-4 Months From Gap Assessment To ISO 27001 Certification
2013 Version
Withdrawn, Invalid Since 31 October 2025

ISO 27001:2022 - What Changed, And Why The 2013 Version No Longer Counts

ISO/IEC 27001:2022 restructured Annex A from 114 controls across 14 domains into 93 controls across four themes, and introduced 11 new controls covering threat intelligence, cloud services security, data masking, data leakage prevention, web filtering, secure coding, configuration management, information deletion, physical security monitoring, monitoring activities, and ICT readiness for business continuity.

The 93 Annex A Controls

OrganisationalPeoplePhysicalTechnological
ThemeOrganisationalPeoplePhysicalTechnological
Controls3781434
CoversPolicies, Supplier Relationships, Cloud Services, Threat Intelligence, Incident ManagementScreening, Awareness Training, Disciplinary Process, Remote WorkingSecure Areas, Equipment, Clear Desk, Physical MonitoringAccess Control, Cryptography, Secure Development, Logging, Data Masking, Web Filtering
You are not required to implement all 93. You are required to review every one and record your decision in the Statement of Applicability, justifying each inclusion and each exclusion. Auditors treat the SoA as the central reference document across both Stage 1 and Stage 2, and an unjustified exclusion is one of the most common findings.

Stage 1 And Stage 2 Audits Explained

Stage 1 - ISMS Documentation Review

Stage 1 - ISMS Documentation Review

The certification body examines your ISMS scope, information security policy, risk assessment, risk treatment plan and Statement of Applicability. The output is a readiness verdict and a list of gaps to close.

Stage 2 - ISMS Implementation Audit

Stage 2 - ISMS Implementation Audit

Conducted after Stage 1, the certification body verify the controls are live and effective through evidence sampling, staff interviews and direct observation. They test whether people actually follow the policies you wrote.

The certificate is issued after Stage 2 closes successfully. Any non-conformity raised must
be resolved through a corrective action plan before issuance

ISO 27001 Internal Audit with Kratikal

Kratikal supports both stages by helping you with ISMS implementation and internal audit, making your organization ready for both the stages of external audit and the certification process.

Our Approach

01

Gap Assessment

We begin by assessing the organization’s current information security practices against ISO/IEC 27001 requirements. This helps identify gaps, define the ISMS scope, and set a roadmap for implementation.

02

Risk Assessment

We identify and evaluate risks related to data breaches, unauthorized access, and other security threats, focusing on identifying information security risks to ensure the confidentiality, integrity, and availability (CIA) criteria.

03

Policy Drafting

Based on the gap and risk findings, we draft essential policies such as the Information Security Policy, Access Control Policy, and Data Protection Policy customized to your business needs.

04

Implementation

We help implement the required controls and processes to operationalize the ISMS. This includes assigning responsibilities, integrating policies into workflows, and ensuring compliance with the standard.

05

Training

We provide training sessions to build awareness and ensure employees understand their roles in maintaining information security.

06

Internal Audit

A comprehensive internal audit is conducted to evaluate the effectiveness of the ISMS, identify any non-conformities, and recommend corrective actions before the certification audit.

07

Certification

Finally, we support your team through the ISO/IEC 27001 certification process—ensuring readiness for Stage 1 and Stage 2 audits, and helping resolve any issues identified by the certifying body.

Every ISO 27001:2013 certificate became invalid on October 31, 2025, regardless of its printed expiry. Organisations that missed it cannot take a transition audit; they must complete a full Stage 1 and Stage 2 certification against the 2022 standard, which costs more and takes longer than the transition path did.

If your certificate still references 2013, you are currently uncertified.

Why Do Organizations Need ISO 27001?

ISO 27001 is not mandated by Indian law. It is mandated by your customers. Enterprise procurement teams, BFSI clients and overseas buyers increasingly make a valid ISO/IEC 27001:2022 certificate a precondition for signing which turns a voluntary standard into a revenue gate.

Who Needs ISO 27001 Certification?

SaaS and Product Companies

SaaS and Product Companies

IT Services and BPO

IT Services and BPO

BFSI, NBFCs and Fintech

BFSI, NBFCs and Fintech

Healthtech and Hospitals

Healthtech and Hospitals

Manufacturing with Connected OT

Manufacturing with Connected OT

Organisation Entering a Government or PSU Tender

Organisation Entering a Government or PSU Tender

Our Trust Block

Compliance Projects Completed
SME's & Enterprises Served

Client Testimonials

★★★★★

Kratikal has been instrumental in guiding DAC through the ISO 27001 re-certification process. Their expertise and comprehensive support ensured a smooth transition, from preparation to successful completion. The team's proactive approach and attention to detail were crucial in meeting all compliance requirements seamlessly. We truly appreciate their dedication and professionalism.

Skanda BagepalliSupport Manager, DigitalApiCraft
★★★★★

We sincerely appreciate your outstanding support and guidance throughout the ISO certification process. Your efforts have been instrumental in the successful completion of this project. We would like to extend our special thanks to the team for their dedicated assistance and commitment, which made a significant difference. We look forward to continuing this partnership and receiving the same level of support as we embark on this long journey together.

Lokesh NSr. Software Engineer, TechFino
Capital Pvt Ltd

Benefits

Protection of Customer Data

Protection of Customer Data

Clear controls showing how customer data is stored, accessed, and deleted.

Adhere to legal and regulatory requirements

Adhere to legal and regulatory requirements

Maps directly to the "reasonable security safeguards" expected

Enhance security resilience

Enhance security resilience

A tested incident response and business continuity capability

Enhance brand reputation

Enhance brand reputation

Clears the security questionnaire stage of enterprise RFPs

FAQs

An ISO 27001 certified organisation must run an internal audit at least once a year to review the relevance and effectiveness of the controls deployed in its environment. The certification body also conducts annual surveillance audits in years two and three, followed by a full recertification audit in year four.

ISMS policies derive from the security controls listed in Annex A of ISO/IEC 27001. In the 2022 revision, Annex A contains 93 controls grouped into four themes - organisational, people, physical and technological and the policies act as the guidance for implementing them.

ISMS implementation covers defining scope, running a risk assessment, drafting policies, documenting roles and responsibilities, implementing the applicable Annex A controls, delivering awareness training, deploying supporting technical measures such as endpoint security, planning business continuity, and conducting an internal audit before the certification audit.

There is no fixed timeline for ISO 27001 certification. It depends largely on the scope, organization size, number of locations, complexity of operations, existing security controls, and specific business requirements.

Stage 1 is a documentation and readiness review in which the certification body examines the ISMS scope, policies, risk assessment and Statement of Applicability, and flags gaps. Stage 2 verifies that the controls are actually implemented and effective through evidence review, staff interviews and observation. The certificate is issued after Stage 2 is passed.

An ISO/IEC 27001 certificate is valid for three years, subject to annual surveillance audits by the certification body in years two and three. A full recertification audit is required before the three-year cycle ends.

The 2022 revision restructured Annex A from 114 controls in 14 domains down to 93 controls across four themes - organisational, people, physical and technological and introduced 11 new controls covering areas such as threat intelligence, cloud services security, data masking and secure coding. The 2013 version has been withdrawn, so all new certifications and transitions are issued against the 2022 standard.

ISO 27001 is a voluntary standard rather than a statutory requirement in India. In practice it is frequently mandated contractually by enterprise customers and in RFPs, and it is widely used as the control backbone for demonstrating the reasonable security safeguards expected under the Digital Personal Data Protection Act, 2023, although it does not cover every DPDP obligation on its own.

The Statement of Applicability is a mandatory document that lists every Annex A control and records whether it is included in the ISMS, with a justification for each inclusion or exclusion and a note on how included controls are implemented. Auditors treat it as a central reference during both Stage 1 and Stage 2.