Praxis-Q Achieves ISO 9001:2015 and ISO/IEC 27001:2022 Certification
We hold our clients to ISO 9001 and ISO/IEC 27001 every day. As of 1 September 2026, Praxis-Q holds them too. PraxisQ Consulting LLP has been independently audited and certified to both ISO 9001:2015 (Quality Management System) and ISO/IEC 27001:2022 (Information Security Management System), covering the same information security, cybersecurity and regulatory compliance services we deliver to clients — ISMS consulting and implementation, VAPT, cyber assurance, risk assessment and management, compliance and readiness audits, security assessments, security awareness training, and managed compliance services, delivered from Mohali, Punjab, India.
The certificates
- ISO 9001:2015 — Quality Management System. Certificate No. 305026090131Q. View certificate.
- ISO/IEC 27001:2022 — Information Security Management System. Certificate No. 305026090132IS. View certificate.
Both certificates were issued on 1 September 2026, run through 31 August 2029, and carry annual surveillance audits (the first due 31 August 2027, the second 31 August 2028) — the same ongoing-compliance rhythm we build into every client engagement, not a one-time badge.
Who certified us, and who stands behind them
The audit and certification were performed by QRO (Quality Research Organization / QRO Certification LLP), operating under accreditation from EGAC (the Egyptian Accreditation Council), a national accreditation body recognized as a management-systems signatory (ISO/IEC 17021-1) to the IAF Multilateral Recognition Arrangement — the framework that lets a certificate issued in one country be recognized worldwide. In practice, that means our QMS and ISMS were assessed against the same internationally-recognized bar we help our own clients clear.
Why we bothered to certify ourselves
Most compliance firms ask clients to document controls, train staff, manage risk and submit to independent audit — without doing the same to themselves. We didn't think that was good enough. Getting audited by an accredited, IAF-recognized body means an outside party independently verified our own information security management system and quality management system, not just our sales pitch.
Concretely, this certification now sits alongside our existing CERT-In empanelment for RBI SAR, MeitY and SEBI-mandated audits — one more layer of independently-verified assurance for clients in banking, fintech, SaaS and regulated industries who need to know their auditor's own house is in order.
What this means for clients
- Documented, audited quality management (ISO 9001:2015) across how we scope, deliver and review every engagement — the same consistency clients rely on when picking an audit partner for a fixed timeline.
- An independently certified ISMS (ISO/IEC 27001:2022) protecting the client data, evidence and audit artifacts that pass through our own systems during an engagement.
- A verifiable chain of trust: QRO → EGAC → IAF, the same accreditation model that underpins every ISO certificate we help clients obtain.
If you're evaluating a compliance or cybersecurity partner for your own ISO 27001 certification, ask your shortlist the question we just answered for ourselves: who audits the auditor? Contact Praxis-Q to talk through your certification timeline — from an assessor now certified to the same standards we deliver.
Free Consultation
Ready to Get Compliant?
ISO 27001, PCI DSS, HIPAA, SOC 2 & more — fast-track in a few weeks.
Tags
Share this article
Sahil Dubey
Compliance & Security Expert
Praxis-Q’s compliance and offensive-security practitioners deliver ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR and DPDP engagements for banks, payment gateways and regulated fintechs.
