ISO/IEC 27001 compliance services — design, implement & certify your ISMS.
ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS), providing a systematic, risk-based framework for managing information security across people, processes, and technology. SIRI Law LLP guides organisations from initial gap assessment through certification, with ongoing support for continual improvement and surveillance audits.
Getting the transition status right
The 2013-to-2022 transition deadline isn't upcoming. It's already passed — and an unmigrated certificate is now expired, not merely outdated.
Some ISO 27001 content describes the 2022 edition's changes without stating plainly that the transition window has closed. ISO/IEC 27001:2022 rolled out in October 2022, replacing the 2013 edition, and certification bodies gave certified organisations a 36-month transition window. That window ended on 31 October 2025. Any organisation still holding a 2013-edition certificate after that date does not have a slightly outdated certification — it has an expired one, with no valid pathway back to 2013-edition compliance. In fact, the cutoff came earlier for some organisations: any recertification review had to be initiated against the 2022 edition, not 2013, from 30 April 2024 onward, and no new certifications against the 2013 edition were permitted from that date either.
By 2026, every certification audit, whether initial or surveillance, is necessarily conducted against ISO/IEC 27001:2022. This is worth stating precisely because an organisation that assumes its 2013 certificate is "still fine, just a bit old" is operating on a false premise that could surface at the worst possible moment — during an enterprise customer's security review, or a cyber insurance renewal that asks for proof of current certification.
For any organisation planning a gap assessment or renewal, the practical starting question is simple and worth confirming explicitly rather than assuming: is your current or most recent certificate issued against the 2022 edition, and if not, has a 2022-edition recertification review already been scheduled or completed?
Evidence, not guesswork
Annex A's 93 controls, across 4 themes
The 2022 restructure that replaced the old 14-domain structure with something more usable.
Organisational
Policies, roles, supplier relationships, threat intelligence, cloud services.
People
Screening, terms of employment, awareness, disciplinary process.
Physical
Secure areas, equipment, media handling, physical entry controls.
Technological
Access control, cryptography, secure coding, data masking, logging.
Source: ISO/IEC 27001:2022 Annex A. The 2022 revision introduced 11 new controls, including threat intelligence, cloud security, data masking, and secure coding, alongside the restructure from 14 domains into these 4 themes. Confirm current control text with the published standard before finalising a Statement of Applicability.
Scope of services
What our engagement covers
- ISO 27001:2022 gap assessment against all Annex A controls
- ISMS scope definition and context of the organisation
- Risk assessment methodology design (ISO 27005 aligned)
- Asset inventory and information classification
- Risk register development and risk treatment planning
- Statement of Applicability (SoA) — all 93 controls addressed
- Security policy framework — 20+ policy documents
- Control implementation advisory — all 4 Annex A themes
- Supplier and third-party security management programme
- Business continuity and disaster recovery planning
- Internal audit programme design and execution
- Management review preparation and facilitation
- Stage 1 and Stage 2 certification audit support
- Non-conformity response and corrective action management
- Post-certification surveillance audit support
- DPDPA/GDPR integration within the ISMS framework
What the numbers actually mean
Four figures that frame ISO 27001 compliance today
No valid pathway remains to certify or recertify against the 2013 edition — 2022 is the only current standard.
Across 4 themes, including 11 controls new in the 2022 restructure.
From gap assessment through Stage 2 audit — compressible with good existing controls.
With annual surveillance audits required in between full recertification cycles.
Our engagement process
How we work, step by step
Initial Scoping & Assessment
Gap assessment against ISO/IEC 27001:2022, including confirmation of your current certification status if applicable, engagement scope definition, and a prioritised remediation roadmap.
Programme Design
Control framework, documentation structure, evidence requirements, and governance processes tailored to your organisation.
Implementation Advisory
Advising on implementation of each required control, working alongside your technical and operational teams to build controls that are practical and auditable.
Internal Audit & Validation
Internal audit or readiness assessment identifying any remaining gaps before the formal certification or attestation process begins.
Certification / Attestation Support
Managing auditor queries, providing evidence, and resolving findings during the formal audit or assessment.
Post-Certification Advisory
Ongoing support — surveillance audit preparation, change management, and regulatory update advisory.
Typical engagement timeline varies by organisation size and existing control maturity.
Benefits & deliverables
What you get from this engagement
Gap Assessment
Comprehensive gap assessment against ISO 27001:2022 Annex A, producing a prioritised remediation roadmap with effort estimates and a realistic certification timeline.
Risk Methodology Design
Risk assessment methodology aligned with ISO 27005 and your organisational context, ensuring it is practical, auditable, and proportionate to your risk appetite.
Documentation Development
The full ISMS documentation set — policies, procedures, records, and the Statement of Applicability — tailored to your organisation, not generic templates.
Control Implementation
Advisory on implementing each required control, providing practical, technically sound guidance that satisfies the auditor without creating unnecessary operational burden.
Internal Audit
A rigorous pre-certification internal audit, identifying any remaining gaps and preparing your team for the Stage 2 certification audit.
Certification Audit Support
Presence during the certification audit, managing auditor queries, providing evidence, and resolving non-conformities on the day.
Integration advantage
Compliance engagements backed by qualified legal counsel
Our compliance engagements ensure your programme satisfies both technical certification requirements and legal obligations under DPDPA, IT Act, and sector-specific regulation.
We check certificate status, not just control coverage
If your organisation is still working from a 2013-edition certificate, that's the first thing we flag, since it changes the entire engagement from a routine gap assessment to an urgent recertification.
DPDPA and GDPR built into the ISMS, not bolted on
Our legal team integrates DPDPA and GDPR obligations directly into your ISMS documentation and Statement of Applicability, avoiding duplicate compliance work.
Controls that pass the audit without breaking operations
Every control recommendation is scoped for what your organisation can actually sustain, not a theoretical best-case implementation that collapses after certification.
Certified engineers
Our team holds CCSP, CISM, CIPP/E, CEH, OSCP, CISSP, CPENT, and ISO 27001 Lead Auditor credentials — including the Lead Auditor qualification specific to this standard.
Frequently asked
ISO/IEC 27001, answered directly
How long does ISO 27001 certification take?
From gap assessment to certification, most organisations take 9 to 18 months. Smaller organisations with a limited ISMS scope and good existing controls can achieve certification in 6 to 9 months. Larger, complex organisations may take 18 to 24 months. We provide a realistic timeline after the gap assessment, based on your specific context.
Is our ISO 27001:2013 certificate still valid?
No, not if it hasn't transitioned. ISO/IEC 27001:2022 replaced the 2013 edition, and certification bodies gave organisations a 36-month transition window ending 31 October 2025. Any organisation still certified under the 2013 edition after that date holds an expired certificate — recertification audits since 30 April 2024 have already been required to run against the 2022 edition, and no new certifications against 2013 have been permitted since then. If your certificate predates the transition and you haven't confirmed a 2022-edition recertification, we recommend checking its status immediately rather than assuming continuity.
What is the difference between ISO 27001 and SOC 2?
ISO 27001 is an international standard with mandatory certification by an accredited body, applicable to any organisation globally. SOC 2 is a US-origin attestation framework specifically for service organisations (SaaS, cloud), attested by a CPA firm against Trust Services Criteria. ISO 27001 is more globally recognised; SOC 2 is the de facto standard for US enterprise SaaS procurement. Many organisations pursue both.
Do we need to certify the entire organisation?
No — ISO 27001 allows you to define a scope that covers specific services, systems, or locations. A focused scope can accelerate certification and reduce cost while still satisfying the requirements of most enterprise customers. We advise on scope definition as part of the gap assessment, balancing commercial value with implementation effort.
What does the annual surveillance audit involve?
After initial certification (valid for 3 years), accredited certification bodies conduct annual surveillance audits to verify your ISMS remains compliant and operational. Surveillance audits are less intensive than the initial certification audit, typically focusing on a subset of controls, ISMS objectives, and any identified non-conformities. We support all surveillance audits and the 3-year recertification.
Does the July 2026 ISO/IEC 27000 update change anything about our ISO 27001 certification?
No. The July 2026 revision applies to ISO/IEC 27000, the overview and vocabulary document for the ISMS family, not to ISO/IEC 27001 itself, which remains the current, unrevised 2022 edition. Nothing about Annex A's requirements or how certification audits are conducted has changed as a result.
Ready to start your ISO/IEC journey?
All engagements begin with a complimentary scoping call.
Let us understand your environment and confirm your certification status before proposing the right approach.
Related services
Other ways SIRI Law LLP supports your compliance posture
Visit or contact us
SIRI Law LLP — Hyderabad, India
| Registered office | HITEC City, Madhapur, Hyderabad, Telangana 500081, India |
| Telephone | +91 79819 12046 |
| info@sirilawllp.com | |
| Other offices | New Delhi, India · Austin, Texas, USA · Online worldwide |
| Hours | Mon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7 |

