HomeBlogGovernance and ComplianceISO 27001 Certification and ISO 27001:2022 Transition Case Study for a Global Manufacturing Company
ISO 27001 Certification and ISO 27001:2022 Transition Case Study for a Global Manufacturing Company

Executive Summary
A globally recognised manufacturing company in the electrical and electronic sector. Worked with Kalp Systems to implement a structured Information Security Management System (ISMS) and achieve ISO 27001:2013 certification across its Indian operations.
Following successful certification, the organisation worked with Kalp Systems again to lead a smooth and audit-ready transition to ISO 27001:2022 while maintaining operational continuity.
This case study outlines how ISO 27001 certification and the subsequent 2022 transition were implemented across engineering, research and development, manufacturing, and supply chain functions without disrupting business operations.
About the Client
Client: Intelligent Automation Company (Name Withheld for Confidentiality)
Industry: Electrical and Electronic Manufacturing
Employees: 930
Annual Revenue: USD 176.4 Million
Locations in Scope: Gujarat, India, 2 manufacturing sites
Engagement Duration: 2019 to Ongoing
The client operates in more than 60 countries and is recognised as a global leader in energy-efficient air cooling solutions. As a publicly listed enterprise, the organisation required a mature, auditable, and internationally recognised information security framework aligned with its global reputation and regulatory expectations.
Business Context
As the organisation expanded globally, information assets such as product designs, engineering documentation, vendor data, and cloud-hosted systems became increasingly distributed and complex.
Senior leadership identified the need for a formal Information Security Management System to:
- Protect intellectual property and R&D assets
- Strengthen governance across multiple business units
- Improve risk visibility across manufacturing and supply chain environments
- Demonstrate compliance maturity to global partners and stakeholders
- Align with international information security standards
ISO 27001 certification was selected as the strategic framework to achieve these objectives.
Key Challenges
Implementing ISO 27001 certification in a manufacturing environment presented several operational and governance challenges:
- Establishing a structured ISMS across engineering, R&D, operations, procurement, and supply chain functions
- Managing sensitive data distributed across on-premises infrastructure, vendor systems, and cloud platforms
- Protecting intellectual property embedded within product lifecycle processes
- Integrating information security controls without slowing production workflows
- Ensuring the scalability of security practices aligned with global expansion
- Transitioning to ISO 27001:2022 requirements while maintaining certification continuity
Implementation Strategy by Kalp Systems
Kalp Systems delivered a structured, phased engagement focused on sustainable implementation rather than documentation-driven compliance.
The approach was executed in two major phases.
Phase 1: ISO 27001:2013 Certification
Enterprise-Wide Risk Assessment
Kalp Systems conducted a comprehensive risk assessment covering:
- Engineering and design environments
- Manufacturing systems
- Vendor and third-party integrations
- Cloud services
- Corporate IT infrastructure
Information assets were identified, classified, and evaluated for risks to confidentiality, integrity, and availability.
Gap Analysis Against ISO 27001:2013
A detailed gap analysis was conducted to assess the organisation’s existing controls against the requirements of ISO 27001:2013.
This created a structured remediation roadmap aligned with business priorities.
ISMS Framework Design and Documentation
Kalp Systems designed and implemented a pragmatic Information Security Management System that included:
- Information Security Policy
- Risk Assessment and Risk Treatment Methodology
- Statement of Applicability, SoA
- Standard Operating Procedures
- Access control policies
- Vendor risk management processes
- Incident management framework
- Training and awareness programmes
The focus was on building operationally aligned controls that supported manufacturing efficiency.
Internal Audit and Certification Support
Kalp Systems:
- Conducted internal audits
- Facilitated management review meetings
- Prepared audit evidence documentation
- Coordinated with the certification body
Outcome:
The organisation successfully achieved ISO 27001:2013 certification across both manufacturing sites with no major non-conformities.
Phase 2: Transition to ISO 27001:2022
With the release of ISO 27001:2022, the client required structured alignment with the updated Annex A control framework while maintaining certification validity.
Delta Assessment
Kalp Systems performed a detailed delta assessment to:
- Map existing 2013 controls to the 2022 control structure
- Identify newly introduced and enhanced controls
- Assess impact across technical and business processes
Implementation of Updated Controls
Key focus areas during the transition included:
- Threat intelligence integration
- Secure coding and secure development practices
- Cloud services governance and monitoring
- Information deletion and data handling lifecycle controls
- Enhanced supplier and third-party risk oversight
Documentation and SoA Update
The Statement of Applicability was revised to reflect the new control framework.
Risk treatment plans, policies, and supporting procedures were updated in line with ISO 27001:2022 requirements.
Audit Coordination and Business Continuity
Kalp Systems managed the transition timeline in coordination with the certification body, ensuring:
- No disruption to manufacturing operations
- Controlled implementation timelines
- Continuous compliance posture
The transition process remains structured and aligned with audit readiness objectives.
Business Impact and Outcomes
The engagement delivered measurable governance and operational improvements:
- Successful ISO 27001:2013 certification with zero major audit findings
- Seamless and structured transition to ISO 27001:2022
- Improved protection of intellectual property and R and D data
- Integrated security controls within manufacturing and product lifecycle processes
- Strengthened vendor and third-party risk governance
- Enhanced management visibility into information security risks
- Scalable ISMS aligned with global expansion
Information security became embedded within operational decision-making rather than functioning as an isolated compliance initiative.
Conclusion
This case study demonstrates how ISO 27001 certification and ISO 27001:2022 transition can be effectively implemented within a complex global manufacturing environment.
Through structured risk management, practical control implementation, and strong audit coordination, the organisation strengthened its information security posture while maintaining operational efficiency and global credibility.
Kalp Systems continues to support the client in sustaining and enhancing its Information Security Management System in alignment with evolving business and regulatory requirements.