Home All services
Start a project → Call Now

ISO 27001 consultant in India

Prepare for ISO 27001 certification — with the scope written first.

We help you build an information security management system (ISMS) to ISO/IEC 27001:2022. We start with the scope statement, then build a Statement of Applicability (SoA) to survive the auditor's questions. A certification body you appoint does the audit.

  • A reason for every control
  • Readiness review before the audit
  • We reply within one working day.
  • ISO/IEC 27001:2022
  • Amendment 1:2024
  • Annex A, all 93 controls
Illustration: a glowing card that outlines which systems are in scope, a checklist with five ticks and one item still open, and a blank award rosette, all on one podium

In brief

What it is
Help to build an ISMS to ISO/IEC 27001:2022, the international information security standard, and get it ready for audit.
Why it matters
Buyers ask for the certificate, then read the scope printed on it. Draw it too wide and you overpay. Draw it too narrow, then oversell it, and you lose their trust.
What you get
A scope statement, a Statement of Applicability with a reason for every control, the risk work behind it, and a readiness review before the audit.

What you get, and who signs it

You get three sets of documents, each with a named owner.

Scope statement and context register. You sign these.

The clause 4.3 scope statement, worded as it will be printed, plus your register of context and interested parties. Amendment 1:2024 (February 2024, no transition period) added a line on whether climate change is a relevant issue. Skip it and the auditor gets a free finding.

SoA and risk treatment plan. We draft, your risk owners approve.

The Statement of Applicability (SoA): all 93 controls in Annex A, the standard's list of security controls, each with a reason and its real status. Your risk owners approve the treatment plan and accept the remaining risk. Clauses 6.1.3 e) and f) name them, not your consultant, and the auditor will ask which of them read it.

Gap analysis and readiness review. We produce these.

An ISO 27001 gap analysis against clauses 4 to 10 and all 93 controls, then a readiness review before the certification body arrives. It's an honest report, not a certificate. Any consultancy selling you an "ISO 27001 compliance certificate" is selling a document that doesn't exist.

Already certified? See compliance as a service or GRC as a service.

Scope and the SoA

Two documents decide your audit, and most teams rush them.

Teams often spend four months on policies and twenty minutes on the scope sentence. That's backwards. The scope statement (clause 4.3) is printed on your certificate and sets the boundary for every risk, asset and Annex A control that follows.

Next comes the SoA, required by clause 6.1.3 d). It lists each of the 93 controls: included or excluded, why, and whether it is actually implemented. Auditors read the reasons first. An exclusion is allowed. One you can't trace to your scope and risk register in a sentence is a finding.

Two ways to get the scope wrong

  • Too wide. You pay for controls covering offices, subsidiaries and product lines nobody asked you to certify.
  • Too narrow, then oversold. You advertise the badge; procurement reads the scope line, sees one product and twelve people, and treats it as misdirection.

Indian firms held 6,758 valid ISO/IEC 27001 certificates in the ISO Survey 2024, second only to China, so your customer has read a lot of scope lines.

How the documents chain, and what Annex A holds

Each document must trace back to the one before it: scope statement, risk assessment (6.1.2), risk treatment (6.1.3), SoA, certificate. Annex A enters at 6.1.3 c) as a comparison set to catch what you missed, not as the starting checklist.

  • Organizational: 37 controls, 5.1 to 5.37.
  • People: 8 controls, 6.1 to 6.8.
  • Physical: 14 controls, 7.1 to 7.14.
  • Technological: 34 controls, 8.1 to 8.34.

Exclusions that hold

Six common exclusions, and what the auditor asks next.

Clause 6.1.3 d) asks for a reason for inclusions too. A missing one is among the most frequently raised SoA nonconformities (audit findings).

ExclusionHolds?What the auditor asks next
A.7.4 Physical security monitoringOften yesShow me the scope wording that puts the office outside the boundary, and where A.5.19 to A.5.23 cover the hosting provider.
A.5.23 Cloud services securityEffectively neverThe scope names a hosted product. Excluding this usually means the scope was written before anyone looked at the estate.
A.8.28 Secure codingNot if the scope names a productWho writes the code inside this boundary? If development is out of scope, why is the product in it?
A.8.23 Web filteringYes, fairly oftenFair on endpoints you don't manage. Which control treats that risk instead, and does the SoA row say so?
A.8.11 Data maskingSometimesYour register has no risk about non-production copies of customer data. Are there none, or did nobody look?
A.5.21 ICT supply chain securityRarelyYou buy software. Point at the risk this exclusion answers, or at the supplier register that makes it redundant.

No supplier register yet? Third-party risk management builds one.

How we run it

We write the scope sentence first, then build everything on it.

Certification takes two audits: Stage 1 checks your documents and readiness; Stage 2 is the main audit. Our five steps aim to leave Stage 1 nothing to find. Your own people set the pace, as our ISO 27001 case study shows.

  1. Draft the scope sentence

    Half a day with the founder or security lead and whoever owns the customer contracts. We write the clause 4.3 statement as it will be printed: services, locations, and the interfaces and dependencies left out. Then we ask what a procurement reviewer would conclude.

  2. Test it against the contract

    If the customer security addendum that started the project covers a product the draft leaves out, the scope is wrong. Better to learn that in week one. Widening scope to look impressive adds audit days, sites and cost, and wins nothing, so we push back.

  3. Assess risk, then treat it

    Risk assessment (clause 6.1.2) comes before treatment (6.1.3), because controls have to come out of risks. Auditors spot a reversed order at once: no SoA row traces back to a risk.

  4. Fill the SoA row by row

    All 93 rows get a decision, a reason traced to a risk, a contract or a law, and an honest status. "Partially implemented" is an acceptable answer. Overstating it is how Stage 2 goes badly.

  5. Internal audit and management review

    Clause 9.2 needs a completed internal audit of the whole ISMS; 9.3 needs a management review with every input listed in 9.3.2. Without them, Stage 2 brings major nonconformities and a rebooking. We run the internal audit against the SoA, control by control.

Limits, stated plainly

What we won't do, and what a certificate can't do.

No marking our own homework

We won't audit an ISMS we built and call it independent, or refer you to anyone offering consultancy and certification on one invoice.

Not a substitute for the law

A certificate doesn't discharge CERT-In's reporting duties under the April 2022 directions, or the DPDP Act security safeguards. Those are separate obligations with their own timelines.

What to check on any certificate

It must come from a certification body accredited by a signatory to the Global ACI MRA (the international recognition arrangement); in India, that is NABCB. It must say ISO/IEC 27001:2022, and your customer will read its scope line.

What SecWiz is not. A certification body. We don't issue ISO 27001 certificates, and ISO/IEC 17021-1 bars a certification body from certifying a client it consulted for, so you appoint the accredited body yourself. We aren't ISO 27001 certified ourselves either.

What changed in accreditation in 2026?

Global ACI took over the roles of IAF and ILAC on 1 January 2026: look for the MRA mark, not the old MLA most sites still name. From 31 March 2026, IAF MD 29:2024 requires accredited bodies to apply ISO/IEC 27006-1:2024 to all their clients.

Managing AI too? See ISO/IEC 42001. Other frameworks: GRC and compliance.

FAQ

Questions buyers ask before committing the budget.

Not answered here? Ask us directly.

No, and no consultancy can. ISO/IEC 17021-1 bars a certification body from certifying a client it provided management system consultancy to, with a mandatory separation period. Consultancy-plus-certificate packages are common in India. Accepting one means either the certificate is unaccredited, or the body is in breach and the certificate is at risk of withdrawal. We build and prepare the ISMS. A body you appoint, accredited and independent of us, does the audit and signs the result. We aren't ISO 27001 certified ourselves either.

Six to twelve months from kickoff to Stage 2 for a firm of roughly 100 to 500 people with existing IT and no formal ISMS, then four to eight weeks to close nonconformities and receive the certificate. Nine months is the honest median. Working harder won't compress it: clause 9.2 needs a completed internal audit covering the whole ISMS, 9.3 needs a management review, and certification bodies want to see controls that have actually been running, usually for around three months. Book the certification body early. In India that scheduling adds four to ten weeks.

Yes. Exclusion is built into clause 6.1.3 d), which asks for a justification, not for a full house of 93. What gets written up is an exclusion with no reason traceable to your scope, your risk register or a contract. The same clause also requires a justification for each inclusion, the half most teams forget, and a missing one is among the most frequently raised SoA nonconformities. Don't leave the 93 rows for the last week before Stage 2.

As narrow as clause 4.3 lets you define it, which is narrower than most people assume. Certifying one product team is legitimate, and the certificate is valid. But the scope statement is printed on the certificate, and sophisticated buyers read it. If your site says ISO 27001 certified and the PDF says twelve people and one product, that gap does more damage than having no certificate. Certify narrow if that's the honest boundary, then say precisely what's certified wherever you mention it.

No. A certificate is evidence, not a legal safe harbour, and neither the DPDP Act nor the Rules name ISO 27001. The Rules do set out reasonable security safeguards as a list that maps cleanly onto Annex A, so an SoA-backed ISMS is the cheapest way to build the evidence. The main Data Fiduciary duties take effect in the last phase of the Rules' commencement, which leaves time to build an ISMS properly rather than patch one together. Significant Data Fiduciaries carry extra duties no certificate discharges.

No. Every certificate against ISO/IEC 27001:2013 expired or was withdrawn on 31 October 2025, at the end of the 36-month transition period set by IAF MD 26. A supplier's 2013 certificate is now a red flag, not a credential. If it's your own, you're uncertified and need an initial certification audit, not a transition, because there's nothing left to transition to.

No, and the difference is structural. ISO 27001 is a certification: an accredited certification body audits you and issues a public certificate naming a defined scope, valid three years with surveillance audits at roughly 12 and 24 months. SOC 2 is an attestation: a licensed CPA firm issues an opinion report under AICPA standards. There's no certificate and no accreditation body above the auditor, and you share the report under NDA. ISO 27001 prescribes the artifacts, so two certified companies have the same skeleton. In SOC 2 you write your own control descriptions, so two reports can describe very different environments.

Not any more. ISO/IEC 27701:2025, published on 14 October 2025, made the privacy standard a standalone management system standard, so an ISO 27001 ISMS is no longer a prerequisite. Most organizations still run the two together, because shared clauses and shared evidence make it cheaper. Certification body requirements now sit in ISO/IEC 27706:2025. Check one thing first: an accredited standalone privacy certificate depends on your certification body having transitioned to 27706:2025, and not all of them have.

Let's talk

Send us your scope statement and a few SoA rows.

We'll read your clause 4.3 wording and a few SoA rows and tell you where an auditor will push. Not started? We draft the scope sentence with you first. We work remotely from India across client time zones. We reply within one working day.