ISO Certifications
ISO 27001 (Non-IAF)
Quick answer: ISO 27001:2022 Information Security Management certification in 14-30 days
₹14,999
Gujarat offerAll-inclusive · No hidden fees · No bank details required
4.9 (171 reviews)
Why choose FinTax24
- Expert Verified Reviewed by compliance specialists
- Process Checked Accuracy and compliance checks
- Data Secure Secure document handling
- 4.9/5 rated Verified rating from 171+ clients
Audience
Who needs ISO 27001 (Non-IAF)?
- IT services, software product and SaaS companies
- BPO, KPO, BPM and GCC captive units
- Fintech, payment aggregators and BFSIs handling customer data
- Healthcare, pharma and clinical research organizations
- Data centres, hosting and managed service providers
- Any organization processing client Personally Identifiable Information (PII)
How it works
- 1
Gap Assessment
Map current security posture against ISO 27001:2022 clauses and the 93 Annex A controls.
- 2
Documentation
Draft policies, risk treatment plan, Statement of Applicability and mandatory records.
- 3
Implementation
Operate the ISMS with evidence of access reviews, training, drills and incident handling.
- 4
Stage 1 + 2 Audit
CB reviews SoA and policies (Stage 1) then audits controls across sites (Stage 2).
- 5
Certificate Issued
Receive the non-IAF ISO 27001:2022 certificate valid for 3 years subject to surveillance.
- 6
Annual Surveillance
Yearly surveillance audits confirm SoA compliance and risk treatment effectiveness.
Timeline
Why file this
Benefits of iso 27001 (non-iaf)
- Demonstrates confidentiality, integrity and availability of client data
- Stronger eligibility for enterprise SaaS, BPO and GCC RFPs
- Maps directly to GDPR, DPDPA 2023 and RBI cyber security controls
- Includes 93 Annex A controls across 4 themes in the 2022 version
- Reduces likelihood of breach and lowers incident-response cost
- Annual surveillance audit keeps certificate active for 3 years
- Foundation for ISO 27017 (cloud) and ISO 27701 (privacy)
- Improves customer trust in BFSI, fintech and healthcare contracts
Documents required
8 documents needed for iso 27001 (non-iaf).
- Information security policy and Statement of Applicability (SoA)
- Risk assessment methodology and risk treatment plan
- Asset inventory and data classification register
- Access control policy and user access review records
- Incident management process and past incident logs
- Business continuity and disaster recovery plans
- Internal audit report and management review minutes
- Applicable legal register (IT Act 2000, DPDPA 2023, GDPR)
DIY vs FinTax24
Why file iso 27001 (non-iaf) with FinTax24 instead of doing it yourself.
| Aspect | DIY / Portal | Local Tax Consultant | FinTax24 |
|---|---|---|---|
| Filing time | 7–14 days (typical) | Varies by availability and workload | 14-30 business days |
| Expert review | None | Depends on the consultant | Expert verified on every filing |
| Document check | You self-verify; rejected on portal | Manual review may vary | Pre-verified by our team before submission |
| Support | Email / chatbot | Appointment-based or office hours | WhatsApp + phone, Mon–Sat 10 AM–7 PM IST |
| Pricing | Government fees only | Consultant fee + government fees | Transparent: ₹6,999 + govt fees |
Frequently asked questions
What is ISO 27001:2022 certification?
ISO/IEC 27001:2022 is the international standard for Information Security Management Systems. It requires a risk-based approach, a Statement of Applicability and continuous control monitoring across 93 Annex A controls.
How long does ISO 27001 certification take in India?
With a ready ISMS, certification is achieved in 14-30 days via non-IAF CBs such as IAS, UAF and ASCB. First-time companies typically need 2-3 months for ISMS implementation before audit.
Is this Non-IAF accredited?
Yes. This is a non-IAF mark issued by accredited certification bodies such as IAS, UAF, ASCB and others. IAF-accredited ISO 27001 marks via NABCB-accredited CBs are scoped separately.
What is the validity of an ISO 27001 certificate?
Validity is 3 years from issue, subject to successful annual surveillance audits and a re-certification audit before the 3-year expiry.
Does ISO 27001 satisfy DPDPA 2023 or GDPR?
ISO 27001 maps strongly to DPDPA, GDPR and RBI cyber security framework but does not automatically satisfy them. ISO 27701 is the privacy-specific extension, and legal advice is recommended.
What is a Statement of Applicability (SoA)?
The SoA lists each of the 93 Annex A controls, its applicability, justification for exclusion (where allowed) and implementation status. It is mandatory for ISO 27001:2022 audit.
How many controls are in ISO 27001:2022?
ISO 27001:2022 has 93 Annex A controls grouped under 4 themes: Organizational, People, Physical and Technological. The 2013 version had 114 controls across 14 domains.
What is the cost of ISO 27001 in India?
Non-IAF ISO 27001 in India starts from ₹14,999 with annual surveillance at ₹6,999. Final cost depends on headcount, sites and number of Annex A controls applied.
Sources & authority: For regulations on iso 27001 (non-iaf), refer to iso.org , qci.org.in .
Last reviewed by: FinTax24 Compliance Desk · Reviewed on:
Related ISO Certifications
- ISO 9001 (Non-IAF) ISO 9001:2015 Quality Management System certification — issued in 7-15 days View details →
- ISO 14001 (Non-IAF) ISO 14001:2015 Environmental Management System certification in 7-15 days View details →
- ISO 45001 (Non-IAF) ISO 45001:2018 Occupational Health and Safety certification in 7-15 days View details →
- ISO 10002 (Non-IAF) ISO 10002:2018 Customer Satisfaction and Complaints Handling certification in 7-15 days View details →
Related glossary terms Show more
Related glossary terms
Plain-English definitions for terms that come up in ISO Certifications.
About FinTax24
ISO 27001 · Startup India · MCA registered- Legal name
- FinTax24 LLP
- Founded
- 2021
- Headquarters
- Palitana, Gujarat, India
- Certifications
- ISO 27001 · ISO 9001 · ISO 22301
- Recognition
- Startup India · MCA registered
- Coverage
- All 33 Gujarat districts + Dadra & Nagar Haveli & Daman & Diu
- Clients served
- 10,000+
- Hours
- Mon - Sat: 10 AM - 7 PM IST
Ready to file ISO 27001 (Non-IAF)?
Talk to an expert on WhatsApp. Most consultations are free.