Home » ISO Certification and Accreditation » Certification Process
At Ampcus Cyber India Private Limited, we are committed to providing independent, objective, and credible certification services that align with the principles of impartiality, competence, and transparency. Our certification process has been developed in accordance with the requirements of ISO/IEC 17021-1, ISO/IEC 27001, and ANAB accreditation criteria, ensuring that every certification decision is based on verified evidence and independent review. Ampcus Cyber functions as an accredited Certification Body (CB), offering ISO/IEC 27001 certification services to organizations seeking to demonstrate their commitment to information security management excellence. Our certification framework follows a structured, systematic, and impartial approach from application to certification maintenance.
The certification process begins with a formal application from the client organization. This application defines the scope of certification, including applicable sites, processes, and services. Upon receipt, Ampcus Cyber conducts an Application Review to:
Following review, a Certification Agreement is executed, clearly outlining the audit scope, confidentiality obligations, impartiality commitments, timelines, and fees. This ensures full transparency and understanding between the client and Ampcus Cyber prior to the commencement of certification activities.
The Stage 1 Audit is conducted to assess the organization’s preparedness for certification and to evaluate the implementation of its management system documentation. Key objectives include:
A detailed Stage 1 Audit Report is prepared and shared with the client, summarizing readiness status, areas requiring improvement, and recommendations for proceeding to Stage 2. This phase ensures that the client has established the necessary framework to support a successful certification audit.
The Stage 2 Audit is the primary evaluation phase, conducted on-site to verify that the management system is effectively implemented and operational. During this stage, Ampcus Cyber auditors:
Audit findings are classified as:
At the conclusion, a Closing Meeting is conducted to review all findings, clarify observations, and outline corrective action timelines. The audit report, including all findings and conclusions, is provided to the client for review and response.
Following the audit, the client organization must address identified nonconformities by submitting a Corrective Action Plan (CAP) within the agreed timeframe (typically 30 days). The CAP must outline:
Ampcus Cyber reviews and verifies the adequacy and effectiveness of corrective actions, which may include document reviews, remote verification, or follow-up on-site visits. Only after all major nonconformities are satisfactorily resolved does the process proceed to certification decision-making.
All certification decisions are made by Ampcus Cyber’s authorized Certification Decision Makers (CDM), who operates independently from the audit team to ensure impartiality. The CDM reviews:
Based on this review, the CDM determines the applicable certification decision outcome in accordance with the certification process.
Ampcus Cyber conducts annual surveillance audits to ensure the continued effectiveness of the certified management system. These audits focus on:
Surveillance audits maintain client accountability and reinforce the ongoing performance of certified systems.
Every three years, Ampcus Cyber conducts a Recertification Audit to confirm that the client’s management system remains effective and aligned with current standards and business requirements. This audit covers the entire scope of certification and ensures that the ISMS continues to support organizational objectives and regulatory compliance. Successful completion results in renewal of certification for another three-year cycle.
Impartiality and independence are core principles of Ampcus Cyber’s certification philosophy. We ensure that:
All client information, documents, and records are treated as confidential, accessible only to authorized personnel or regulatory authorities such as ANAB upon request. This ensures that the integrity and trust of our certification services are upheld at all times.
Ampcus Cyber maintains detailed records for all certification activities to ensure transparency, traceability, and accountability. Records include:
All records are securely stored in our controlled repository for a minimum period of seven (7) years, in compliance with ANAB and ISO requirements. Access is strictly limited to authorized personnel to maintain data integrity and confidentiality.
Ampcus Cyber continuously enhances its certification processes through:
These measures ensure that our certification services remain reliable, consistent, and aligned with international best practices.
Ampcus Cyber is dedicated to maintaining the highest standards of professionalism and integrity in all certification activities. Our structured, impartial, and transparent certification process ensures that clients receive credible and internationally recognized certification outcomes. By choosing Ampcus Cyber, organizations demonstrate their commitment to information security, regulatory compliance, and continual improvement - strengthening trust among customers, regulators, and business partners.
This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.
Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.
This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.
Keeping this cookie enabled helps us to improve our website.
This website uses the following additional cookies:
(List the cookies that you are using on the website here.)
More information about our Cookie Policy