Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Governance, Risk & Compliance

ISO 27001:2022 certification, built to survive year two.

An ISO 27001 certification consultant in India can get you a certificate in a few months. The harder question is whether the management system behind it still functions at the first surveillance audit, when the consultant has gone and someone internal has to produce a year of risk reviews, internal audits and management meetings.

ISO 27001:2022 is a management system standard, not a control checklist. The certifiable part is the machinery (scope, risk assessment, treatment, objectives, internal audit, management review, corrective action) and the 93 Annex A controls are what the risk assessment selects from. Programmes that start with the control list and work backwards produce documentation nobody uses.

We build it the other way round, sized to your organisation, and we design the ongoing operation to fit the people who will run it. Where cloud services are in scope, ISO 27017 extends the control set; where you also need SOC 2, the evidence largely overlaps and should be collected once.

Why you need it

01 / 06

Why organisations certify.

01

It removes a commercial blocker.

Enterprise procurement, government tenders and an increasing number of mid-market buyers require it. The certificate replaces a lengthy security review with a document, which frequently shortens a sales cycle by a quarter.

02

It forces a real risk assessment.

The standard requires you to identify risks to information, own them, treat them and review that treatment. Most organisations discover during this exercise that several accepted risks were never actually accepted by anyone with the authority to accept them.

03

It gives security a governance structure.

Defined scope, assigned responsibilities, measurable objectives, internal audit and management review turn security from a set of activities into something that can be directed and held to account.

04

One control set answers several obligations.

The 2022 Annex A maps closely to SOC 2, and substantially to DPDP Act and GDPR security expectations, sector regulation and customer questionnaires. Building once and mapping is far cheaper than running parallel programmes.

Instrument

02 / 06

The controls, in plain English.

Pick a control and see the question it actually asks and the evidence that answers it. Then check how much of it you were doing for another framework anyway.

What we deliver

03 / 06

What we deliver.

01

Gap analysis

Your current position measured against every clause of ISO 27001:2022 and every applicable Annex A control, with evidence sampled rather than self-reported. Delivered as a gap register with effort estimates, so the certification decision is made on a real number.

02

Scope and ISMS design

Defining what the management system covers (which services, sites, systems and people) because scope determines both the cost of certification and the value of the certificate. Too narrow and customers reject it; too broad and the programme stalls.

03

Risk assessment and treatment

A repeatable risk methodology, an asset and risk register your team can maintain, treatment decisions with named owners, and a Statement of Applicability that justifies every control you have included and every one you have not.

04

Control implementation

Practical delivery of the Annex A controls the risk assessment selected (policies, access control, cryptography, logging, supplier management, secure development, business continuity) implemented in your actual environment rather than described in a document.

05

Internal audit and management review

The clauses that catch most first-time applicants. We run the first internal audit programme, prepare the management review, and train someone internal to run both after we leave.

06

Certification audit support

Selecting an accredited certification body, preparing your team for Stage 1 and Stage 2, being present during the audit, and handling nonconformities through to closure.

How we run it

04 / 06

Six stages to certification.

  1. 01

    Initial assessment and gap analysis

    Current state against clauses 4-10 and Annex A, with evidence sampled. The output is a costed, sequenced gap register and an honest timeline, including when we think you are not ready to start.

    Weeks 1-3
  2. 02

    Define scope and objectives

    ISMS boundaries agreed and documented, interested parties and their requirements identified, and security objectives set that align with what the business is actually trying to do.

    Weeks 3-4
  3. 03

    Risk assessment and treatment

    Assets and risks identified and evaluated using a documented methodology, treatment decisions made and owned, and the Statement of Applicability produced with justification for every inclusion and exclusion.

    Weeks 4-8
  4. 04

    Implementation of controls

    The selected Annex A controls delivered in priority order, with policies written to be followed and evidence generated as a by-product of operating them rather than assembled before the audit.

    Months 2-6
  5. 05

    Internal audit and management review

    A full internal audit against the standard, nonconformities raised and corrected, and a documented management review with the leadership team. Auditors check these first, and they are the most common reason a Stage 2 fails.

    Months 5-7
  6. 06

    External audit and certification

    Stage 1 documentation review, then Stage 2 implementation audit with an accredited body. We attend both, manage the evidence requests, and drive any findings to closure within the corrective action window.

    Months 6-9

Key benefits

05 / 06

What changes after.

The security questionnaire gets shorter

A certificate with a scope statement that covers what the customer is buying answers most of an enterprise security review in one attachment.

Risk decisions have owners

A maintained risk register with named owners and dated treatment decisions, so accepting a risk becomes a decision someone made rather than something that happened.

The system survives the consultant

Internal audit, management review and risk review run on your calendar, by your people, with the templates and training to sustain them through surveillance and recertification.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Standards

  • ISO/IEC 27001:2022
  • ISO/IEC 27002:2022
  • ISO/IEC 27005
  • ISO/IEC 27004

ISMS operation

  • Risk register and treatment plan
  • Statement of Applicability
  • Internal audit programme
  • Management review pack

Evidence automation

  • AphelioNYX Compliance Hub
  • Cloud posture evidence collection
  • Access review workflows

Technical control validation

  • Nessus
  • Prowler
  • Semgrep
  • Wazuh

Mapping

  • SOC 2 Trust Services Criteria
  • DPDP Act, 2023
  • GDPR Article 32

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

What clients ask about ISO 27001.

How long does ISO 27001:2022 certification take?
Six to twelve months for most organisations, driven far more by how much needs building than by size. A company with mature controls and no management system can certify in about six months; one starting from very little should plan on nine to twelve. The certification body also needs Stage 1 and Stage 2 booked with a gap between them, which adds weeks that no amount of effort compresses.
What does it cost?
Two separate costs. The certification body charges audit days based on your headcount and scope complexity, quoted directly by them. Consulting cost depends on how much of the work you do internally: some clients want the whole programme delivered, others want gap analysis and audit support and do the implementation themselves. We quote both parts openly at scoping so you can see which is which.
Can we certify only part of the business?
Yes, and defining scope well is one of the more consequential decisions in the programme. Scope can cover a specific product, service, site or entity. The constraint is commercial rather than technical: if the scope statement on your certificate does not clearly cover the service your customer is buying, they will read it and ask for more. We advise against the very narrow scopes that look efficient and then fail their purpose.
What changed in the 2022 version?
Annex A was restructured from 114 controls in 14 domains into 93 controls in four themes (organisational, people, physical and technological) with 11 new controls covering areas such as threat intelligence, cloud services, data leakage prevention and secure coding. The management system clauses are largely unchanged. Organisations certified against the 2013 version have had to transition, and new certifications are issued against 2022.
What happens after we are certified?
The certificate runs three years with surveillance audits in years one and two and a full recertification in year three. Between them the management system has to actually operate: risk reviews, internal audits, management reviews, corrective actions and evidence of the controls running. This is where certificates are lost, and it is why we design the ongoing operation around your team rather than around ours.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.