📞 Call Now 💬 WhatsApp 📋 Report
⚖️
SIRI Law LLP
● Typically replies within 30 min
👋 Hi! How can SIRI Law LLP help you today?

We offer expert legal and cybersecurity advisory. Tap below for a confidential chat.
SIRI Law · Now
💬  Start Chat on WhatsApp
ISO/IEC 27001 Compliance Services in India | SIRI Law LLP
ISO/IEC 27001 · Information Security · Hyderabad, India

ISO/IEC 27001 compliance services — design, implement & certify your ISMS.

ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS), providing a systematic, risk-based framework for managing information security across people, processes, and technology. SIRI Law LLP guides organisations from initial gap assessment through certification, with ongoing support for continual improvement and surveillance audits.

93Annex A controls across 4 themes — Organisational, People, Physical, Technological
31 Oct 20252013-edition transition deadline — now passed; 2013 certificates held after this date are expired
70,000+Organisations certified globally — the world's most widely recognised information security standard
9–18 moTypical timeline from gap assessment to certification
The ISO 27001 transition clock
Live tracking · scroll to see every relevant date
Rolled out
OCT 2022
ISO/IEC 27001:2022 published, replacing the 2013 edition — restructured Annex A, 11 new controls, 93 total across 4 themes.
Cutoff
30 APR 2024
Last date any recertification review could still be initiated against the 2013 edition — 18 months after 2022's publication.
Deadline passed
31 OCT 2025
36-month transition window closes — 2013-edition certificates held after this date are expired, full stop.
Confirmed
2026
Every certification and surveillance audit conducted in 2026 is against the 2022 edition — there is no valid 2013-edition pathway remaining.
Related, not 27001
JUL 2026
ISO/IEC 27000 (the family overview document) receives a substantial 6th-edition revision — restructured, but ISO 27001 itself has had no new edition in 2026.
Standing
3 years
Certification validity period — annual surveillance audits required in between, full recertification audit at year three.

Getting the transition status right

The 2013-to-2022 transition deadline isn't upcoming. It's already passed — and an unmigrated certificate is now expired, not merely outdated.

Some ISO 27001 content describes the 2022 edition's changes without stating plainly that the transition window has closed. ISO/IEC 27001:2022 rolled out in October 2022, replacing the 2013 edition, and certification bodies gave certified organisations a 36-month transition window. That window ended on 31 October 2025. Any organisation still holding a 2013-edition certificate after that date does not have a slightly outdated certification — it has an expired one, with no valid pathway back to 2013-edition compliance. In fact, the cutoff came earlier for some organisations: any recertification review had to be initiated against the 2022 edition, not 2013, from 30 April 2024 onward, and no new certifications against the 2013 edition were permitted from that date either.

By 2026, every certification audit, whether initial or surveillance, is necessarily conducted against ISO/IEC 27001:2022. This is worth stating precisely because an organisation that assumes its 2013 certificate is "still fine, just a bit old" is operating on a false premise that could surface at the worst possible moment — during an enterprise customer's security review, or a cyber insurance renewal that asks for proof of current certification.

A related but distinct 2026 update: the ISO 27000 family overview
In July 2026, ISO and IEC published a substantial sixth edition of ISO/IEC 27000 — the overview and vocabulary document for the entire ISMS family, not ISO 27001 itself. The revision restructured how the family's documents are categorised and significantly trimmed the terminology section, redirecting most definitions to ISO's Online Browsing Platform instead. It's worth knowing this happened, since it sometimes gets conflated with a 27001 update in casual conversation — but ISO/IEC 27001:2022 remains the current, unrevised edition of the certifiable standard itself; nothing in the July 2026 27000 update changes what Annex A requires or how certification audits are conducted.

For any organisation planning a gap assessment or renewal, the practical starting question is simple and worth confirming explicitly rather than assuming: is your current or most recent certificate issued against the 2022 edition, and if not, has a 2022-edition recertification review already been scheduled or completed?

Evidence, not guesswork

Annex A's 93 controls, across 4 themes

The 2022 restructure that replaced the old 14-domain structure with something more usable.

37

Organisational

Policies, roles, supplier relationships, threat intelligence, cloud services.

8

People

Screening, terms of employment, awareness, disciplinary process.

14

Physical

Secure areas, equipment, media handling, physical entry controls.

34

Technological

Access control, cryptography, secure coding, data masking, logging.

Source: ISO/IEC 27001:2022 Annex A. The 2022 revision introduced 11 new controls, including threat intelligence, cloud security, data masking, and secure coding, alongside the restructure from 14 domains into these 4 themes. Confirm current control text with the published standard before finalising a Statement of Applicability.

Scope of services

What our engagement covers

  • ISO 27001:2022 gap assessment against all Annex A controls
  • ISMS scope definition and context of the organisation
  • Risk assessment methodology design (ISO 27005 aligned)
  • Asset inventory and information classification
  • Risk register development and risk treatment planning
  • Statement of Applicability (SoA) — all 93 controls addressed
  • Security policy framework — 20+ policy documents
  • Control implementation advisory — all 4 Annex A themes
  • Supplier and third-party security management programme
  • Business continuity and disaster recovery planning
  • Internal audit programme design and execution
  • Management review preparation and facilitation
  • Stage 1 and Stage 2 certification audit support
  • Non-conformity response and corrective action management
  • Post-certification surveillance audit support
  • DPDPA/GDPR integration within the ISMS framework

What the numbers actually mean

Four figures that frame ISO 27001 compliance today

Expired
2013 certs post-31 Oct 2025

No valid pathway remains to certify or recertify against the 2013 edition — 2022 is the only current standard.

93
Annex A controls

Across 4 themes, including 11 controls new in the 2022 restructure.

9–18 mo
Typical certification timeline

From gap assessment through Stage 2 audit — compressible with good existing controls.

3 yrs
Certification validity

With annual surveillance audits required in between full recertification cycles.

Our engagement process

How we work, step by step

01

Initial Scoping & Assessment

Gap assessment against ISO/IEC 27001:2022, including confirmation of your current certification status if applicable, engagement scope definition, and a prioritised remediation roadmap.

02

Programme Design

Control framework, documentation structure, evidence requirements, and governance processes tailored to your organisation.

03

Implementation Advisory

Advising on implementation of each required control, working alongside your technical and operational teams to build controls that are practical and auditable.

04

Internal Audit & Validation

Internal audit or readiness assessment identifying any remaining gaps before the formal certification or attestation process begins.

05

Certification / Attestation Support

Managing auditor queries, providing evidence, and resolving findings during the formal audit or assessment.

06

Post-Certification Advisory

Ongoing support — surveillance audit preparation, change management, and regulatory update advisory.

Typical engagement timeline varies by organisation size and existing control maturity.

Benefits & deliverables

What you get from this engagement

Gap Assessment

Comprehensive gap assessment against ISO 27001:2022 Annex A, producing a prioritised remediation roadmap with effort estimates and a realistic certification timeline.

Risk Methodology Design

Risk assessment methodology aligned with ISO 27005 and your organisational context, ensuring it is practical, auditable, and proportionate to your risk appetite.

Documentation Development

The full ISMS documentation set — policies, procedures, records, and the Statement of Applicability — tailored to your organisation, not generic templates.

Control Implementation

Advisory on implementing each required control, providing practical, technically sound guidance that satisfies the auditor without creating unnecessary operational burden.

Internal Audit

A rigorous pre-certification internal audit, identifying any remaining gaps and preparing your team for the Stage 2 certification audit.

Certification Audit Support

Presence during the certification audit, managing auditor queries, providing evidence, and resolving non-conformities on the day.

Integration advantage

Compliance engagements backed by qualified legal counsel

Our compliance engagements ensure your programme satisfies both technical certification requirements and legal obligations under DPDPA, IT Act, and sector-specific regulation.

01 — Precision

We check certificate status, not just control coverage

If your organisation is still working from a 2013-edition certificate, that's the first thing we flag, since it changes the entire engagement from a routine gap assessment to an urgent recertification.

02 — Integration

DPDPA and GDPR built into the ISMS, not bolted on

Our legal team integrates DPDPA and GDPR obligations directly into your ISMS documentation and Statement of Applicability, avoiding duplicate compliance work.

03 — Practical

Controls that pass the audit without breaking operations

Every control recommendation is scoped for what your organisation can actually sustain, not a theoretical best-case implementation that collapses after certification.

04 — Credentials

Certified engineers

Our team holds CCSP, CISM, CIPP/E, CEH, OSCP, CISSP, CPENT, and ISO 27001 Lead Auditor credentials — including the Lead Auditor qualification specific to this standard.

Frequently asked

ISO/IEC 27001, answered directly

How long does ISO 27001 certification take?

From gap assessment to certification, most organisations take 9 to 18 months. Smaller organisations with a limited ISMS scope and good existing controls can achieve certification in 6 to 9 months. Larger, complex organisations may take 18 to 24 months. We provide a realistic timeline after the gap assessment, based on your specific context.

Is our ISO 27001:2013 certificate still valid?

No, not if it hasn't transitioned. ISO/IEC 27001:2022 replaced the 2013 edition, and certification bodies gave organisations a 36-month transition window ending 31 October 2025. Any organisation still certified under the 2013 edition after that date holds an expired certificate — recertification audits since 30 April 2024 have already been required to run against the 2022 edition, and no new certifications against 2013 have been permitted since then. If your certificate predates the transition and you haven't confirmed a 2022-edition recertification, we recommend checking its status immediately rather than assuming continuity.

What is the difference between ISO 27001 and SOC 2?

ISO 27001 is an international standard with mandatory certification by an accredited body, applicable to any organisation globally. SOC 2 is a US-origin attestation framework specifically for service organisations (SaaS, cloud), attested by a CPA firm against Trust Services Criteria. ISO 27001 is more globally recognised; SOC 2 is the de facto standard for US enterprise SaaS procurement. Many organisations pursue both.

Do we need to certify the entire organisation?

No — ISO 27001 allows you to define a scope that covers specific services, systems, or locations. A focused scope can accelerate certification and reduce cost while still satisfying the requirements of most enterprise customers. We advise on scope definition as part of the gap assessment, balancing commercial value with implementation effort.

What does the annual surveillance audit involve?

After initial certification (valid for 3 years), accredited certification bodies conduct annual surveillance audits to verify your ISMS remains compliant and operational. Surveillance audits are less intensive than the initial certification audit, typically focusing on a subset of controls, ISMS objectives, and any identified non-conformities. We support all surveillance audits and the 3-year recertification.

Does the July 2026 ISO/IEC 27000 update change anything about our ISO 27001 certification?

No. The July 2026 revision applies to ISO/IEC 27000, the overview and vocabulary document for the ISMS family, not to ISO/IEC 27001 itself, which remains the current, unrevised 2022 edition. Nothing about Annex A's requirements or how certification audits are conducted has changed as a result.

Ready to start your ISO/IEC journey?

All engagements begin with a complimentary scoping call.

Let us understand your environment and confirm your certification status before proposing the right approach.

or call +91 79819 12046 — Mon–Sat, 9 AM – 7 PM IST

Visit or contact us

SIRI Law LLP — Hyderabad, India

Registered officeHITEC City, Madhapur, Hyderabad, Telangana 500081, India
Telephone+91 79819 12046
Emailinfo@sirilawllp.com
Other officesNew Delhi, India · Austin, Texas, USA · Online worldwide
HoursMon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7
© SIRI Law LLP · Hyderabad, Telangana

This page is provided for general informational purposes only. Compliance requirements vary by organisation, sector, and jurisdiction. References to ISO/IEC 27001:2022 transition deadlines and the ISO/IEC 27000 family reflect publicly available standards information as of publication and remain subject to further ISO/IEC revision; confirm current standard editions and certification body requirements before relying on any specific date here. Engagement with SIRI Law LLP requires a formal retainer. This page does not constitute legal advice. SIRI Law LLP is a registered law firm under the Limited Liability Partnership Act 2008, practising under the Advocates Act 1961; complaints regarding professional conduct may be directed to the Bar Council of Telangana.

Scroll to Top