Empanelment & Routes
ISO 27001 for Government AI Deals: Worth It?
· 11 minute read
Buy ISO 27001 when tenders score it, buyers demand it, or your own chaos is expensive. Do not buy it as a fake air-gap. The certificate is an ISMS, not a topology.
A power PSU tender in Vadodara gave eight technical marks to a live ISO/IEC 27001 certificate whose scope included the service being bid. The uncertified startup had the better isolation story and lost by six marks. They spent the next two quarters arguing that ISO is a Western ritual. Their air-gap was real. The matrix did not have a row called 'real air-gap'. It had a row called 'ISO 27001'. They had chosen not to read the matrix when they chose not to certify.
ISO/IEC 27001 is the international standard for an information security management system. A certification body audits your ISMS and issues a certificate with a scope and an expiry. Government RFEs in India love to score it because it is a third-party object they can photocopy. That is not foolish. It is a proxy. Proxies can be gamed. They can also be the difference between a shortlist and a story.
This is a decision guide. Sometimes the certificate is worth the money and the six months. Sometimes it is theatre that delays the product. It is never a substitute for DPDP processor terms, for a residency map, or for a packet capture that shows no outbound. Prcept will hold whatever evidence a tender fairly scores. We will not pretend the certificate is the architecture.
Not legal advice and not a certification-body brochure. Scopes, transition to newer editions, and auditor quality vary. Read the RFE's exact wording — 27001, 27001:2013, 27001:2022, 'or equivalent', 'from a NABCB-accredited body'.
What the certificate is
It says that, for the scoped activities and locations, you run a management system: risks are assessed, controls are chosen, people are told, incidents have a place to go, and a third party checked. It does not say that a particular department's prompts never leave India. It does not say you do not train on customer data. It does not say the SDC VLAN has no default route.
Scope is the whole game. A certificate that covers 'corporate email and HR' will not satisfy a tender that asked for the software-development and support scope. A group certificate that does not name the bidding legal entity will bounce. A certificate that expired last month is a disqualifier, not a 'in progress' story, unless the RFE is unusually kind.
The Statement of Applicability is the adult document. If you excluded the controls that would have caught a vendor telemetry SDK, you have an ISMS that chose not to see. Auditors vary in how hard they push. Buyers almost never read the SoA. You should.
| Claim someone will make | What 27001 can support | What you still need |
|---|---|---|
| We are secure | A managed system and an external audit | Architecture review, pcap, identity design |
| We are DPDP ready | Some overlapping controls (access, incident, supplier) | Roles, purpose, notice, processor contract, deletion |
| Data stays in India | Only if you wrote residency into the ISMS and the contract | A topology and a legal transfer decision |
| Air-gapped | Only if the scoped controls actually forbid the hops | Deny-outbound, media SOP, licence design |
| We do not train on customer data | A control and a supplier clause if you wrote them | Product default, contract, and engineering proof |
When it is worth it
It is worth it when the tenders you will bid in the next 18 months score it, require it as PQ, or treat it as a tie-breaker. Pull five RFEs you actually missed or plan to chase. If three of them give material marks or a gate, the certificate is a cost of goods, not a lifestyle brand.
It is worth it when a single large buyer — a PSU, a bank-like regulator, a central agency — has said, in writing, that they will not issue a work order without it. One such letter can pay for the audit.
It is worth it when your own house is on fire: everyone is admin, laptops are folklore, vendors have standing VPN, and you are about to hold citizen data. The certificate is a forcing function. You could write the ISMS without certifying. Most twelve-person firms will not, unless an auditor is coming.
It is less worth it when you sell only a tightly air-gapped appliance to two campuses who will do their own assurance, and no RFE you can name will score the paper this year. In that world, spend the same money on the media protocol, the eval harness, and a second engineer. Revisit in twelve months.
- Do not certify to impress Twitter.
- Do not certify a shell entity you do not bid through.
- Do not let a consultant write an ISMS nobody lives. Auditors are not all asleep, and employees will tell the truth in interviews.
- Do not pause product isolation work for six months 'because ISO is the priority'. Parallelise, or you will have a certificate on a leaky runtime.
How to buy it without being captured
Pick a scope that matches the bidding entity and the service: design, build, deploy, support of the agent platform, named locations, named cloud or on-prem. If you are air-gap-first, put the media and jump-host process in the ISMS so the auditor sees the thing you sell.
Pick a certification body that government buyers will recognise. Many RFEs say NABCB-accredited or equivalent. A mysterious foreign mark on a PDF can attract a clarification you do not want during PQ.
Budget time, not only fees. A first-time twelve-person firm is often in a two-to-three-audit-cycle year: internal, stage 1, stage 2. Someone must own it who is not also the only bid manager and the only on-prem engineer. If that someone does not exist, you are not ready, or you must hire.
Write the no-training-on-customer-data and no-silent-subprocessor rules as ISMS policies. Then they are auditable. Then they also show up in tenders as more than a slogan.
How buyers should score it — and what else to score
If you score ISO, score the scope sentence, not the logo. A certificate that does not cover the service is zero. A lapsed certificate is zero.
Give equal or greater marks to evidence ISO cannot replace: residency map, outbound schedule, training clause, CERT-In logging, processor list. Otherwise you will shortlist tidy firms that phone home.
Do not make ISO a PQ gate if you want DPIIT startups to bid, unless you are willing to shrink the set. Gates are allowed. Be honest that you chose a smaller market.
Objections you will hear — and what to do with them
These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.
ISO is enough; we can skip the air-gap annexure.
No. Plenty of certified SaaS firms have default routes to global telemetry. Ask for both.
Startups should get a waiver.
Some RFEs waive via DPIIT. Many do not. Lobby the RFE if you must. Do not invent a waiver in the cover letter.
We will put 'ISO in progress' and take half marks.
Only if the matrix says so. Most give zero for in progress. Booking an auditor is not a certificate.
SOC 2 is more modern.
Indian government matrices still print 27001 more often. If you already have SOC 2, keep it for private banks and still read the RFE. Dual stacking is a cost decision.
A 30-day decide, then a six-month do
Decide with a spreadsheet of RFEs, not with a consultant's fear deck.
- Week 1: collect five to ten target RFEs. Note whether 27001 is PQ, scored, or absent. Note the edition and accreditation language.
- Week 2: estimate fees, internal time, and who would own the ISMS. If that person is fictional, the project is fictional.
- Week 3: decide go / wait 12 months / go only if a named buyer letter arrives.
- If go: set scope to the bidding entity and the product; write no-training and supplier controls on day one; book a body buyers will recognise; do not stop isolation engineering.
How this shows up in the file
Internal decision note: 'We [will / will not] pursue ISO/IEC 27001 in FY[ ]. Reason: [marks / buyer letter / internal chaos / not this year]. Scope if yes: [entity, locations, services]. What ISO will not replace: DPDP map, residency, pcap, no-training clause. Owner: … Target stage-2: …'
Buyer note: 'ISO 27001 marks require a live certificate whose scope covers the offered service and the bidding legal entity. Separate marks apply to residency, outbound, and training-on-customer-data. A logo without a scope sentence scores zero.'
What the next noting must contain
“ISO 27001 for Government AI Deals: Worth It?” belongs in a file, not only in a search result. A P5 Startup/Vendor should be able to point at one artefact that proves “ISO 27001 government tender”: a packet capture, a processing schedule, a scored evaluation row, a dated notice, or a refusal rule. If the only evidence is a slide, you have a heading.
Buy ISO 27001 when tenders score it, buyers demand it, or your own chaos is expensive. Do not buy it as a fake air-gap. The certificate is an ISMS, not a topology. DPDP 2023 does not define sovereign AI and does not write a blanket localisation rule for every model hop. CERT-In’s 28 April 2022 directions still set specified incident clocks and 180-day log retention in India for in-scope events. The November 2025 AI governance text is guidance, not a statute. A Proprietary Article Certificate, when it is lawful, lives in GFR Rule 166 — not Rule 161.
Write three dated sentences under C4 Empanelment & Routes: what was decided, which designation owns it after the next posting order, and when it will be re-checked. Unsigned sentences are souvenirs. Dated sentences are controls.
- Name the designation that owns “ISO 27001 government tender”, plus a deputy.
- Attach one artefact a stranger can open next year.
- Name the instrument you are actually using — Act, direction, GFR clause, GeM term, or guideline paragraph.
- Leave unsourced percentages, GMV slides and house forecasts out of the noting.
- Revisit when the model, the SI, the notice, the region or the posting changes.
This article is informational field guidance for Indian public institutions and their vendors, not legal, tax, procurement or engineering advice. Confirm the live circular, RFE, GCC, GeM term, state G.O. and your counsel before you file anything. Incentives, ceilings and portal screens change.
Questions this usually raises
- Does ISO 27001 make us DPDP compliant?
- No. It can support security and supplier controls. DPDP is a statute about personal data, roles, purpose and rights. Map both.
- Will ISO 27001 get us through a state empanelment?
- Only if that RFE scores or requires it. Many do. Some do not. It will not replace turnover, EMD, or experience if those are gates.
- How long does certification take?
- For a small firm with a real owner, think in months, not weeks. Anyone promising a certificate in a fortnight without a system is selling paper.
- Is ISO 27001 mandatory for government AI?
- Not as a national law for all AI. It is mandatory where the bid says so. Treat the bid as the law of that buy.
- Should we wait for the latest edition transition?
- Ask the certification body and read the RFE's edition language. Do not use transition uncertainty as a reason to do nothing if the market already scores you at zero.