ISO/IEC 27001 is a globally recognized standard for building and managing an effective Information Security Management System (ISMS). It helps organizations identify risks, protect sensitive data, and strengthen security across systems, processes, and third-party information.
ISO/IEC 27001:2022 restructured Annex A from 114 controls across 14 domains into 93 controls across four themes, and introduced 11 new controls covering threat intelligence, cloud services security, data masking, data leakage prevention, web filtering, secure coding, configuration management, information deletion, physical security monitoring, monitoring activities, and ICT readiness for business continuity.
| Theme | Organisational | People | Physical | Technological |
| Controls | 37 | 8 | 14 | 34 |
| Covers | Policies, Supplier Relationships, Cloud Services, Threat Intelligence, Incident Management | Screening, Awareness Training, Disciplinary Process, Remote Working | Secure Areas, Equipment, Clear Desk, Physical Monitoring | Access Control, Cryptography, Secure Development, Logging, Data Masking, Web Filtering |
The certification body examines your ISMS scope, information security policy, risk assessment, risk treatment plan and Statement of Applicability. The output is a readiness verdict and a list of gaps to close.
Conducted after Stage 1, the certification body verify the controls are live and effective through evidence sampling, staff interviews and direct observation. They test whether people actually follow the policies you wrote.
The certificate is issued after Stage 2 closes successfully. Any non-conformity raised must
be resolved through a corrective action plan before issuance
Kratikal supports both stages by helping you with ISMS implementation and internal audit, making your organization ready for both the stages of external audit and the certification process.
We begin by assessing the organization’s current information security practices against ISO/IEC 27001 requirements. This helps identify gaps, define the ISMS scope, and set a roadmap for implementation.
We identify and evaluate risks related to data breaches, unauthorized access, and other security threats, focusing on identifying information security risks to ensure the confidentiality, integrity, and availability (CIA) criteria.
Based on the gap and risk findings, we draft essential policies such as the Information Security Policy, Access Control Policy, and Data Protection Policy customized to your business needs.
We help implement the required controls and processes to operationalize the ISMS. This includes assigning responsibilities, integrating policies into workflows, and ensuring compliance with the standard.
We provide training sessions to build awareness and ensure employees understand their roles in maintaining information security.
A comprehensive internal audit is conducted to evaluate the effectiveness of the ISMS, identify any non-conformities, and recommend corrective actions before the certification audit.
Finally, we support your team through the ISO/IEC 27001 certification process—ensuring readiness for Stage 1 and Stage 2 audits, and helping resolve any issues identified by the certifying body.
Every ISO 27001:2013 certificate became invalid on October 31, 2025, regardless of its printed expiry. Organisations that missed it cannot take a transition audit; they must complete a full Stage 1 and Stage 2 certification against the 2022 standard, which costs more and takes longer than the transition path did.
If your certificate still references 2013, you are currently uncertified.
ISO 27001 is not mandated by Indian law. It is mandated by your customers. Enterprise procurement teams, BFSI clients and overseas buyers increasingly make a valid ISO/IEC 27001:2022 certificate a precondition for signing which turns a voluntary standard into a revenue gate.
SaaS and Product Companies
IT Services and BPO
BFSI, NBFCs and Fintech
Healthtech and Hospitals
Manufacturing with Connected OT
Organisation Entering a Government or PSU Tender
Kratikal has been instrumental in guiding DAC through the ISO 27001 re-certification process. Their expertise and comprehensive support ensured a smooth transition, from preparation to successful completion. The team's proactive approach and attention to detail were crucial in meeting all compliance requirements seamlessly. We truly appreciate their dedication and professionalism.
We sincerely appreciate your outstanding support and guidance throughout the ISO certification process. Your efforts have been instrumental in the successful completion of this project. We would like to extend our special thanks to the team for their dedicated assistance and commitment, which made a significant difference. We look forward to continuing this partnership and receiving the same level of support as we embark on this long journey together.
Clear controls showing how customer data is stored, accessed, and deleted.
Maps directly to the "reasonable security safeguards" expected
A tested incident response and business continuity capability
Clears the security questionnaire stage of enterprise RFPs
An ISO 27001 certified organisation must run an internal audit at least once a year to review the relevance and effectiveness of the controls deployed in its environment. The certification body also conducts annual surveillance audits in years two and three, followed by a full recertification audit in year four.
ISMS policies derive from the security controls listed in Annex A of ISO/IEC 27001. In the 2022 revision, Annex A contains 93 controls grouped into four themes - organisational, people, physical and technological and the policies act as the guidance for implementing them.
ISMS implementation covers defining scope, running a risk assessment, drafting policies, documenting roles and responsibilities, implementing the applicable Annex A controls, delivering awareness training, deploying supporting technical measures such as endpoint security, planning business continuity, and conducting an internal audit before the certification audit.
There is no fixed timeline for ISO 27001 certification. It depends largely on the scope, organization size, number of locations, complexity of operations, existing security controls, and specific business requirements.
Stage 1 is a documentation and readiness review in which the certification body examines the ISMS scope, policies, risk assessment and Statement of Applicability, and flags gaps. Stage 2 verifies that the controls are actually implemented and effective through evidence review, staff interviews and observation. The certificate is issued after Stage 2 is passed.
An ISO/IEC 27001 certificate is valid for three years, subject to annual surveillance audits by the certification body in years two and three. A full recertification audit is required before the three-year cycle ends.
The 2022 revision restructured Annex A from 114 controls in 14 domains down to 93 controls across four themes - organisational, people, physical and technological and introduced 11 new controls covering areas such as threat intelligence, cloud services security, data masking and secure coding. The 2013 version has been withdrawn, so all new certifications and transitions are issued against the 2022 standard.
ISO 27001 is a voluntary standard rather than a statutory requirement in India. In practice it is frequently mandated contractually by enterprise customers and in RFPs, and it is widely used as the control backbone for demonstrating the reasonable security safeguards expected under the Digital Personal Data Protection Act, 2023, although it does not cover every DPDP obligation on its own.
The Statement of Applicability is a mandatory document that lists every Annex A control and records whether it is included in the ISMS, with a justification for each inclusion or exclusion and a note on how included controls are implemented. Auditors treat it as a central reference during both Stage 1 and Stage 2.