Live Founding Cohort open, limited seats remaining Back to main site →

The operating timeline for a first-time Indian filer

Zero to first certificate in 12 to 18 months. This lesson walks the month-by-month operating calendar every Indian CISO and ISMS Manager should be running for first-time certification.

Free preview 12 min read Verified
Legal basis
ISO/IEC 27001 primary-source stack current to 29 August 2026. Core: ISO/IEC 27001:2022 (published October 2022, current base standard), ISO/IEC 27001:2022/Amd 1:2024 (published February 2024, climate action changes to Clauses 4.1 and 4.2), ISO/IEC 27002:2022 (published February 2022, 93 Annex A controls across four themes: Organizational 37, People 8, Physical 14, Technological 34 with 11 new controls including threat intelligence, cloud services, ICT readiness, physical security monitoring, configuration management, information deletion, data masking, DLP, monitoring activities, web filtering, secure coding), ISO/IEC 27005:2022 (risk management guidance), ISO/IEC 27006:2015 + A1:2020 (CB requirements), ISO/IEC 27000:2018 (overview and vocabulary), ISO/IEC 27003:2017 (ISMS implementation guidance), ISO/IEC 27004:2016 (monitoring and measurement), ISO/IEC 27017:2015 (cloud code of practice), ISO/IEC 27018:2019 (cloud PII protection), ISO/IEC 27701:2025 (standalone privacy management system published 14 October 2025 with three-year transition to October 2028 for 27701:2019 certificate holders), ISO 31000:2018 (risk management guidelines), ISO 19011:2018 (auditing management systems guidelines). India-specific: NABCB (National Accreditation Board for Certification Bodies, Quality Council of India, IAF MLA member) accreditation regime, NABCB Policy on Transition to ISO/IEC 27701:2025 (published January 2026), NABCB Accreditation Symbol mandatory on accredited certificates from 1 July 2026, BIS adoption as IS/ISO/IEC 27001:2022 identical to ISO text. Related frameworks: NIST Cybersecurity Framework 2.0 (February 2024) for cross-mapping, SOC 2 Trust Services Criteria 2017 with 2022 Revised Points of Focus for the SOC 2 versus ISO 27001 comparison, DPDP Act 2023 and DPDP Rules 2025 for the Privacy overlay under Annex A.5.34 and ISO 27701:2025, CERT-In Directions dated 28 April 2022 (effective 27 June 2022) for the Indian incident reporting overlay under A.5.24 through A.5.27, RBI Cybersecurity Framework 2016 and Master Direction on IT Governance April 2024 for the BFSI overlay. Personal certification schemes referenced (not primary): PECB Lead Implementer (31 CPD credits, 3-year cert validity, USD 100 annual maintenance, operates under ISO/IEC 17024), IRCA Lead Auditor (CQI subsidiary), BSI Lead Implementer and Lead Auditor. Certification body landscape referenced: Bureau Veritas India, BSI India, TÜV SÜD South Asia, TÜV Nord India, DNV Business Assurance India, SGS India, Intertek India, IRQS. Vendor tooling landscape referenced in Module 6: Vanta, Drata, Sprinto (India-headquartered Bengaluru), Secureframe, AuditBoard, Archer, ServiceNow GRC, MetricStream. Items requiring ongoing verification and flagged inside the relevant lessons: any ISO/IEC 27001 next-edition timeline (currently no revision announced), any further amendments to 27001:2022 beyond Amd 1:2024, IAF Mandatory Document updates applicable to ISMS audits, NABCB transition policy for future ISO 27001 revisions, current vendor pricing on Vanta, Drata, Sprinto, Secureframe, AuditBoard.

Here is the mistake almost every Indian CISO makes with a first ISO 27001. They discover the requirement in month zero when a European tender or a GCC parent asks for it. They panic. They engage a consultant in month two who promises certification in six months. By month four the consultant has produced a large binder of policies nobody in the organisation has read. By month six the CB does Stage 1 and lists nine nonconformities. By month twelve the internal audit programme has not run because nobody trained an internal auditor. By month eighteen the certificate finally issues.

ISO 27001 first-time certification is a 12 to 18 month workstream for a serious implementation. Here is the calendar.

The overall shape

Total elapsed time for a first-time filer: 12 to 18 months from decision to certificate for a typical Indian SaaS Series A to Series C, mid-cap IT services firm, or Global Capability Centre.

Shorter (8 to 12 months) is possible if the organisation already has ISO 9001 or ISO 20000 heritage (much of the management system layer is reusable) and a mature security engineering function (many Annex A controls are already operating).

Longer (18 to 24 months) is typical for organisations with limited management-system heritage, distributed multi-site operations requiring IAF MD 1 sampling, or heavy scope-negotiation with the CB.

Months 1 to 3: Foundation

  • Month 1: Scope the ISO 27001 decision. Sponsor identified at top management level (CEO, COO, CTO or CISO reporting to CEO). Budget approved. First-year programme cost for a Series A to Series C Indian SaaS or mid-cap enterprise typically runs Rs 30 lakh to Rs 60 lakh (advisory + tooling + auditor + internal FTE time). Sponsor sign-off document circulated.
  • Month 2: Buy vs Build decision on GRC tooling. Options walked in Module 6: Vanta, Drata, Sprinto (India-headquartered), Secureframe, AuditBoard (enterprise scale), Archer / ServiceNow GRC / MetricStream (enterprise). Most Indian SaaS at Series A to C buy Sprinto. Most GCCs and enterprises with parent GRC standards inherit the parent's platform (typically Archer or ServiceNow). Most mid-cap IT services firms build in-house on SharePoint or Confluence.
  • Month 3: Draft the ISMS Scope Statement (Module 2 Lesson 1 template). Draft the ISMS Policy (Module 2 Lesson 2 template). Top management approves the ISMS Policy formally.

Months 4 to 6: Building the ISMS core

  • Month 4: Run the first Risk Assessment cycle (Module 6). Asset inventory. Threat and vulnerability identification. Likelihood and impact scoring. Inherent and residual risk calculation. Produce the first Risk Register.
  • Month 5: Build the Statement of Applicability mapping all 93 Annex A controls to Include or Exclude with justification (Module 4 Lesson 5 template). Draft the Risk Treatment Plan (Module 6 Lesson 4 template). Get risk owner sign-offs on residual risks.
  • Month 6: Populate documented information for the other clauses. Competence records (Clause 7.2). Awareness training programme (Clause 7.3 aligned to A.6.3). Communication plan (Clause 7.4). Documented operating procedures for the 15 to 25 highest-risk controls (A.5.37).

Months 7 to 9: Operational running

  • Month 7: The ISMS starts operating. Change tickets flow. Access reviews run. Vulnerability scans execute. Incident register captures incidents. Evidence accumulates in the GRC platform or the manual evidence repository.
  • Month 8: First Internal Audit cycle begins (Clause 9.2). Internal auditor competence must be established (typically an internal team member trained on ISO 19011:2018 [L5-C1] and ISO 27001 clauses). Audit programme designed with three-year rolling coverage of all clauses and applicable Annex A controls (Module 3 Lesson 4 template).
  • Month 9: Internal audit findings issued. CAPA opened for each nonconformity. First Management Review conducted (Clause 9.3, Module 3 Lesson 4 template).

Months 10 to 12: CB selection and Stage 1

  • Month 10: CB selection kickoff. Issue RFPs to three or four NABCB-accredited CBs (Module 7 Lesson 2 template). Options: Bureau Veritas India, BSI India, TÜV SÜD South Asia, TÜV Nord India, DNV Business Assurance India, SGS India, Intertek India, IRQS. Evaluation criteria: accreditation scope for information security, sector experience, audit day cost, international recognition, auditor competence for your specific industry.
  • Month 11: CB selected. Contract signed. Stage 1 date scheduled typically 4 to 6 weeks out.
  • Month 12: Stage 1 audit conducted (typically remote under IAF MD 4). Findings issued. Address findings before Stage 2 date. Typical remediation window 4 to 12 weeks depending on findings' severity.

Months 13 to 15 (or 14 to 18): Stage 2 and certificate

  • Month 13 to 14: Fix Stage 1 findings. If severe, extend to Month 15.
  • Month 14 to 15: Stage 2 audit conducted (typically 6 to 12 days on site plus remote components). Interviews, walkthroughs, evidence review. Nonconformities issued.
  • Month 15 to 16: Close Stage 2 nonconformities via CAPA. Major nonconformities blocking certificate issuance require closure and CB verification. Minor nonconformities require credible CAPA plan.
  • Month 16 to 18: Certificate issued. Publish on customer trust portal (Module 8 Lesson 2 template). Answer waiting tenders and customer questionnaires with the new certificate.

Year 2 and Year 3: Surveillance and recertification

The compliance treadmill starts. Year 1 surveillance audit is typically 30 to 40 percent of initial Stage 2 audit days. Focus on nonconformity closure from Stage 2, any significant ISMS changes, sampled Annex A controls, continued operation of internal audit programme and management review.

Year 2 surveillance similar to Year 1 with rotated Annex A control sampling.

Year 3 recertification is a full-scope audit similar to initial Stage 2. If ISMS has been well-maintained, lighter delivery; if drifted, substantial nonconformities possible.

Cost bands for a Series A to Series C Indian SaaS / mid-cap enterprise / GCC

ItemYear 1 (first certification)Year 2 (surveillance)Year 3 (recertification)
GRC platform (Sprinto / Vanta / Drata / Secureframe)Rs 5 to 12 lakhRs 6 to 12 lakhRs 6 to 12 lakh
Advisory / readiness consultant (optional)Rs 6 to 15 lakhRs 1 to 4 lakhRs 3 to 6 lakh
CB audit fees, BoutiqueRs 4 to 8 lakh (Stage 1 + Stage 2)Rs 1.5 to 3 lakh (surveillance)Rs 3 to 6 lakh
CB audit fees, Mid-tier (TÜV Nord, DNV, SGS, IRQS)Rs 6 to 14 lakhRs 2.5 to 5 lakhRs 5 to 10 lakh
CB audit fees, Top-tier (Bureau Veritas, BSI, TÜV SÜD, Intertek)Rs 10 to 25 lakhRs 4 to 8 lakhRs 8 to 18 lakh
Internal FTE time (1 to 2 FTE across ISMS Manager / CISO / DevOps / Internal Auditor)Rs 10 to 20 lakh notionalRs 5 to 10 lakh notionalRs 6 to 12 lakh notional

Bands verified against current CB engagement patterns for Indian organisations and GRC platform vendor pricing pages. Numbers shift 15 to 25 percent year on year; treat as directional not authoritative.

The parallel SOC 2 question

If your customer base is mixed (US enterprise plus Europe / UK / APAC), the pragmatic question is: run ISO 27001 and SOC 2 sequentially or in parallel?

  • Sequential (start ISO 27001, add SOC 2 in Year 2): lower cash burn in Year 1, longer time to full commercial coverage. Right for Europe / UK / APAC dominant revenue.
  • Sequential (start SOC 2, add ISO 27001 in Year 2): same logic, US dominant revenue.
  • Parallel: highest Year 1 cash burn but fastest time to full commercial coverage. Right for Series B or Series C companies with pending large deals across both geographies. Combined SOC 2 + ISO 27001 programmes share 70 to 80 percent of the control set; marginal cost of second framework is 40 to 60 percent of first.

Vanta, Drata, Sprinto and Secureframe all support combined SOC 2 + ISO 27001 workflows. Most Indian SaaS at Series B to C are running combined programmes as of 2026.

End of the free-preview module

You now know what ISO 27001 is, how it compares to SOC 2 and NIST CSF and ISO 27701, the substantive changes in the 2022 revision plus the Amendment 1:2024 climate change addition, the certification lifecycle from Stage 1 through recertification, and the 12 to 18 month operating calendar from decision to certificate.

The rest of the course goes deep into the mechanics. Module 2 begins Clauses 4 through 6 (Context, Leadership, Planning) where certifications are won or lost at Stage 1. Modules 4 and 5 walk each of the 93 Annex A controls including the 11 new ones. Module 6 is the risk assessment operating layer with ISO 27005:2022. Module 7 walks Stage 1 and Stage 2 audit preparation. Module 8 closes with post-certification, ISO 27701:2025 privacy add-on and the ISO 42001 AI horizon. Enrol to continue.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview complete You've read every free lesson in Module 1

Ready for the rest of ISO/IEC 27001 Lead Implementer Practitioner Certification?

  • All 7 paid modules (35 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹19,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
ISO 19011:2018, ISO 19011:2018 (auditing guidelines) (Auditing management systems) L5-C1
ISO 19011:2018 provides guidelines for auditing management systems. Governs first-party (internal) and second-party (customer) audits. Certification (third-party) audits are governed by ISO/IEC 17021-1 read with ISO/IEC 27006. ISMS internal audit programme (Clause 9.2) is designed per ISO 19011.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The ISO 27001 story
Module 2: Clauses 4 to 6: Context, Leadership, Planning
  • Clause 4 Context of the organisation (including Amendment 1:2024 climate change)
  • Clause 5 Leadership and the ISMS Policy
  • Clause 6.1 Actions to address risks and opportunities
  • Clauses 6.1.2 and 6.1.3 — Risk assessment and treatment methodology
  • Clauses 6.2 and 6.3 — ISMS objectives and Planning of changes
Module 3: Clauses 7 to 10: Support, Operation, Evaluation, Improvement
  • Clause 7 Support — Resources, competence, awareness, communication
  • Clause 7.5 Documented information — the four mandatory items + ISMS Manual TOC
  • Clause 8 Operation — Executing the plan
  • Clause 9 — Monitoring, Internal Audit, Management Review
  • Clause 10 Improvement — Nonconformity and CAPA
Module 4: Annex A controls Part 1: Organizational + People
  • A.5 Organizational controls Part 1 (A.5.1 through A.5.20)
  • A.5 Organizational controls Part 2 (A.5.21 through A.5.37)
  • A.6 People controls (8 controls, A.6.1 through A.6.8)
  • The 11 new controls in ISO/IEC 27002:2022 walkthrough
  • Building the Statement of Applicability (all 93 controls)
Module 5: Annex A controls Part 2: Physical + Technological
  • A.7 Physical controls (14 controls, A.7.1 through A.7.14)
  • A.8 Technological controls Part 1 (A.8.1 through A.8.17)
  • A.8 Technological controls Part 2 (A.8.18 through A.8.34)
  • Cloud-specific controls and ISO 27017 / 27018 alignment
  • Control Ownership Matrix and evidence sources
Module 6: The risk assessment operating layer
  • Choosing a risk methodology (asset-based, scenario-based, hybrid)
  • Asset inventory and information classification
  • Threat identification, vulnerability identification, likelihood + impact scoring
  • Risk treatment options (Modify, Retain, Avoid, Share) and the Risk Treatment Plan
  • GRC tooling — buy vs build (Sprinto, Vanta, Drata, Secureframe, AuditBoard, Archer)
Module 7: Certification body selection + Stage 1 + Stage 2 audits
  • What NABCB accreditation means (and why IAF MLA matters)
  • CB RFP process + Selection Matrix (Bureau Veritas, BSI, TÜV SÜD, TÜV Nord, DNV, SGS, Intertek, IRQS)
  • Stage 1 audit — documentation review
  • Stage 2 audit — operating effectiveness testing
  • Handling nonconformities, CAPA closure, certificate issuance
Module 8: Post-certification + adjacent standards
  • Surveillance Years 1 + 2, and recertification Year 3
  • Publishing certification status + answering VSAQ / CAIQ / SIG questionnaires
  • ISO/IEC 27701:2025 privacy add-on + DPDP Act 2023 crosswalk
  • ISO/IEC 27017 (cloud) + ISO/IEC 27018 (cloud PII) extensions
  • ISO/IEC 42001 AI Management System as the next horizon