An ISO 27001 certification consultant in India can get you a certificate in a few months. The harder question is whether the management system behind it still functions at the first surveillance audit, when the consultant has gone and someone internal has to produce a year of risk reviews, internal audits and management meetings.
ISO 27001:2022 is a management system standard, not a control checklist. The certifiable part is the machinery (scope, risk assessment, treatment, objectives, internal audit, management review, corrective action) and the 93 Annex A controls are what the risk assessment selects from. Programmes that start with the control list and work backwards produce documentation nobody uses.
We build it the other way round, sized to your organisation, and we design the ongoing operation to fit the people who will run it. Where cloud services are in scope, ISO 27017 extends the control set; where you also need SOC 2, the evidence largely overlaps and should be collected once.