
September 10, 2026
11 min read
By Kokil Thapa | Last reviewed: September 2026
Your client asks for proof that customer data is handled safely. A procurement team sends an ISO 27001 questionnaire. Your board wants a credible answer before signing enterprise deals. An ISO 27001 Certification Roadmap turns that pressure into a sequenced plan: define scope, build an Information Security Management System (ISMS), close gaps against Annex A controls, and survive two audit stages. If you ship web platforms—especially portals with documents, payments, and personal data—the technical work sits inside that roadmap, not beside it. Start with ISO 27001 basics for engineers if the standard language is new to your team.
What Is an ISO 27001 Certification Roadmap?
ISO/IEC 27001 is the international standard for building and certifying an ISMS. The roadmap is the practical sequence your organisation follows to meet it. You are not certifying "the whole company" by default. You certify a defined scope: a product line, business unit, or hosted service boundary.
On production Laravel and WordPress systems I maintain, scope usually means a named environment: production app, admin panel, CI/CD pipeline, backup store, and the people who operate them. Legal-tech portals with document upload and payment flows—like those described in our Mijar Law Associates client portal work—often become the certification boundary because that is where sensitive data lives.
The standard itself is published by ISO/IEC 27001. Annex A lists 93 controls grouped into organisational, people, physical, and technological themes. Your Statement of Applicability (SoA) explains which controls apply and why others are excluded.
Who owns the roadmap?
Certification is a management system exercise, not a solo dev task. You need executive sponsorship, a designated ISMS owner, and input from engineering, HR, legal, and operations. Developers own evidence for technical controls: access logs, encryption, backup tests, change records.
How Long Does ISO 27001 Certification Take?
Most organisations need 6 to 18 months from kickoff to certificate. A 15-person SaaS team with decent logging and RBAC might hit 9 months. A 200-person firm with scattered spreadsheets and shared admin passwords needs longer.
Timeline drivers include scope size, existing documentation, auditor availability, and how fast you close nonconformities. Stage 1 checks whether your ISMS design is sound. Stage 2 checks whether controls actually work in practice.
| Organisation profile | Typical timeline | Common bottleneck |
|---|---|---|
| Small product team (5–20 staff) | 6–9 months | Missing asset inventory and SoA |
| Mid-size agency or ISV (20–100) | 9–14 months | Weak change management evidence |
| Enterprise or regulated sector | 12–18+ months | Cross-department policy alignment |
| Greenfield ISMS on new platform | 8–12 months | Building ops habits alongside product |
Budget time for corrective actions after internal audit. Auditors treat repeat findings harshly. Plan a 30-day buffer before Stage 2 if your team also ships feature work.
What Are the Phases of an ISO 27001 Implementation?
Think in seven concrete phases. Each phase produces artefacts auditors expect to see.
- Establish governance. Appoint an ISMS manager. Define roles in an RACI matrix. Publish an information security policy signed by leadership.
- Define scope and context. Document interested parties (customers, regulators, partners). List internal and external issues. Draw a scope boundary diagram showing systems, locations, and data flows.
- Run risk assessment. Identify assets, threats, vulnerabilities, and impacts. Score likelihood and consequence. Record treatment decisions: mitigate, accept, transfer, or avoid.
- Select and implement controls. Map treatments to Annex A controls. Implement technical fixes: MFA, least privilege, encrypted backups, secure SDLC checks.
- Operate the ISMS. Run awareness training. Log incidents. Review access quarterly. Test disaster recovery. Keep change tickets linked to deployments.
- Measure and audit internally. Track KPIs: patch SLA, failed login rate, backup success. Conduct an internal audit against ISO 27001 clauses and your SoA.
- External certification audit. Stage 1 review, then Stage 2. Address findings. Receive certificate. Enter annual surveillance cycle.
Clause 4 covers context. Clause 5 covers leadership. Clause 6 covers planning and risk. Clause 7 covers support and competence. Clause 8 covers operational control. Clause 9 covers monitoring and internal audit. Clause 10 covers nonconformity and improvement. Your roadmap should map deliverables to each clause before Stage 1.
Statement of Applicability essentials
The SoA is a living register. For each Annex A control, state: applicable or not, implementation status, and linked policy or procedure. Auditors cross-check SoA entries against live systems. A control marked "implemented" without evidence becomes a major nonconformity.
How Do Developers Prepare Technical Controls for ISO 27001?
Engineering evidence wins or loses Stage 2. Policies on paper mean little if production still allows shared root SSH keys. On Ubuntu servers running PHP 8.3 or 8.4 with Laravel 12 or 13, I focus on controls auditors can verify quickly.
Access control and identity
Enforce MFA on GitLab, hosting panels, and cloud consoles. Remove shared accounts. Map application roles to job functions using packages like Spatie Laravel Permission. Review privileged access quarterly and keep sign-off records.
Secure development and change management
Link every production deploy to a ticket or merge request. Run CI checks before release: lint, tests, dependency audit. Document how secrets stay out of Git. Rotate API keys on a schedule. Our API rate limiting guide supports abuse-prevention evidence for publicly exposed endpoints.
# Example: GitLab CI security gate (excerpt)
stages:
- test
- security
- deploy
dependency_audit:
stage: security
script:
- composer audit --format=plain
- npm audit --audit-level=high
allow_failure: false
deploy_production:
stage: deploy
script:
- dep deploy production
when: manual
only:
- main
Logging, monitoring, and incident response
Centralise auth logs, admin actions, and payment callbacks. Define retention (often 12 months minimum for audit trails). Write a runbook for suspected breach: contain, preserve logs, notify stakeholders. Test it once per year.
Backup, recovery, and availability
Automate nightly database dumps. Store encrypted copies off-server. Run a restore drill and document RTO/RPO results. On shared EC2 stacks I maintain with Deployer 7, backup paths and cron jobs must match the live release symlink—not last month's folder.
Supplier management matters when you rely on hosting, email, SMS, or payment gateways. Collect SOC reports or ISO certificates from vendors. Document due diligence in your vendor register. For Nepal deployments using eSewa, Khalti, or ConnectIPS, record how callback URLs are validated and how failed payments are logged.
Password policy alone is weak evidence. Pair it with enforced complexity, a tested password generation standard for service accounts, and proof that human users cannot reuse compromised credentials across systems.
Evidence pack checklist for engineering
- Asset register: servers, domains, repos, databases, third-party APIs
- Network diagram with data classification labels
- Access review spreadsheets with dates and approver names
- Sample change tickets tied to tagged releases
- Vulnerability scan or
composer auditoutput with remediation notes - Backup logs and latest successful restore test report
- Incident log—even if empty, show the process exists
Detailed control guidance lives in ISO/IEC 27002, the implementation companion to 27001. Use it when writing control descriptions in your SoA.
How Much Does ISO 27001 Certification Cost in Nepal and Globally?
Costs split into internal effort, tooling, consultant fees, and certification body charges. Numbers vary by scope and auditor, but planning ranges help boards approve budget.
| Cost category | Nepal / South Asia (indicative) | Global SMB (indicative) |
|---|---|---|
| Gap assessment consultant | Rs 300,000–800,000 (~USD 2,200–5,900) | USD 5,000–15,000 |
| ISMS documentation support | Rs 400,000–1,200,000 (~USD 3,000–8,900) | USD 8,000–25,000 |
| Stage 1 + Stage 2 audit fees | Rs 500,000–1,500,000 (~USD 3,700–11,100) | USD 10,000–30,000 |
| Annual surveillance audit | Rs 200,000–600,000 (~USD 1,500–4,400) | USD 4,000–12,000 |
| Internal staff time (12 months) | 0.25–0.5 FTE blended | Same order of magnitude |
Tooling adds modest cost: vulnerability scanning, SIEM, or GRC platforms. A small team can start with GitLab CI, OS patching via Linux administration practices, and structured spreadsheets before buying enterprise GRC software.
Certification bodies must be accredited. Verify your auditor through the national accreditation body or the International Accreditation Forum listings. Cheap unaudited "certificates" from unknown bodies fail enterprise due diligence.
How Do You Maintain ISO 27001 Certification After the Audit?
Certification is a three-year cycle with annual surveillance audits. Treat the ISMS as operational infrastructure, not a one-time documentation project.
Schedule management reviews at least yearly. Review KPI trends, incident summaries, audit findings, and risk register changes. Update the SoA when you add new services—mobile apps, AI features, or a second data centre all trigger reassessment.
When building new features under certification scope, bake security into delivery. A enterprise application engagement should include threat modelling for document uploads, payment flows, and admin impersonation paths from day one.
Link maintenance work to controls: patching cadence, log review rotation, and quarterly access recertification. Our support and maintenance service model aligns with Clause 8 operational expectations when scope includes hosted applications.
For legal-tech and client portals—such as Notary Nepal or Court Marriage In Nepal—data minimisation and retention policies must match what the application actually stores. Auditors sample live records, not marketing copy.
Key Takeaways
- Define a narrow, testable certification scope before writing policies—vague boundaries fail Stage 2.
- Build a risk register and Statement of Applicability that link every Annex A control to live evidence.
- Engineering proof (MFA, logging, backups, change tickets) matters more than policy PDFs alone.
- Run a rigorous internal audit 4–8 weeks before Stage 2 to close major nonconformities early.
- Budget Rs 1.2–3.5 million all-in for many Nepal SMBs over 12 months, plus ongoing surveillance fees.
- Treat surveillance audits as continuous compliance—update the ISMS whenever architecture or vendors change.
People Also Ask
What is the difference between ISO 27001 and SOC 2?
ISO 27001 certifies your ISMS against an international standard through accredited auditors. SOC 2 is an attestation report (Type I or II) focused on Trust Services Criteria, common in US SaaS sales. Many product companies pursue both; ISO 27001 gives a portable certificate, while SOC 2 reports are customer-specific and periodic.
Can a startup get ISO 27001 certified with a small team?
Yes, if scope stays tight. Certifying a single SaaS product and its production stack is realistic for teams under 20 people. Exclude unrelated internal tools from scope with documented justification. Startups fail when they certify "everything" before basic access control and logging exist.
Do developers need ISO 27001 training?
Developers need role-based awareness training, not lead-auditor certification. They should understand secure coding expectations, incident reporting paths, and how their tickets become audit evidence. ISMS managers and internal auditors benefit from formal ISO 27001 lead implementer or lead auditor courses.
How does ISO 27001 relate to GDPR or Nepal data protection practice?
ISO 27001 does not replace privacy law. It provides a control framework that supports lawful processing: access control, encryption, breach procedures, and supplier management. Map ISO controls to legal obligations in your compliance register. Privacy policies and technical measures must align.
Build Your ISO 27001 Certification Roadmap With Engineering in the Loop
ISO 27001 certification is achievable for web product teams when the ISO 27001 Certification Roadmap treats security controls as production requirements—not a paperwork sprint before the auditor arrives. Scope tightly, close technical gaps early, and keep evidence where auditors look: logs, tickets, backups, and access reviews.
If you are planning certification for a Laravel platform, legal-tech portal, or eCommerce stack, align development, hosting, and ISMS ownership from the start. Review our custom software development approach, browse relevant portfolio projects, or read the DevOps career roadmap for overlapping operational skills. When you want hands-on help scoping technical controls, contact us to discuss your timeline and audit target.
Frequently Asked Questions
0 Comments
Leave a comment
Your email is not published. Comments appear once they have been read. Sign in to have your details filled in.

