ISO 27001:2022, recertification-friendly.
The world's most-asked-for security certification — built into tecsxpert as a first-class program. Annex A controls, SoA management, internal audit calendar, surveillance and recertification automation.
An ISO 27001 program, not a checklist.
Annex A:2022 — all 93 controls
Organizational, people, physical, technological. Each control comes with a default policy, owner template, and evidence collector.
Statement of Applicability
Live SoA generated from applicability decisions. Justifications, exclusions, control selection — versioned and signed.
Internal audit calendar
ISO 19011-aligned audit planning, sampling, walkthroughs, finding management, management review packs.
Risk treatment
Risk register with treatment plans, residual risk tracking, board-level acceptance workflows.
Surveillance & recertification
3-year cycle automation. Delta-aware change packs. Cert body coordination from inside the platform.
Crosswalks built in
Every Annex A control is mapped to SOC 2, DPDP, GDPR, HIPAA, PCI and NIST. Evidence flows everywhere it should.
From kickoff to certificate — fast.
Most Managed GRC customers close ISO 27001 stage 1 audit within 90 days of kickoff, and stage 2 within another 60. Self-service customers run the same playbook — at their own pace.
ISO 27001 questions, answered.
How long does ISO 27001 certification take?
For a typical SMB or startup, ISO 27001:2022 certification takes 6–12 months from initial gap assessment to certification audit. The timeline depends on the scope of the ISMS, the maturity of existing controls, and the certification body's availability. Tecsxpert accelerates the process with pre-mapped Annex A controls, automated evidence collection, and internal audit tooling.
What is the difference between ISO 27001 and ISO 27001:2022?
ISO 27001:2022 is the current version, updated from the 2013 edition. Key changes include a restructured Annex A with 93 controls (down from 114), 11 new controls covering cloud security, threat intelligence, physical security monitoring, and data masking, and alignment with the Annex SL management system structure. Organisations certified to the 2013 standard had until October 2025 to transition. Tecsxpert maps exclusively to the 2022 standard.
What is a Statement of Applicability (SoA)?
The Statement of Applicability is a mandatory ISO 27001 document that lists all 93 Annex A controls, justifies which are applicable to your ISMS, and documents your implementation status and rationale for any exclusions. Tecsxpert generates and maintains your SoA automatically, updating it as your control posture changes.
How much does ISO 27001 certification cost in India?
ISO 27001 certification costs in India typically range from ₹4–15 lakhs all-in, depending on organisation size, scope, and whether you use a managed GRC service or self-service tooling. This includes consultant or platform costs, internal team time, and certification body audit fees. Tecsxpert's self-service tier starts at ₹3,500/month and includes full ISO 27001:2022 support.
From scoping to certificate.
30-minute walkthrough on your real stack. No slideware. Bring your AWS account or GitHub org if you want to see live findings.