Here is the moment every Indian CISO discovers ISO 27001 the hard way. You are in the second round of a tender for a European bank. Their procurement team sends a compliance questionnaire. Item 3.1: "Provide a copy of your current ISO/IEC 27001:2022 certificate issued by a certification body accredited under an IAF Multilateral Recognition Arrangement (MLA) signatory." Item 3.2: "Provide the Statement of Applicability referenced in your certificate." You look at your compliance folder. You have a SOC 2 Type II. You have a DPDP Act 2023 readiness memo. You have an internal information security policy. You do not have an ISO 27001 certificate. The tender clock is 45 days. First-time ISO 27001 certification takes 12 to 18 months. The deal dies on Item 3.1.
This lesson is written for the moment before that moment. What ISO 27001 actually is, why your enterprise buyer demands it, and why the certificate you cannot produce in 45 days matters enough to run a 12 to 18 month workstream to get it.
What ISO 27001 is, one paragraph
ISO/IEC 27001:2022 is the international standard for an information security management system, published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) jointly through Subcommittee 27 of Joint Technical Committee 1 [L1-C1]. It sets out requirements for establishing, implementing, maintaining and continually improving an ISMS. Certification is not self-issued. An organisation demonstrates conformity by passing a two-stage audit performed by a certification body that is itself accredited by a national accreditation body which is itself a signatory to the IAF Multilateral Recognition Arrangement. The certificate is valid for three years and covers a defined scope (the parts of the organisation covered by the ISMS).
That paragraph contains four separate concepts that beginners routinely conflate. The standard (ISO 27001) says what an ISMS must contain. The ISMS is the system you build to meet the standard. The certificate is issued by a CB after audit. The accreditation is the chain of authority (IAF MLA to NABCB to CB to certificate) that makes the certificate mean anything.
Where ISO 27001 sits in the ISO family
The ISO/IEC 27000 family currently contains over 40 published standards. This course focuses on nine of them.
| Standard | Purpose | Certifiable? |
|---|---|---|
| ISO/IEC 27000:2018 | Overview and vocabulary. The dictionary of the ISMS family. | No |
| ISO/IEC 27001:2022 | ISMS requirements. The certifiable standard. | Yes |
| ISO/IEC 27002:2022 | Information security controls. The 93 Annex A controls, expanded with implementation guidance. | No (controls are certifiable via 27001 SoA) |
| ISO/IEC 27003:2017 | ISMS implementation guidance. Non-normative. | No |
| ISO/IEC 27004:2016 | Monitoring, measurement, analysis and evaluation. Metrics guidance for Clause 9.1. | No |
| ISO/IEC 27005:2022 | Risk management guidance. Companion to Clauses 6.1.2 and 6.1.3. | No |
| ISO/IEC 27006:2015 + A1:2020 | Requirements for bodies providing audit and certification of ISMS. Governs CBs, not clients. | No (CBs comply) |
| ISO/IEC 27017:2015 | Code of practice for information security in cloud services. Extension of 27002. | Yes (joint 27001 + 27017) |
| ISO/IEC 27018:2019 | Code of practice for protection of PII in public clouds acting as PII processors. | Yes (joint 27001 + 27018) |
| ISO/IEC 27701:2025 | Privacy Information Management System. Standalone since October 2025. | Yes (standalone) |
You certify to 27001. You implement the controls listed in 27001 Annex A which are detailed in 27002. You use the risk methodology guided by 27005. Your CB is governed by 27006. If you add cloud, 27017 or 27018 layer on. If you add privacy, 27701:2025 is now standalone (since October 2025). The rest of the 27000 family provides reference material.
Who accredits certification bodies in India
You cannot self-certify. You cannot get a valid ISO 27001 certificate from an unaccredited body. The chain of authority runs:
- ISO/IEC publishes the standard (ISO 27001:2022).
- International Accreditation Forum (IAF) operates the Multilateral Recognition Arrangement (MLA) that makes ISMS certificates mutually recognised across signatory countries.
- NABCB (National Accreditation Board for Certification Bodies), the Indian accreditation body under the Quality Council of India, is a full member of IAF and a signatory to the MLA
[L1-C2]. NABCB accredits Indian CBs for ISO 27001. - Certification bodies (Bureau Veritas India, BSI India, TÜV SÜD South Asia, TÜV Nord India, DNV Business Assurance India, SGS India, Intertek India, IRQS) perform the audits and issue the certificates.
- Your organisation receives the certificate covering your defined scope.
A certificate issued by a NABCB-accredited CB carries the IAF MLA equivalence stamp. It is recognised by UKAS in the UK, ANAB in the US, DAkkS in Germany, JAB in Japan, ANSI-ASQ in North America and every other IAF MLA signatory. Your European bank buyer accepts it without a debate. A certificate issued by an unaccredited body carries no such recognition and will not clear procurement.
Important 2026 change. Use of the NABCB Accreditation Symbol on accredited certificates became mandatory from 1 July 2026 [L1-C3]. If your certificate is dated on or after that date, the NABCB Symbol should be visible. If it is not, ask your CB. A certificate without the Symbol issued after 1 July 2026 is non-compliant with NABCB accreditation rules and your buyer may reject it.
Why enterprise buyers demand it
Four reasons, in the order they matter.
One: their procurement policy requires it. Any enterprise buying from India has an internal vendor risk framework that classifies vendors by data sensitivity and mandates specific assurance evidence for each tier. For any vendor touching customer data, transactional data, or operational systems, an ISO 27001 certificate is the default assurance in Europe, UK, APAC and the Middle East. Their procurement team cannot approve vendor onboarding without it.
Two: their regulator requires it of their vendors. If your customer is a European bank, the ECB Guidelines on Outsourcing and Third-Party Risk Management require them to obtain independent assurance over material third-party providers. If your customer is a UK financial services firm, the FCA Operational Resilience rules require the same. ISO 27001 is the default artefact. Without it your customer breaches their own regulator's outsourcing rules by using you.
Three: their auditor will ask them where it is. If your customer's own ISMS certification includes you as a supplier in scope for Annex A.5.19 (Information security in supplier relationships), their next surveillance audit will ask what independent assurance they hold over your controls. If your customer's SOX or JSOX audit relies on you for a material IT general control, the same question applies from a different angle.
Four: their insurer requires it. Cyber insurance underwriters require the insured to obtain ISO 27001, SOC 2 or equivalent third-party assurance from all material SaaS and outsourced-services vendors. Without the certificate the insurer can decline a breach claim on the ground that the insured failed to verify vendor controls.
All four stack. Your customer wants the deal too, but their procurement team, their regulators, their auditors and their insurers are structurally prevented from signing off without the ISO 27001 certificate in hand.
What ISO 27001 is not
A short list of misconceptions worth clearing early.
- Not a technical security assessment. ISO 27001 audits management systems, not networks. The auditor does not run a penetration test or a vulnerability scan. The auditor tests whether your ISMS is designed and operating as documented. Penetration testing is inputs to your risk assessment, not a substitute for the ISMS.
- Not a product certification. ISO 27001 certifies an organisation, not a product. Common Criteria (ISO/IEC 15408) and FIPS 140 certify products. Do not confuse them.
- Not one-and-done. The certificate is valid three years with annual surveillance audits in Years 1 and 2 and full recertification in Year 3. You are on a permanent audit treadmill from certification onwards.
- Not free of the Amendment 1:2024 climate change addition. Since February 2024 you must formally consider whether climate change is relevant to your ISMS under Clause 4.1 and whether interested parties have climate-related requirements under Clause 4.2. Lesson 1.3 walks the amendment in detail.
- Not the same as SOC 2. Different standards body (ISO not AICPA). Different report format (certificate not attestation). Different reader (procurement not auditor). Lesson 1.2 next walks the comparison.
- Not conferred by a PECB Lead Implementer classroom course. That is a personal certification for consultants. This course teaches the operational knowledge behind the standard; it does not confer the PECB certificate. If you want the PECB personal cert, take their exam directly.
The Indian picture
Nearly every mature Indian IT services company (Infosys, TCS, Wipro, HCLTech, Tech Mahindra, LTI Mindtree) publishes an ISO/IEC 27001:2022 certification across its global delivery network [L1-C4]. Nearly every mature Indian SaaS (Zoho, Freshworks, Sprinto) publishes ISO 27001 alongside SOC 2, ISO 27017, ISO 27018 and ISO 27701 [L1-C5]. Indian fintech (Razorpay, PhonePe, Paytm) publishes ISO 27001 alongside PCI DSS. These postures are the current bar. Being outside them makes your enterprise sales cycle materially harder in Europe, UK, APAC, Middle East and increasingly in enterprise India.
If you are running a Series A to Series C Indian SaaS, or a mid-cap IT services firm, or a Global Capability Centre, or a healthcare data processor, or a fintech, or a telecom, or a professional services organisation with any material client data exposure, ISO 27001 is either already on your roadmap or about to be. This course is written for that operator.
Next lesson: ISO 27001 vs SOC 2 vs NIST CSF vs ISO 27701. When each applies. Which one your customer actually wants when they ask for "your security certificate".