From Zero ISMS to Full ISO 27001 Certification — In Under 6 Months, First Attempt
A growing IT services company in Ahmedabad was losing enterprise deals because they couldn't prove their security posture. Their international clients were demanding ISO 27001. They had no formal policies, no ISMS, and no idea where to start. We took them from zero to certified.
100%
ISO 27001:2022 Compliant
1st
Attempt Certification
0
Major Non-Conformities
Client Background
An IT services and consulting company based in Ahmedabad, Gujarat. They manage critical intellectual property and data for global clients across the US and Europe. About 80 employees working on sensitive client projects — software development, data analytics, and managed services.
The Problem
They were in a tough spot:
Two enterprise contracts worth ₹3Cr+ were stuck because the clients demanded ISO 27001 proof
Their security measures were ad-hoc — some password policies here, a firewall there, but nothing formal or documented
They had no idea what an ISMS looked like or how to prepare for an external audit
The VP of IT thought it would take 2 years. They needed it in 6 months or they'd lose the deals
What We Did
We broke the certification journey into three clear phases and kept things moving fast:
Started with a thorough gap analysis — compared where they were against every ISO 27001:2022 control. Identified 47 gaps across access control, encryption, incident management, and physical security
Built their ISMS from scratch — policies, procedures, risk registers, asset inventories, everything documented properly. Ran awareness training for all 80 staff so everyone understood their role in security
Conducted rigorous internal audits to find and fix issues before the external auditors showed up. Then guided them through Stage 1 (documentation review) and Stage 2 (implementation audit) with an accredited certification body
Technologies & Frameworks
ISO 27001:2022 framework with Annex A controls
Risk management using qualitative methodology
Access control systems and multi-factor authentication
Incident management and business continuity planning
Data classification and encryption policies
Results
Achieved full ISO 27001:2022 certification on the very first attempt
Zero major non-conformities reported by the external auditor
Completed the entire journey in 5.5 months — ahead of schedule
Both enterprise contracts (₹3Cr+) were signed within weeks of certification
The ISMS is now part of their daily operations, not just a checkbox exercise
Client Outcome
"We thought ISO 27001 would take years. Nonce Systems made it happen in under 6 months with zero disruption to our operations. Zero major non-conformities. Their process is incredibly streamlined — they knew exactly what auditors look for and got us ready for it." The company has since won three more enterprise accounts directly because of their certification.