How long does ISO 27001 certification take in India?
Most SMEs are certification-ready in 12–16 weeks from the gap assessment, depending on headcount, number of sites and starting maturity. The certification body's own scheduling for Stage 1 and Stage 2 adds time on top — we help you book that early so it doesn't become the bottleneck.
Do you certify us yourselves?
No — and be cautious of anyone who says they can. A consultant who both prepares and certifies you has a conflict of interest that invalidates the certificate. We prepare you, run the internal audit, and support you through the certification body's Stage 1 and Stage 2 audits. The certificate is issued by the CB.
How do I check a certification body is legitimate?
Verify its accreditation before you sign anything. In India, check NABCB's directory of accredited bodies; internationally, check the IAF CertSearch database. An unaccredited certificate costs less and is worth nothing — buyers and regulators reject them.
We do this check as part of every readiness engagement, and we'll do it for you on request even if we aren't working together.
What does an engagement cost?
Quotes are fixed-fee and issued in writing before work starts, scoped to your headcount, sites, and current maturity. Pricing on enquiry — a 30-minute consultation is usually enough for us to scope it, and you'll get a clear number with milestones rather than an open-ended day rate.
Can you combine ISO 9001 and ISO 27001?
Yes, and it's usually cheaper than running them separately. Both use the same Annex SL high-level structure, so one integrated management system, one document set and one internal audit programme can serve both — with a single CB audit covering the combined scope.
How does ISO 27701 relate to India's DPDP Act?
They're different things doing complementary jobs. DPDP is law and sets your obligations; ISO 27701 is a certifiable framework that gives you a structured, auditable way to meet them. Implementing 27701 won't automatically make you DPDP-compliant, but it gives you the inventory, consent handling, rights workflows and records that demonstrating compliance requires.
We're already certified — why would we need VMaaS?
Certification proves your system existed on audit day. Surveillance audits, customer questionnaires and actual attackers all care about the months in between. VMaaS keeps evidence flowing continuously — scans, risk-ranked findings, remediation records — so audit season stops being a fire drill.
Do you work remotely or on-site?
Both. Gap assessments and internal audits benefit from time on-site; documentation, reviews and VMaaS run remotely. We're based in Bengaluru and work with clients across India.