ISO 27001 & ISMS

Praxis-Q Achieves ISO 9001:2015 and ISO/IEC 27001:2022 Certification

We just became ISO 9001:2015 and ISO/IEC 27001:2022 certified ourselves, audited by QRO and accredited by EGAC under the IAF Multilateral Recognition Arrangement.

S
Sahil Dubey
September 1, 2026
3 min read
45 views
Praxis-Q Achieves ISO 9001:2015 and ISO/IEC 27001:2022 Certification

Praxis-Q Achieves ISO 9001:2015 and ISO/IEC 27001:2022 Certification

We hold our clients to ISO 9001 and ISO/IEC 27001 every day. As of 1 September 2026, Praxis-Q holds them too. PraxisQ Consulting LLP has been independently audited and certified to both ISO 9001:2015 (Quality Management System) and ISO/IEC 27001:2022 (Information Security Management System), covering the same information security, cybersecurity and regulatory compliance services we deliver to clients — ISMS consulting and implementation, VAPT, cyber assurance, risk assessment and management, compliance and readiness audits, security assessments, security awareness training, and managed compliance services, delivered from Mohali, Punjab, India.

The certificates

  • ISO 9001:2015 — Quality Management System. Certificate No. 305026090131Q. View certificate.
  • ISO/IEC 27001:2022 — Information Security Management System. Certificate No. 305026090132IS. View certificate.

Both certificates were issued on 1 September 2026, run through 31 August 2029, and carry annual surveillance audits (the first due 31 August 2027, the second 31 August 2028) — the same ongoing-compliance rhythm we build into every client engagement, not a one-time badge.

Who certified us, and who stands behind them

The audit and certification were performed by QRO (Quality Research Organization / QRO Certification LLP), operating under accreditation from EGAC (the Egyptian Accreditation Council), a national accreditation body recognized as a management-systems signatory (ISO/IEC 17021-1) to the IAF Multilateral Recognition Arrangement — the framework that lets a certificate issued in one country be recognized worldwide. In practice, that means our QMS and ISMS were assessed against the same internationally-recognized bar we help our own clients clear.

Why we bothered to certify ourselves

Most compliance firms ask clients to document controls, train staff, manage risk and submit to independent audit — without doing the same to themselves. We didn't think that was good enough. Getting audited by an accredited, IAF-recognized body means an outside party independently verified our own information security management system and quality management system, not just our sales pitch.

Concretely, this certification now sits alongside our existing CERT-In empanelment for RBI SAR, MeitY and SEBI-mandated audits — one more layer of independently-verified assurance for clients in banking, fintech, SaaS and regulated industries who need to know their auditor's own house is in order.

What this means for clients

  • Documented, audited quality management (ISO 9001:2015) across how we scope, deliver and review every engagement — the same consistency clients rely on when picking an audit partner for a fixed timeline.
  • An independently certified ISMS (ISO/IEC 27001:2022) protecting the client data, evidence and audit artifacts that pass through our own systems during an engagement.
  • A verifiable chain of trust: QRO → EGAC → IAF, the same accreditation model that underpins every ISO certificate we help clients obtain.

If you're evaluating a compliance or cybersecurity partner for your own ISO 27001 certification, ask your shortlist the question we just answered for ourselves: who audits the auditor? Contact Praxis-Q to talk through your certification timeline — from an assessor now certified to the same standards we deliver.

Free Consultation

Ready to Get Compliant?

ISO 27001, PCI DSS, HIPAA, SOC 2 & more — fast-track in a few weeks.

Book Free Audit →

Tags

pillar:iso-27001ISO 9001ISO 27001ISO/IEC 27001:2022QROEGACIAFcertificationcompany news

Share this article

S

Sahil Dubey

Compliance & Security Expert

Praxis-Q’s compliance and offensive-security practitioners deliver ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR and DPDP engagements for banks, payment gateways and regulated fintechs.

Related compliance and security services