Governance, Risk & Compliance

Certification is the outcome. The management system is the work.

An ISO 27001 certificate is worth exactly as much as the management system behind it. We build that system with you, run the risk treatment, and get you through Stage 1 and Stage 2 — but the certificate itself comes from an accredited certification body, not from us. Anyone telling you otherwise is selling you a worthless piece of paper.

ISO/IEC 27001:2022 · Annex A Organizational 37 People 8 Physical 14 Technological 34 Statement of Applicability every control: applies or does not, and why The first document a certification auditor opens Certificate issued by an accredited body — never by us
93Annex A controls
4Control themes
4–9 moTypical first certification
0Certificates we issue

What ISO 27001 actually certifies

ISO/IEC 27001:2022 does not certify that your systems are secure. It certifies that you run an Information Security Management System — that you have decided what your controls are, assigned them to owners, assessed the risks they address, and can demonstrate that the whole thing operates and improves. That distinction matters, because it explains why the auditor spends more time on your risk register and your management review minutes than on your firewall rules.

This is also why the certificate is the easy part and the second year is hard. Enough templates and enough overtime in the month before Stage 2 will get most organisations through a first audit. The surveillance audit twelve months later is where programmes fall over, because the same evidence has to be produced again by people who were not there the first time, from a shared drive full of undated screenshots.

We build for the surveillance audit rather than the certification audit. Controls should produce their own evidence as a by-product of operating — access reviews that log themselves, vulnerability scans with their own history, change approvals that live where changes actually happen. And because our testing feeds the same risk register, a penetration test finding and a control failure are one object rather than two teams’ separate problems.

Coverage

The 2022 structure, and where the work actually lands

The 2022 edition replaced the 2013 edition’s fourteen domains with 93 controls across four themes. Your Statement of Applicability — which controls apply, which do not, and why — is the first document any certification auditor opens.

Organizational controls (37)

Policies, roles and responsibilities, supplier and cloud-service relationships, incident management, business continuity, threat intelligence and the legal and regulatory register. The largest theme by count, and the one most often under-documented.

People controls (8)

Screening, terms of employment, awareness and training, the disciplinary process, remote working and confidentiality agreements. Small in number, disproportionately common as a nonconformity.

Physical controls (14)

Secure areas, equipment siting and protection, clear desk and clear screen, secure disposal and media handling. Routinely skipped by cloud-only teams, and still assessed — a co-working desk and an unlocked laptop are in scope.

Technological controls (34)

Access control, cryptography, logging and monitoring, malware protection, data leakage prevention and secure development (A.8.25–A.8.29). This is where independent testing evidence goes straight into the file rather than being asserted.

Clauses 4 to 10

The management-system requirements that are not in Annex A at all: context, leadership, planning, support, operation, performance evaluation and improvement. Certification is failed here more often than on a technical control.

Scope definition

Which entities, sites, systems and services are being certified, and what is legitimately excluded. This single decision is the largest lever on both cost and audit duration, and it is the first thing we settle.

Approach

How an ISO 27001 programme runs

A first certification typically takes four to nine months, driven by starting position and scope rather than by headcount. The certification body also needs Stage 1 and Stage 2 booked with a gap between them, which is calendar time you cannot compress.

  1. 01 · Scope and gap assessment

    What is being certified, and where you stand against all 93 controls and clauses 4–10. Every gap is costed in effort with an owner, so the programme can be planned rather than discovered.

  2. 02 · Risk assessment and treatment

    A risk register your management team can actually discuss, using a documented and repeatable methodology, fed by real findings from testing rather than a hypothetical threat list.

  3. 03 · Statement of Applicability and documentation

    The SoA justified control by control, plus the policy set — written for how your organisation works, not a renamed template pack with someone else’s company name still in the footer.

  4. 04 · Implement and operate

    Controls built and actually run: access reviews performed, logs reviewed, suppliers assessed, incidents exercised. Evidence collection automated wherever the platform can carry it.

  5. 05 · Internal audit and management review

    Both are mandatory under clause 9 before you can go external. We run them as a genuine dry run, so nonconformities surface with us rather than with your auditor.

  6. 06 · Certification and surveillance

    We support Stage 1 and Stage 2 and answer the technical questions in the room. Then continuous monitoring, so year two is a review rather than a rebuild.

Run against recognised standards

  • ISO/IEC 27001:2022The certifiable requirements standard
  • ISO/IEC 27002:2022Implementation guidance for Annex A
  • ISO/IEC 27005Information security risk management
  • ISO/IEC 27701Privacy extension, where personal data is in scope
  • NIST CSF 2.0Cross-mapped where a maturity view is also wanted
  • SOC 2Cross-mapped for organisations pursuing both

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Gap assessment with costed remediation

Every gap against all 93 controls and clauses 4–10, with an effort estimate and a named owner — an honest baseline, not an inflated readiness percentage.

Risk register and treatment plan

Live, owned and reviewable. The document auditors examine most closely and that clients maintain worst.

Statement of Applicability

Justified control by control, with inclusions and exclusions defensible on their own terms and mapped to the evidence that supports them.

Complete ISMS policy set

Access, incident, continuity, supplier, cryptography, development and HR security — in language your staff will actually follow.

Internal audit and management review

Run properly and documented properly, in the form certification bodies accept.

Certification audit support

We are in the room for Stage 1 and Stage 2, and we take the technical questions so your team does not have to.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • A customer contract or tender requires ISO 27001 and there is a date attached to it.
  • You hold a 2013-edition certificate, or you were told one was still available.
  • You are certified and the surveillance audit is a fire drill every single year.
  • You have a policy set nobody reads and controls nobody operates, and you already know it.
  • You are being asked for ISO 27001 and SOC 2 by different customers and want to do the work once.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

ISO 27001 — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

Does SemperWise issue the ISO 27001 certificate?

No, and no consultancy legitimately can. The certification audit must be performed by an accredited certification body that is independent of whoever implemented the management system. We implement the ISMS, run your internal audit and support you through the external audit — but the certificate is issued by the certification body on their own judgement. Any firm offering to both implement and certify is offering you something an informed customer will not accept.

How long does ISO 27001 certification take?

Four to nine months for most organisations, driven by starting position and scope rather than company size. An organisation with reasonable IT discipline, a tight scope and an internal owner who can give it real time can be audit-ready in about four months. Starting from nothing, with a broad scope and no dedicated owner, plan for nine. Stage 1 and Stage 2 also have to be booked with a gap between them, which adds calendar time regardless of how fast you work.

What happened to ISO 27001:2013?

It was withdrawn, and the transition period for certificates issued against it ended on 31 October 2025 (as of August 2026). Only the 2022 edition — 93 Annex A controls across four themes — is current. If anyone offers you a 2013-edition certification today, that is a reason to walk away rather than a shortcut.

What is a Statement of Applicability?

The document that lists all 93 Annex A controls and records, for each one, whether it applies to your organisation and why. Inclusions have to be justified and so do exclusions. It is the first document a certification auditor reads, because it defines what they are auditing you against, and a weak SoA makes every subsequent conversation harder.

What does ISO 27001 certification cost in India?

Two separate costs. The certification body charges its own audit fee based on scope and headcount, paid directly to them — we do not mark it up. Our implementation fee depends on how much of the work you absorb internally: an organisation with an existing IT function and an engaged owner pays considerably less than one needing the whole programme delivered. We scope properly and quote a fixed price rather than a day rate that grows.

Do we need ISO 27001 or SOC 2?

It usually depends on who is asking. European, Indian and Middle Eastern enterprise buyers, and most tender processes, ask for ISO 27001. North American technology buyers ask for SOC 2. If you sell to both, start with ISO 27001 — it is a management system, so it gives you the structure — then add SOC 2, which is materially cheaper in that order than the reverse.

Is ISO 27001 mandatory in India?

Not by statute for most sectors. It is increasingly mandatory commercially, which amounts to the same thing when a contract depends on it. It also gives you a defensible base for DPDP Act obligations around security safeguards and breach response, because the controls substantially overlap even though the legal duties are separate.

Does certification make us secure?

No. It makes you consistent, and consistency is a precondition for security rather than a substitute for it. A certified organisation has decided what its controls are and can show they operate. Whether those controls stop a competent attacker is a different question, and it is the one testing answers — which is why our findings feed the same risk register the ISMS runs on.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.