Last updated: April 29, 2026
ISO 27001:2022 is the global infosec standard. Indian SaaS that sells to enterprise customers needs it.
The ISMS lifecycle
- Define scope (which systems, departments, locations)
- Risk assessment (assets, threats, vulnerabilities, risk treatment)
- Statement of Applicability (SoA) — which Annex A controls apply
- Implement controls
- Internal audit
- Management review
- External audit (Stage 1 + Stage 2)
- Certification + ongoing surveillance audits
2022 changes
- Annex A reduced from 114 to 93 controls (reorganised, not weakened)
- 11 new controls (threat intel, cloud security, secure coding, etc.)
- Aligned more closely with modern environments
Effort estimate (Indian SaaS, 50 employees)
- 4-6 months prep
- 2-3 months Stage 1+2 audit
- ₹6-15 lakh certification body fees
- Plus internal effort and tooling
Module Quiz · 5 questions
Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.