Here is the mistake almost every Indian CISO makes with a first ISO 27001. They discover the requirement in month zero when a European tender or a GCC parent asks for it. They panic. They engage a consultant in month two who promises certification in six months. By month four the consultant has produced a large binder of policies nobody in the organisation has read. By month six the CB does Stage 1 and lists nine nonconformities. By month twelve the internal audit programme has not run because nobody trained an internal auditor. By month eighteen the certificate finally issues.
ISO 27001 first-time certification is a 12 to 18 month workstream for a serious implementation. Here is the calendar.
The overall shape
Total elapsed time for a first-time filer: 12 to 18 months from decision to certificate for a typical Indian SaaS Series A to Series C, mid-cap IT services firm, or Global Capability Centre.
Shorter (8 to 12 months) is possible if the organisation already has ISO 9001 or ISO 20000 heritage (much of the management system layer is reusable) and a mature security engineering function (many Annex A controls are already operating).
Longer (18 to 24 months) is typical for organisations with limited management-system heritage, distributed multi-site operations requiring IAF MD 1 sampling, or heavy scope-negotiation with the CB.
Months 1 to 3: Foundation
- Month 1: Scope the ISO 27001 decision. Sponsor identified at top management level (CEO, COO, CTO or CISO reporting to CEO). Budget approved. First-year programme cost for a Series A to Series C Indian SaaS or mid-cap enterprise typically runs Rs 30 lakh to Rs 60 lakh (advisory + tooling + auditor + internal FTE time). Sponsor sign-off document circulated.
- Month 2: Buy vs Build decision on GRC tooling. Options walked in Module 6: Vanta, Drata, Sprinto (India-headquartered), Secureframe, AuditBoard (enterprise scale), Archer / ServiceNow GRC / MetricStream (enterprise). Most Indian SaaS at Series A to C buy Sprinto. Most GCCs and enterprises with parent GRC standards inherit the parent's platform (typically Archer or ServiceNow). Most mid-cap IT services firms build in-house on SharePoint or Confluence.
- Month 3: Draft the ISMS Scope Statement (Module 2 Lesson 1 template). Draft the ISMS Policy (Module 2 Lesson 2 template). Top management approves the ISMS Policy formally.
Months 4 to 6: Building the ISMS core
- Month 4: Run the first Risk Assessment cycle (Module 6). Asset inventory. Threat and vulnerability identification. Likelihood and impact scoring. Inherent and residual risk calculation. Produce the first Risk Register.
- Month 5: Build the Statement of Applicability mapping all 93 Annex A controls to Include or Exclude with justification (Module 4 Lesson 5 template). Draft the Risk Treatment Plan (Module 6 Lesson 4 template). Get risk owner sign-offs on residual risks.
- Month 6: Populate documented information for the other clauses. Competence records (Clause 7.2). Awareness training programme (Clause 7.3 aligned to A.6.3). Communication plan (Clause 7.4). Documented operating procedures for the 15 to 25 highest-risk controls (A.5.37).
Months 7 to 9: Operational running
- Month 7: The ISMS starts operating. Change tickets flow. Access reviews run. Vulnerability scans execute. Incident register captures incidents. Evidence accumulates in the GRC platform or the manual evidence repository.
- Month 8: First Internal Audit cycle begins (Clause 9.2). Internal auditor competence must be established (typically an internal team member trained on ISO 19011:2018
[L5-C1]and ISO 27001 clauses). Audit programme designed with three-year rolling coverage of all clauses and applicable Annex A controls (Module 3 Lesson 4 template). - Month 9: Internal audit findings issued. CAPA opened for each nonconformity. First Management Review conducted (Clause 9.3, Module 3 Lesson 4 template).
Months 10 to 12: CB selection and Stage 1
- Month 10: CB selection kickoff. Issue RFPs to three or four NABCB-accredited CBs (Module 7 Lesson 2 template). Options: Bureau Veritas India, BSI India, TÜV SÜD South Asia, TÜV Nord India, DNV Business Assurance India, SGS India, Intertek India, IRQS. Evaluation criteria: accreditation scope for information security, sector experience, audit day cost, international recognition, auditor competence for your specific industry.
- Month 11: CB selected. Contract signed. Stage 1 date scheduled typically 4 to 6 weeks out.
- Month 12: Stage 1 audit conducted (typically remote under IAF MD 4). Findings issued. Address findings before Stage 2 date. Typical remediation window 4 to 12 weeks depending on findings' severity.
Months 13 to 15 (or 14 to 18): Stage 2 and certificate
- Month 13 to 14: Fix Stage 1 findings. If severe, extend to Month 15.
- Month 14 to 15: Stage 2 audit conducted (typically 6 to 12 days on site plus remote components). Interviews, walkthroughs, evidence review. Nonconformities issued.
- Month 15 to 16: Close Stage 2 nonconformities via CAPA. Major nonconformities blocking certificate issuance require closure and CB verification. Minor nonconformities require credible CAPA plan.
- Month 16 to 18: Certificate issued. Publish on customer trust portal (Module 8 Lesson 2 template). Answer waiting tenders and customer questionnaires with the new certificate.
Year 2 and Year 3: Surveillance and recertification
The compliance treadmill starts. Year 1 surveillance audit is typically 30 to 40 percent of initial Stage 2 audit days. Focus on nonconformity closure from Stage 2, any significant ISMS changes, sampled Annex A controls, continued operation of internal audit programme and management review.
Year 2 surveillance similar to Year 1 with rotated Annex A control sampling.
Year 3 recertification is a full-scope audit similar to initial Stage 2. If ISMS has been well-maintained, lighter delivery; if drifted, substantial nonconformities possible.
Cost bands for a Series A to Series C Indian SaaS / mid-cap enterprise / GCC
| Item | Year 1 (first certification) | Year 2 (surveillance) | Year 3 (recertification) |
|---|---|---|---|
| GRC platform (Sprinto / Vanta / Drata / Secureframe) | Rs 5 to 12 lakh | Rs 6 to 12 lakh | Rs 6 to 12 lakh |
| Advisory / readiness consultant (optional) | Rs 6 to 15 lakh | Rs 1 to 4 lakh | Rs 3 to 6 lakh |
| CB audit fees, Boutique | Rs 4 to 8 lakh (Stage 1 + Stage 2) | Rs 1.5 to 3 lakh (surveillance) | Rs 3 to 6 lakh |
| CB audit fees, Mid-tier (TÜV Nord, DNV, SGS, IRQS) | Rs 6 to 14 lakh | Rs 2.5 to 5 lakh | Rs 5 to 10 lakh |
| CB audit fees, Top-tier (Bureau Veritas, BSI, TÜV SÜD, Intertek) | Rs 10 to 25 lakh | Rs 4 to 8 lakh | Rs 8 to 18 lakh |
| Internal FTE time (1 to 2 FTE across ISMS Manager / CISO / DevOps / Internal Auditor) | Rs 10 to 20 lakh notional | Rs 5 to 10 lakh notional | Rs 6 to 12 lakh notional |
Bands verified against current CB engagement patterns for Indian organisations and GRC platform vendor pricing pages. Numbers shift 15 to 25 percent year on year; treat as directional not authoritative.
The parallel SOC 2 question
If your customer base is mixed (US enterprise plus Europe / UK / APAC), the pragmatic question is: run ISO 27001 and SOC 2 sequentially or in parallel?
- Sequential (start ISO 27001, add SOC 2 in Year 2): lower cash burn in Year 1, longer time to full commercial coverage. Right for Europe / UK / APAC dominant revenue.
- Sequential (start SOC 2, add ISO 27001 in Year 2): same logic, US dominant revenue.
- Parallel: highest Year 1 cash burn but fastest time to full commercial coverage. Right for Series B or Series C companies with pending large deals across both geographies. Combined SOC 2 + ISO 27001 programmes share 70 to 80 percent of the control set; marginal cost of second framework is 40 to 60 percent of first.
Vanta, Drata, Sprinto and Secureframe all support combined SOC 2 + ISO 27001 workflows. Most Indian SaaS at Series B to C are running combined programmes as of 2026.
End of the free-preview module
You now know what ISO 27001 is, how it compares to SOC 2 and NIST CSF and ISO 27701, the substantive changes in the 2022 revision plus the Amendment 1:2024 climate change addition, the certification lifecycle from Stage 1 through recertification, and the 12 to 18 month operating calendar from decision to certificate.
The rest of the course goes deep into the mechanics. Module 2 begins Clauses 4 through 6 (Context, Leadership, Planning) where certifications are won or lost at Stage 1. Modules 4 and 5 walk each of the 93 Annex A controls including the 11 new ones. Module 6 is the risk assessment operating layer with ISO 27005:2022. Module 7 walks Stage 1 and Stage 2 audit preparation. Module 8 closes with post-certification, ISO 27701:2025 privacy add-on and the ISO 42001 AI horizon. Enrol to continue.