ISO/IEC 27001 Certification Readiness
The international standard for information security management. We help you build an ISMS that holds up — designing it with your teams, validating the controls the way an attacker would, and bringing you to audit-ready for a clean Stage 1 and Stage 2 certification audit.
Gap assessment to internal audit. CERT-In Empaneled. The accredited body issues the certificate — we make sure you earn it.
The benchmark for managing information security
ISO/IEC 27001 is the world's most widely recognized standard for an Information Security Management System — an ISMS.
It is not a checklist of products to buy; it is a framework for governing security as an ongoing discipline. You define the scope of what you are protecting, assess the risks to it, decide which controls treat those risks, operate them, and continually improve — under the oversight of leadership and the scrutiny of internal and external audit. Certification is independent, third-party proof that this system exists and works.
The standard was substantially updated in 2022. ISO/IEC 27001:2022 restructured its control set — Annex A — from the legacy 114 controls across 14 domains into 93 controls grouped under four clear themes, and introduced eleven new controls reflecting how security has changed: threat intelligence, cloud-service security, data leakage prevention, secure coding and more. The transition window for organizations still on the 2013 edition closed on 31 October 2025 — the 2013 version is now withdrawn, and every active certificate is held against the 2022 edition. Whether you are certifying for the first time or were caught mid-transition, the target is the same one: ISO/IEC 27001:2022.
"Certification isn't a document you obtain. It's an assertion an accredited body makes about a system that genuinely works — so we build the system to be true, not just to pass."
Why organizations pursue ISO 27001
ISO/IEC 27001 is voluntary — but rarely optional. Most organizations reach for it because someone they answer to expects it.
| Criterion | Who expects it — and why |
|---|---|
| A customer or contract demands it | Enterprise buyers, partners and procurement teams increasingly require a current ISO 27001 certificate before they will sign or share data. |
| You're bidding for regulated or public work | Certification is a common eligibility gate in tenders, RFPs and supply-chain due-diligence questionnaires. |
| You handle sensitive or personal data | Where you process customer, financial or personal information, a certified ISMS demonstrates due diligence to regulators and data principals alike. |
| Your board wants assurance | Independent certification gives leadership and audit committees objective evidence that security is governed, not assumed. |
| You operate across borders | As an international standard, ISO 27001 travels — one certificate recognized by customers and regulators in every market you sell into. |
| You want one system, many frameworks | A well-built ISMS becomes the backbone for SOC 2, ISO 27701, ISO 42001, the DPDP Act and more — assess once, reuse the evidence. |
What the standard actually asks for
ISO/IEC 27001:2022 has two halves. The management-system clauses (4–10) define how the ISMS is run — context, leadership, planning, support, operation, performance evaluation and improvement.
Annex A then provides the reference catalogue of security controls, drawn from ISO/IEC 27002:2022: 93 controls organized under four themes. Your Statement of Applicability records, control by control, which you apply and why — the single most scrutinized document in the audit.
Organizational (37 controls) — Policies, roles, supplier and cloud-service security, threat intelligence, incident management and business-continuity readiness — the governance layer that surrounds everything else.
People (8 controls) — Screening, terms of employment, awareness and training, and the human behaviours that controls depend on.
Physical (14 controls) — Secure areas, equipment, media and physical monitoring — protecting the tangible assets and facilities behind the data.
Technological (34 controls) — Access control, cryptography, secure development, configuration management, logging, data-leakage prevention and the technical safeguards an attacker meets first.
The management system itself — Context · Leadership · Planning · Support · Operation · Performance Evaluation · Improvement — runs on a continual Plan-Do-Check-Act cycle, so the ISMS keeps improving rather than decaying between audits.
From gap to certification-ready — and beyond
Certification is awarded by an accredited certification body after a two-stage audit. Our job is everything that earns it: building an ISMS that is genuinely sound, validating that its controls work, and assembling the evidence so the audit confirms what is already true.
We take you from a first gap assessment to a confident Stage 2 — and stay with you through surveillance and recertification.
FIG. 02 — ISMS & certification lifecycle · 01–06 Intect-led · 07–08 accredited certification body · 09 the three-year cycle
The whole cycle is a Plan-Do-Check-Act loop — risk assessment and implementation (Plan/Do), internal audit and management review (Check), remediation and continual improvement (Act). The ISMS is built to get better with every pass, not just to clear one audit.
What an engagement includes
We scope to where you are — a first-time build, a 2013-to-2022 transition, or sustaining an existing certificate — and cover the work end to end.
Gap assessment against ISO/IEC 27001:2022
(management clauses + all 93 Annex A controls)
ISMS scope definition
systems, sites, functions and third parties
Information-security risk assessment and risk treatment plan
Statement of Applicability
inclusion/exclusion decisions with justification
Policy and procedure suite aligned to the standard
Control-implementation support across people, process and technology
Remediation of identified gaps, with a prioritized roadmap
Technical control validation
penetration testing and configuration review that proves controls actually work
Evidence collection and an audit-ready artifact pack
Remediation retest after fixes
Internal audit, conducted to the standard's requirements
Management-review pack for leadership oversight
Pre-assessment / mock Stage 1 and Stage 2
Liaison and support through the certification body's Stage 1 and Stage 2 audits
Surveillance-audit support across the three-year cycle
Recertification readiness
Continuous-compliance guidance as your scope, risks and controls evolve
We audit like we attack
A paper audit confirms that a control is written down. We confirm that it actually holds.
Most readiness work stops at the document
The conventional path to ISO 27001 reviews policies, samples records and ticks the controls that have documentation behind them. That satisfies the letter of the standard — but a written access-control policy and an access-control system that an attacker can walk through are not the same thing. Gaps that never appear in a document review are exactly the gaps that surface in a breach.
We test the control, not just the claim
Intect is CERT-In Empaneled with an offensive-security heritage, so our readiness work is technically validated. Where the standard expects access control, cryptography, secure development or logging to be effective, our researchers test them — safely, the way an adversary would — and bring you pentest-backed evidence that the control performs. You walk into Stage 2 with controls that have already withstood a real probe, and you leave with a security posture that means it.
The certificate proves you have a system. Our testing proves the system works.
PENTEST-BACKED EVIDENCEWhat you receive
Every engagement produces the artefacts your team needs to operate the ISMS — and the evidence pack an accredited certification body expects to review.
Gap assessment report
Your current state mapped against ISO/IEC 27001:2022, with a prioritized roadmap to certification-ready.
Risk assessment & treatment plan
A defensible methodology, risk register and treatment decisions the auditor can follow.
Statement of Applicability
Each of the 93 Annex A controls, included or excluded, with documented justification.
Policy & procedure suite
The ISMS documentation set, written to the standard and tailored to how you actually operate.
Internal audit report
Independent verification that controls are operating, not just documented.
Management review pack
The oversight evidence leadership needs for Clause 9.
Pre-assessment / mock audit report
A dry run of Stage 1 and Stage 2, with findings to close before the real thing.
Technical control validation report
Pentest-backed evidence that key controls genuinely work, with remediation guidance and retest.
Audit-ready evidence pack
Collected, organized artefacts that map cleanly to the controls and clauses.
Why teams choose Intect for ISO 27001
CERT-In Empaneled — An assessor accredited under India's national cybersecurity authority — credibility the audit room recognizes.
We build and we break — Most consultancies only write policy. We implement the ISMS and then test it like attackers, so your evidence is proven, not asserted.
Researcher-led, not template-led — Senior practitioners design your ISMS to your real risk and operations — not a copy-paste documentation kit.
One partner, the full cycle — From first gap assessment through Stage 2 support, surveillance and recertification — continuity instead of handoffs.
Frequently asked questions
Does Intect issue the ISO 27001 certificate?
No — and no consultancy can. The certificate is issued by an independent, accredited certification body after it conducts the Stage 1 and Stage 2 audits. Intect makes you certification-ready: we build and validate the ISMS, run the internal audit and mock audit, and support you through the certification body's audits. Keeping readiness and certification separate is exactly what preserves the audit's independence — and its value.
What's the difference between the audit and certification?
The certification audit is the assessment the accredited body performs in two stages. Certification is the outcome — the certificate they award if you pass. Our internal audit and pre-assessment are independent checks we run beforehand so the certification audit confirms what is already in place.
We were on ISO 27001:2013 — what now?
The transition window closed on 31 October 2025 and the 2013 edition is withdrawn, so all certification now targets ISO/IEC 27001:2022. If you let a 2013 certificate lapse, you re-certify against 2022; if you're building fresh, you build to 2022 from the start. We scope the work to wherever you are.
What is the Statement of Applicability, and why does it matter so much?
The SoA lists all 93 Annex A controls and records, for each, whether you apply it and why. It is the document auditors scrutinize most, because it connects your risk assessment to the controls you actually operate. We build it with you so it is both defensible and accurate.
How long does certification take?
It depends on the size and complexity of your scope and how mature your current controls are — which is exactly what the gap assessment establishes first. We give you a realistic, evidence-based timeline up front rather than a generic promise, and we sequence the work so nothing blocks the certification audit.
What happens after we're certified?
Certification runs on a three-year cycle. The accredited body conducts annual surveillance audits to confirm the ISMS is still operating, and a full recertification audit at the end of the cycle. We support you across all of it, so the certificate stays live and the ISMS keeps improving.
Is ISO 27002 a separate certification?
No. You certify against ISO/IEC 27001. ISO/IEC 27002:2022 is the companion guidance that describes the 93 Annex A controls in detail — it informs how you implement, but it is not itself certifiable.
Build it once, reuse it everywhere
A well-built ISMS is the foundation for much more than one certificate.
Build a system that's ready to be certified.
Tell us where you are — first certificate, 2022 transition, or maintaining an existing one — and we'll scope a readiness assessment that fits, or connect you with an assessor.