WP-01 · Scope of engagement

Certification, without the guesswork.

ISO 27001, ISO 9001 and ISO 27701 readiness led by a certified lead auditor — plus DPDP Act alignment and continuous vulnerability management that keeps you secure between audits.

Led by an Exemplar Global certified lead auditor · 27001 · 9001 · 27701 · Bengaluru, serving clients across India

WP-02 · Findings

Most companies fail their first audit for the same three reasons.

NC-01 · Documentation

Policies written to look right rather than work — the auditor spots the gap between paper and practice within the first hour.

NC-02 · Controls

Controls that exist in the manual but not in daily operations. Evidence requests come back empty.

NC-03 · Timing

A scramble in the final fortnight that leaves nonconformities no last-minute fix can hide.

Auditor's view

We approach it from the other side of the table.

When you have sat in the auditor's chair, you know exactly what gets checked, what gets challenged, and what quietly passes. That is the difference between being certified and being ready.

WP-03 · Service lines

Three ways we keep you audit-ready.

Fixed-fee readiness engagements to get you certified, privacy work aligned to India's DPDP Act, and a managed retainer that keeps your posture defensible all year round.

File A · Readiness27001 / 9001

ISO Certification Readiness

Fixed fee · Defined milestones · Led by a lead auditor

End-to-end preparation for ISO/IEC 27001 (information security) and ISO 9001 (quality) — individually, or as a combined management system that removes duplicate documentation and a second internal audit programme.

  • Gap assessment with clause-level maturity ratings
  • Documentation and controls built to work, not just to pass
  • Internal audit and management review before the CB arrives
  • Support through Stage 1 and Stage 2 certification audits
  • Help selecting and verifying an accredited certification body
Discuss your certification
File B · Privacy27701 / DPDP Act

Privacy & DPDP Readiness

ISO/IEC 27701 · India's Digital Personal Data Protection Act

India's DPDP Act changed the obligations for anyone handling personal data. ISO/IEC 27701 extends your existing ISMS into a privacy information management system — giving you a structured, auditable way to demonstrate compliance rather than a policy PDF nobody follows.

  • Data inventory and processing-activity mapping
  • Consent, notice and data-principal rights workflows
  • 27701 controls mapped against DPDP obligations
  • Processor and vendor agreement review
  • Breach response and notification readiness
Discuss privacy readiness
File C · RetainerVulnerability Management as a Service

Vulnerability Management as a Service

Monthly retainer · Continuous scanning · Prioritised remediation

Certification is a moment; security is a habit. Our managed service scans your estate on a schedule, ranks what actually matters, and tracks fixes to closure — producing exactly the evidence Annex A controls, surveillance audits and customer security questionnaires ask for.

  • Scheduled authenticated scans across servers, endpoints and cloud workloads
  • Risk-ranked findings with business context — signal, not a thousand-row export
  • Remediation tracking with named owners and due dates
  • Monthly executive report mapped to ISO 27001 Annex A evidence requirements
  • Support during surveillance audits and customer security reviews
Discuss a retainer

Every engagement is scoped and quoted in writing before work begins — fixed fee, milestone-based, no open-ended day rates and no surprise line items.

WP-04 · Method

From first call to certificate, in four milestones.

The same sequence an auditor follows to assess you — run in advance, so nothing is a surprise on the day.

M1 · Assess

Gap assessment

Clause-by-clause review of where you stand today, with a maturity rating and a prioritised findings list.

≈ 2 weeks
M2 · Build

Documentation & controls

Policies, procedures and controls written for how your team actually works — implemented, not shelved.

≈ 6–8 weeks
M3 · Verify

Internal audit & fix

A full internal audit run to certification standard, management review, and closure of every finding.

≈ 2–3 weeks
M4 · Certify

Certification support

CB selection, accreditation verification, quote comparison, and hands-on support through Stage 1 and Stage 2.

CB-dependent

WP-05 · Engagement profiles

What an engagement actually looks like.

Three typical scoping shapes, so you can find the one nearest to your situation before you call.

Note: these are illustrative scoping profiles showing how we size and sequence work — not descriptions of past clients. Client engagements are confidential and we don't publish them without written consent.

Profile 01

SaaS company chasing enterprise deals

Roughly 45 staff, cloud-native, blocked in procurement because prospects demand ISO 27001. Priority is speed without a system that collapses after certification.

SCOPE · ISO/IEC 27001, single cloud environment TIMELINE · 14–16 weeks to Stage 2 ADD-ON · VMaaS retainer for ongoing evidence
Profile 02

Services firm handling client personal data

Around 120 staff across two sites, existing 9001 certificate, now facing DPDP obligations and customer privacy questionnaires they can't answer consistently.

SCOPE · ISO/IEC 27001 + 27701, DPDP mapping TIMELINE · 18–22 weeks, phased by site ADD-ON · Vendor and processor agreement review
Profile 03

Certified, but audit season is chaos

Already holds certificates. Every surveillance audit becomes a fire drill because evidence is assembled retrospectively rather than generated continuously.

SCOPE · VMaaS retainer + evidence programme TIMELINE · Ongoing, monthly reporting ADD-ON · Internal audit programme run annually

WP-06 · Credentials

Led by a certified lead auditor.

27001Lead Auditor

Information security

9001Lead Auditor

Quality management

27701Lead Auditor

Privacy information

Lead Auditor certifications issued by Exemplar Global — an internationally recognised personnel certification body for management system auditors.

Most consultants prepare you for an audit they have never conducted. Holdfast is led by an Exemplar Global certified lead auditor across all three standards we prepare clients for — backed by more than a decade in security operations, endpoint management and vulnerability management before that.

That experience shapes everything: the documentation we write is the documentation auditors accept, the evidence we build is the evidence they request, and the internal audit we run before certification is as rigorous as the real one.

A word on accreditation. No consultancy — ours included — can certify you. Certification must come from an independent certification body accredited by NABCB or another IAF-recognised accreditation body. We help you choose one and verify its accreditation before you sign, because certificates from unaccredited bodies get rejected by the buyers and regulators you bought them for.

In development · 2026

LATTICE — post-quantum cryptography readiness

Our upcoming platform maps your cryptographic estate, scores what quantum computing puts at risk, and plans your migration before "harvest now, decrypt later" becomes your problem.

Ask about early access

WP-07 · Questions

Frequently asked.

How long does ISO 27001 certification take in India?

Most SMEs are certification-ready in 12–16 weeks from the gap assessment, depending on headcount, number of sites and starting maturity. The certification body's own scheduling for Stage 1 and Stage 2 adds time on top — we help you book that early so it doesn't become the bottleneck.

Do you certify us yourselves?

No — and be cautious of anyone who says they can. A consultant who both prepares and certifies you has a conflict of interest that invalidates the certificate. We prepare you, run the internal audit, and support you through the certification body's Stage 1 and Stage 2 audits. The certificate is issued by the CB.

How do I check a certification body is legitimate?

Verify its accreditation before you sign anything. In India, check NABCB's directory of accredited bodies; internationally, check the IAF CertSearch database. An unaccredited certificate costs less and is worth nothing — buyers and regulators reject them.

We do this check as part of every readiness engagement, and we'll do it for you on request even if we aren't working together.

What does an engagement cost?

Quotes are fixed-fee and issued in writing before work starts, scoped to your headcount, sites, and current maturity. Pricing on enquiry — a 30-minute consultation is usually enough for us to scope it, and you'll get a clear number with milestones rather than an open-ended day rate.

Can you combine ISO 9001 and ISO 27001?

Yes, and it's usually cheaper than running them separately. Both use the same Annex SL high-level structure, so one integrated management system, one document set and one internal audit programme can serve both — with a single CB audit covering the combined scope.

How does ISO 27701 relate to India's DPDP Act?

They're different things doing complementary jobs. DPDP is law and sets your obligations; ISO 27701 is a certifiable framework that gives you a structured, auditable way to meet them. Implementing 27701 won't automatically make you DPDP-compliant, but it gives you the inventory, consent handling, rights workflows and records that demonstrating compliance requires.

We're already certified — why would we need VMaaS?

Certification proves your system existed on audit day. Surveillance audits, customer questionnaires and actual attackers all care about the months in between. VMaaS keeps evidence flowing continuously — scans, risk-ranked findings, remediation records — so audit season stops being a fire drill.

Do you work remotely or on-site?

Both. Gap assessments and internal audits benefit from time on-site; documentation, reviews and VMaaS run remotely. We're based in Bengaluru and work with clients across India.

WP-08 · Next step

Start with a free consultation.

Thirty minutes, no obligation. Tell us where you are — pursuing your first certificate, adding a standard, facing DPDP obligations, or tired of scrambling before every audit — and you'll leave with a clear picture of scope, timeline and a fixed written quote to follow.

+91 88921 45713

WhatsApp — same number

contact@holdfastassurance.com

◎ Bengaluru, Karnataka · Serving clients across India

We reply within one business day.

WhatsApp