Live Founding Cohort open, limited seats remaining Back to main site →

What ISO/IEC 27001 is and why enterprises demand it

ISO/IEC 27001 is the international standard for an information security management system. This lesson walks what it actually is, where the standard sits in the ISO family, who accredits certification bodies, and why your enterprise buyer, government tender or GCC parent will not sign without the certificate.

Free preview 10 min read Verified
Legal basis
ISO/IEC 27001 primary-source stack current to 29 August 2026. Core: ISO/IEC 27001:2022 (published October 2022, current base standard), ISO/IEC 27001:2022/Amd 1:2024 (published February 2024, climate action changes to Clauses 4.1 and 4.2), ISO/IEC 27002:2022 (published February 2022, 93 Annex A controls across four themes: Organizational 37, People 8, Physical 14, Technological 34 with 11 new controls including threat intelligence, cloud services, ICT readiness, physical security monitoring, configuration management, information deletion, data masking, DLP, monitoring activities, web filtering, secure coding), ISO/IEC 27005:2022 (risk management guidance), ISO/IEC 27006:2015 + A1:2020 (CB requirements), ISO/IEC 27000:2018 (overview and vocabulary), ISO/IEC 27003:2017 (ISMS implementation guidance), ISO/IEC 27004:2016 (monitoring and measurement), ISO/IEC 27017:2015 (cloud code of practice), ISO/IEC 27018:2019 (cloud PII protection), ISO/IEC 27701:2025 (standalone privacy management system published 14 October 2025 with three-year transition to October 2028 for 27701:2019 certificate holders), ISO 31000:2018 (risk management guidelines), ISO 19011:2018 (auditing management systems guidelines). India-specific: NABCB (National Accreditation Board for Certification Bodies, Quality Council of India, IAF MLA member) accreditation regime, NABCB Policy on Transition to ISO/IEC 27701:2025 (published January 2026), NABCB Accreditation Symbol mandatory on accredited certificates from 1 July 2026, BIS adoption as IS/ISO/IEC 27001:2022 identical to ISO text. Related frameworks: NIST Cybersecurity Framework 2.0 (February 2024) for cross-mapping, SOC 2 Trust Services Criteria 2017 with 2022 Revised Points of Focus for the SOC 2 versus ISO 27001 comparison, DPDP Act 2023 and DPDP Rules 2025 for the Privacy overlay under Annex A.5.34 and ISO 27701:2025, CERT-In Directions dated 28 April 2022 (effective 27 June 2022) for the Indian incident reporting overlay under A.5.24 through A.5.27, RBI Cybersecurity Framework 2016 and Master Direction on IT Governance April 2024 for the BFSI overlay. Personal certification schemes referenced (not primary): PECB Lead Implementer (31 CPD credits, 3-year cert validity, USD 100 annual maintenance, operates under ISO/IEC 17024), IRCA Lead Auditor (CQI subsidiary), BSI Lead Implementer and Lead Auditor. Certification body landscape referenced: Bureau Veritas India, BSI India, TÜV SÜD South Asia, TÜV Nord India, DNV Business Assurance India, SGS India, Intertek India, IRQS. Vendor tooling landscape referenced in Module 6: Vanta, Drata, Sprinto (India-headquartered Bengaluru), Secureframe, AuditBoard, Archer, ServiceNow GRC, MetricStream. Items requiring ongoing verification and flagged inside the relevant lessons: any ISO/IEC 27001 next-edition timeline (currently no revision announced), any further amendments to 27001:2022 beyond Amd 1:2024, IAF Mandatory Document updates applicable to ISMS audits, NABCB transition policy for future ISO 27001 revisions, current vendor pricing on Vanta, Drata, Sprinto, Secureframe, AuditBoard.

Here is the moment every Indian CISO discovers ISO 27001 the hard way. You are in the second round of a tender for a European bank. Their procurement team sends a compliance questionnaire. Item 3.1: "Provide a copy of your current ISO/IEC 27001:2022 certificate issued by a certification body accredited under an IAF Multilateral Recognition Arrangement (MLA) signatory." Item 3.2: "Provide the Statement of Applicability referenced in your certificate." You look at your compliance folder. You have a SOC 2 Type II. You have a DPDP Act 2023 readiness memo. You have an internal information security policy. You do not have an ISO 27001 certificate. The tender clock is 45 days. First-time ISO 27001 certification takes 12 to 18 months. The deal dies on Item 3.1.

This lesson is written for the moment before that moment. What ISO 27001 actually is, why your enterprise buyer demands it, and why the certificate you cannot produce in 45 days matters enough to run a 12 to 18 month workstream to get it.

What ISO 27001 is, one paragraph

ISO/IEC 27001:2022 is the international standard for an information security management system, published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) jointly through Subcommittee 27 of Joint Technical Committee 1 [L1-C1]. It sets out requirements for establishing, implementing, maintaining and continually improving an ISMS. Certification is not self-issued. An organisation demonstrates conformity by passing a two-stage audit performed by a certification body that is itself accredited by a national accreditation body which is itself a signatory to the IAF Multilateral Recognition Arrangement. The certificate is valid for three years and covers a defined scope (the parts of the organisation covered by the ISMS).

That paragraph contains four separate concepts that beginners routinely conflate. The standard (ISO 27001) says what an ISMS must contain. The ISMS is the system you build to meet the standard. The certificate is issued by a CB after audit. The accreditation is the chain of authority (IAF MLA to NABCB to CB to certificate) that makes the certificate mean anything.

Where ISO 27001 sits in the ISO family

The ISO/IEC 27000 family currently contains over 40 published standards. This course focuses on nine of them.

StandardPurposeCertifiable?
ISO/IEC 27000:2018Overview and vocabulary. The dictionary of the ISMS family.No
ISO/IEC 27001:2022ISMS requirements. The certifiable standard.Yes
ISO/IEC 27002:2022Information security controls. The 93 Annex A controls, expanded with implementation guidance.No (controls are certifiable via 27001 SoA)
ISO/IEC 27003:2017ISMS implementation guidance. Non-normative.No
ISO/IEC 27004:2016Monitoring, measurement, analysis and evaluation. Metrics guidance for Clause 9.1.No
ISO/IEC 27005:2022Risk management guidance. Companion to Clauses 6.1.2 and 6.1.3.No
ISO/IEC 27006:2015 + A1:2020Requirements for bodies providing audit and certification of ISMS. Governs CBs, not clients.No (CBs comply)
ISO/IEC 27017:2015Code of practice for information security in cloud services. Extension of 27002.Yes (joint 27001 + 27017)
ISO/IEC 27018:2019Code of practice for protection of PII in public clouds acting as PII processors.Yes (joint 27001 + 27018)
ISO/IEC 27701:2025Privacy Information Management System. Standalone since October 2025.Yes (standalone)

You certify to 27001. You implement the controls listed in 27001 Annex A which are detailed in 27002. You use the risk methodology guided by 27005. Your CB is governed by 27006. If you add cloud, 27017 or 27018 layer on. If you add privacy, 27701:2025 is now standalone (since October 2025). The rest of the 27000 family provides reference material.

Who accredits certification bodies in India

You cannot self-certify. You cannot get a valid ISO 27001 certificate from an unaccredited body. The chain of authority runs:

  1. ISO/IEC publishes the standard (ISO 27001:2022).
  2. International Accreditation Forum (IAF) operates the Multilateral Recognition Arrangement (MLA) that makes ISMS certificates mutually recognised across signatory countries.
  3. NABCB (National Accreditation Board for Certification Bodies), the Indian accreditation body under the Quality Council of India, is a full member of IAF and a signatory to the MLA [L1-C2]. NABCB accredits Indian CBs for ISO 27001.
  4. Certification bodies (Bureau Veritas India, BSI India, TÜV SÜD South Asia, TÜV Nord India, DNV Business Assurance India, SGS India, Intertek India, IRQS) perform the audits and issue the certificates.
  5. Your organisation receives the certificate covering your defined scope.

A certificate issued by a NABCB-accredited CB carries the IAF MLA equivalence stamp. It is recognised by UKAS in the UK, ANAB in the US, DAkkS in Germany, JAB in Japan, ANSI-ASQ in North America and every other IAF MLA signatory. Your European bank buyer accepts it without a debate. A certificate issued by an unaccredited body carries no such recognition and will not clear procurement.

Important 2026 change. Use of the NABCB Accreditation Symbol on accredited certificates became mandatory from 1 July 2026 [L1-C3]. If your certificate is dated on or after that date, the NABCB Symbol should be visible. If it is not, ask your CB. A certificate without the Symbol issued after 1 July 2026 is non-compliant with NABCB accreditation rules and your buyer may reject it.

Why enterprise buyers demand it

Four reasons, in the order they matter.

One: their procurement policy requires it. Any enterprise buying from India has an internal vendor risk framework that classifies vendors by data sensitivity and mandates specific assurance evidence for each tier. For any vendor touching customer data, transactional data, or operational systems, an ISO 27001 certificate is the default assurance in Europe, UK, APAC and the Middle East. Their procurement team cannot approve vendor onboarding without it.

Two: their regulator requires it of their vendors. If your customer is a European bank, the ECB Guidelines on Outsourcing and Third-Party Risk Management require them to obtain independent assurance over material third-party providers. If your customer is a UK financial services firm, the FCA Operational Resilience rules require the same. ISO 27001 is the default artefact. Without it your customer breaches their own regulator's outsourcing rules by using you.

Three: their auditor will ask them where it is. If your customer's own ISMS certification includes you as a supplier in scope for Annex A.5.19 (Information security in supplier relationships), their next surveillance audit will ask what independent assurance they hold over your controls. If your customer's SOX or JSOX audit relies on you for a material IT general control, the same question applies from a different angle.

Four: their insurer requires it. Cyber insurance underwriters require the insured to obtain ISO 27001, SOC 2 or equivalent third-party assurance from all material SaaS and outsourced-services vendors. Without the certificate the insurer can decline a breach claim on the ground that the insured failed to verify vendor controls.

All four stack. Your customer wants the deal too, but their procurement team, their regulators, their auditors and their insurers are structurally prevented from signing off without the ISO 27001 certificate in hand.

What ISO 27001 is not

A short list of misconceptions worth clearing early.

  • Not a technical security assessment. ISO 27001 audits management systems, not networks. The auditor does not run a penetration test or a vulnerability scan. The auditor tests whether your ISMS is designed and operating as documented. Penetration testing is inputs to your risk assessment, not a substitute for the ISMS.
  • Not a product certification. ISO 27001 certifies an organisation, not a product. Common Criteria (ISO/IEC 15408) and FIPS 140 certify products. Do not confuse them.
  • Not one-and-done. The certificate is valid three years with annual surveillance audits in Years 1 and 2 and full recertification in Year 3. You are on a permanent audit treadmill from certification onwards.
  • Not free of the Amendment 1:2024 climate change addition. Since February 2024 you must formally consider whether climate change is relevant to your ISMS under Clause 4.1 and whether interested parties have climate-related requirements under Clause 4.2. Lesson 1.3 walks the amendment in detail.
  • Not the same as SOC 2. Different standards body (ISO not AICPA). Different report format (certificate not attestation). Different reader (procurement not auditor). Lesson 1.2 next walks the comparison.
  • Not conferred by a PECB Lead Implementer classroom course. That is a personal certification for consultants. This course teaches the operational knowledge behind the standard; it does not confer the PECB certificate. If you want the PECB personal cert, take their exam directly.

The Indian picture

Nearly every mature Indian IT services company (Infosys, TCS, Wipro, HCLTech, Tech Mahindra, LTI Mindtree) publishes an ISO/IEC 27001:2022 certification across its global delivery network [L1-C4]. Nearly every mature Indian SaaS (Zoho, Freshworks, Sprinto) publishes ISO 27001 alongside SOC 2, ISO 27017, ISO 27018 and ISO 27701 [L1-C5]. Indian fintech (Razorpay, PhonePe, Paytm) publishes ISO 27001 alongside PCI DSS. These postures are the current bar. Being outside them makes your enterprise sales cycle materially harder in Europe, UK, APAC, Middle East and increasingly in enterprise India.

If you are running a Series A to Series C Indian SaaS, or a mid-cap IT services firm, or a Global Capability Centre, or a healthcare data processor, or a fintech, or a telecom, or a professional services organisation with any material client data exposure, ISO 27001 is either already on your roadmap or about to be. This course is written for that operator.

Next lesson: ISO 27001 vs SOC 2 vs NIST CSF vs ISO 27701. When each applies. Which one your customer actually wants when they ask for "your security certificate".

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (35 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹19,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
ISO/IEC 27001:2022, ISO/IEC 27001:2022 (Oct 2022 base standard) (Information security management systems Requirements) L1-C1
ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection, Information security management systems, Requirements. Published 25 October 2022 by ISO/IEC JTC 1/SC 27. Currently effective base standard for ISMS certification. Structure: ten main clauses (0 Introduction through 10 Improvement) plus Annex A referencing the 93 controls of ISO/IEC 27002:2022. Transition from ISO/IEC 27001:2013 closed 31 October 2025 per IAF Mandatory Document.
NABCB Policy, NABCB Accreditation (QCI, IAF MLA) (NABCB accreditation regime for CBs in India) L1-C2
NABCB (National Accreditation Board for Certification Bodies) is the accreditation body under the Quality Council of India (QCI). Full member of IAF, ILAC and APAC; signatory to IAF MLA. Accredits Indian CBs for ISO/IEC 27001 (and other management system standards) against ISO/IEC 17021-1 read with ISO/IEC 27006.
NABCB Policy, NABCB Symbol Mandate 1 July 2026 (Accreditation symbol mandate) L1-C3
NABCB Accreditation Symbol became mandatory on all accredited certificates issued in India with effect from 1 July 2026. Certificates issued without the NABCB Symbol after this date are non-compliant with NABCB accreditation rules. Certified organisations should verify their current certificate displays the Symbol.
Public ISO 27001 Certification, Infosys ISO 27001 posture (Infosys ISMS certification) L1-C4
Infosys maintains ISO/IEC 27001:2022 certification across its global delivery centres. Represents the mature Indian IT services baseline: multi-site scope, integrated with ISO 9001 and ISO 20000, extended with ISO 27017 / 27018 for cloud and ISO 27701 for privacy.
Public ISO 27001 Certification, Zoho ISO 27001 posture (Zoho ISMS + cloud extensions) L1-C5
Zoho publishes its ISMS posture including ISO/IEC 27001, ISO/IEC 27017 (cloud), ISO/IEC 27018 (cloud PII) and ISO/IEC 27701 (privacy) alongside SOC 2, GDPR, DPDP, HIPAA and PCI DSS. Represents the mature Indian SaaS baseline.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The ISO 27001 story
Module 2: Clauses 4 to 6: Context, Leadership, Planning
  • Clause 4 Context of the organisation (including Amendment 1:2024 climate change)
  • Clause 5 Leadership and the ISMS Policy
  • Clause 6.1 Actions to address risks and opportunities
  • Clauses 6.1.2 and 6.1.3 — Risk assessment and treatment methodology
  • Clauses 6.2 and 6.3 — ISMS objectives and Planning of changes
Module 3: Clauses 7 to 10: Support, Operation, Evaluation, Improvement
  • Clause 7 Support — Resources, competence, awareness, communication
  • Clause 7.5 Documented information — the four mandatory items + ISMS Manual TOC
  • Clause 8 Operation — Executing the plan
  • Clause 9 — Monitoring, Internal Audit, Management Review
  • Clause 10 Improvement — Nonconformity and CAPA
Module 4: Annex A controls Part 1: Organizational + People
  • A.5 Organizational controls Part 1 (A.5.1 through A.5.20)
  • A.5 Organizational controls Part 2 (A.5.21 through A.5.37)
  • A.6 People controls (8 controls, A.6.1 through A.6.8)
  • The 11 new controls in ISO/IEC 27002:2022 walkthrough
  • Building the Statement of Applicability (all 93 controls)
Module 5: Annex A controls Part 2: Physical + Technological
  • A.7 Physical controls (14 controls, A.7.1 through A.7.14)
  • A.8 Technological controls Part 1 (A.8.1 through A.8.17)
  • A.8 Technological controls Part 2 (A.8.18 through A.8.34)
  • Cloud-specific controls and ISO 27017 / 27018 alignment
  • Control Ownership Matrix and evidence sources
Module 6: The risk assessment operating layer
  • Choosing a risk methodology (asset-based, scenario-based, hybrid)
  • Asset inventory and information classification
  • Threat identification, vulnerability identification, likelihood + impact scoring
  • Risk treatment options (Modify, Retain, Avoid, Share) and the Risk Treatment Plan
  • GRC tooling — buy vs build (Sprinto, Vanta, Drata, Secureframe, AuditBoard, Archer)
Module 7: Certification body selection + Stage 1 + Stage 2 audits
  • What NABCB accreditation means (and why IAF MLA matters)
  • CB RFP process + Selection Matrix (Bureau Veritas, BSI, TÜV SÜD, TÜV Nord, DNV, SGS, Intertek, IRQS)
  • Stage 1 audit — documentation review
  • Stage 2 audit — operating effectiveness testing
  • Handling nonconformities, CAPA closure, certificate issuance
Module 8: Post-certification + adjacent standards
  • Surveillance Years 1 + 2, and recertification Year 3
  • Publishing certification status + answering VSAQ / CAIQ / SIG questionnaires
  • ISO/IEC 27701:2025 privacy add-on + DPDP Act 2023 crosswalk
  • ISO/IEC 27017 (cloud) + ISO/IEC 27018 (cloud PII) extensions
  • ISO/IEC 42001 AI Management System as the next horizon