Up to 50% off this month — use code NISHUPROMO at checkout

ISO/IEC 27001:2022 Certification — Information Security (ISMS)

ISO Certification

ISO/IEC 27001:2022 Certification — Information Security (ISMS)

ISO 27001 consultancy for IT, SaaS, BPO and fintech teams: risk assessment, Statement of Applicability, policies and audit readiness.

$799 – $1,799

+ GST where applicable

Use code NISHUPROMO at checkout.

  • Secure payment via Razorpay
  • GST invoice by email
  • Dedicated expert assigned
  • Typical delivery 8–16 weeks

Description

ISO/IEC 27001:2022 — Information Security Management System. The international standard for protecting information. Enterprise clients and overseas customers increasingly ask for it before signing contracts.

Who it is for

Software and SaaS companies, IT service providers, data centres and hosting companies, BPO/KPO, fintech, healthcare IT, and any business handling customer or personal data.

Why get certified

  • Win enterprise and international clients that require ISO 27001
  • Answer security questionnaires and vendor audits quickly
  • Lower the risk of breaches, ransomware and data loss
  • Supports DPDP Act 2023 and GDPR compliance efforts

What’s included

  • Free initial consultation and gap analysis against ISO/IEC 27001:2022
  • Defining the certification scope, boundaries and applicable requirements
  • ISMS scope, information security policy and objectives
  • Information asset register and risk assessment & treatment plan
  • Statement of Applicability covering the 93 Annex A controls
  • Policies for access control, cryptography, backup, supplier security, secure development, incident management and business continuity
  • Implementation support and staff awareness training (online)
  • A full internal audit and management review before the external audit
  • Coordination of the Stage 1 and Stage 2 certification audits with an independent, accredited certification body
  • Support to close any non-conformities raised by the auditor
  • The certificate is issued by the certification body, valid for 3 years subject to annual surveillance audits

How it works

  1. 1. Kick-off & gap analysis — we review your current security controls, infrastructure and policies against ISO 27001 and Annex A.
  2. 2. Risk assessment — we identify information assets, threats and vulnerabilities, rate the risks and agree a treatment plan with you.
  3. 3. Policies & Statement of Applicability — we write the ISMS documents and justify each Annex A control as included or excluded.
  4. 4. Implementation — controls are put in place (access reviews, backups, logging, awareness training) and evidence is collected.
  5. 5. Internal audit & management review — a full ISMS internal audit and corrections before the external audit.
  6. 6. Certification audit & certificate — Stage 1 and Stage 2 audits by an accredited certification body, followed by the certificate once findings are closed.

Timeline

Typically 8–16 weeks from kick-off to certificate. The time depends on how ready your organisation is, how quickly documents and evidence are shared, and when the certification body can schedule the audit.

What we need from you

  • Company registration details (incorporation / GST / MSME), address of the site(s) and number of employees
  • A coordinator on your side who can spend a few hours a week during implementation
  • Access to key people for interviews and records/evidence (asset lists, access reviews, backup logs, vendor contracts, incident records)

Pricing notes

  • The price depends on company size and covers one site. Multi-site organisations, organisations with more than 150 employees, or combined (integrated) certifications get a custom quote.
  • Annual surveillance audits in years 2 and 3, and recertification after 3 years, are quoted separately.
  • Travel for on-site audits outside the auditor’s city, if needed, is billed at actual cost.

Genuine, verifiable certification

Nishu Digital prepares you for certification. The certificate itself is issued only by an independent certification body after a real audit, and that body is accredited by an IAF-member accreditation body (such as NABCB in India). We do not sell "certificates without audit". You can verify a genuine certificate on the certification body’s website or on IAF CertSearch.

After you order

Within 1 business day, your dedicated ISO consultant contacts you to schedule the free gap-analysis call and share the document checklist. You can also WhatsApp us any time with your order number.

You may also like

Added to cart