CC··
IP
TZ
ISO 27001 ISMS shield with the CIA triad (Confidentiality, Integrity, Availability) and the four Annex A 2022 control families
Updated 12 June 2026Reading time 18 minRegion Mauritius

Standard

ISO/IEC 27001:2022

Information Security Management System

Annex A controls

93

37 org · 8 people · 14 phys · 34 tech

Typical timeline

6–14 months

depends on scope & maturity

Certificate validity

3 years

annual surveillance audits

01What ISO 27001 is — and why it matters in Mauritius

ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS). It provides a structured, risk-based approach to protecting the confidentiality, integrity and availability of information — whether held electronically, on paper, or in the heads of your team.

In Mauritius, ISO 27001 has moved from "nice to have" to a near-prerequisite for organisations serving regulated European clients. Three forces are driving demand:

  • NIS2 supply-chain pressure. European procurers under NIS2 must secure their ICT supply chain. A Mauritian provider that holds ISO 27001 already meets a large share of these expectations.
  • DORA third-party requirements. Financial entities subject to DORA must scrutinise the resilience of their ICT third-party providers — including Mauritian fintechs, BPOs and global business clients.
  • Local financial regulation. The Financial Services Commission and Bank of Mauritius reference international information-security best practice in their supervisory expectations.

02Defining your scope correctly

Scoping is the single most important decision you will make. Too narrow and the certificate carries little commercial weight; too wide and you turn a 12-month programme into 24 months of pain.

A workable scope statement names:

  • The legal entity (Trivanta Ltd, registered in Mauritius)
  • The services or product lines covered (e.g. "the Nectra Suite SaaS platform and its supporting consulting services")
  • The locations involved (e.g. "Moka office and AWS af-south-1 region")
  • Exclusions and the justification for excluding them

Auditors will challenge any scope statement that excludes critical assets without a clear reason. Get this written down on paper and reviewed before you start drafting policies.

03Annex A controls (2022 revision)

The 2022 revision of ISO/IEC 27001 restructured Annex A into four control themes:

  • Organisational controls (37) — policies, roles, threat intelligence, supplier relationships
  • People controls (8) — screening, terms of employment, awareness, disciplinary process
  • Physical controls (14) — secure areas, equipment, working in secure areas, clear desk
  • Technological controls (34) — access, cryptography, system security, network security, application security

Each control needs a documented owner, evidence of implementation, and a review cadence. A Statement of Applicability records which controls apply, which do not, and why.

04Certification stages and timeline

A first-time ISO 27001 programme in Mauritius typically runs across four phases:

  • Months 1–2 — Gap assessment. Compare current state against the standard. Output: prioritised remediation plan.
  • Months 2–6 — Implementation. Build the ISMS: policies, risk register, controls, evidence, training.
  • Months 6–8 — Internal audit & management review. Prove the ISMS works in practice. Fix what you find.
  • Months 8–10 — Stage 1 & Stage 2 external audit. Conducted by an accredited certification body. The certificate is valid for 3 years with annual surveillance.

Smaller organisations with focused scope can compress this to 6 months. Larger multi-site programmes with complex regulatory overlay typically run 12–14 months.

05Costs in the Mauritius market

Costs depend on scope, headcount, number of sites and the maturity of existing security practice. As a rough Mauritius benchmark:

  • Consulting (implementation): Rs 500k – Rs 2.5M for SME scope; Rs 2.5M – Rs 8M for larger enterprises.
  • Certification body fees: Rs 150k – Rs 400k per cycle (Stage 1 + Stage 2 + annual surveillance).
  • Internal effort: typically a 0.5 FTE for 6–10 months during implementation; 0.1–0.2 FTE for ongoing operation.
  • Tooling: some organisations use a GRC platform such as NectraCORE to manage controls, evidence and audits.

06How ISO 27001 maps onto Mauritian regulation

An ISO 27001-certified Mauritian organisation already covers a large share of:

  • Mauritius Data Protection Act 2017 — technical and organisational measures (s.31), security of processing, breach detection.
  • FSC / Bank of Mauritius cyber expectations — IT governance, third-party oversight, incident reporting, business continuity.
  • FATF / FIAMLA — secure handling of beneficial-ownership data, CDD records and STR/SAR confidentiality.
  • NIS2 / DORA (EU-facing) — supply-chain security expectations for Mauritian providers serving European clients.

07How Trivanta supports ISO 27001 in Mauritius

We run ISO 27001 programmes end-to-end for Mauritian organisations: gap assessment, ISMS design, policy and control implementation, internal audit, Stage 1 / Stage 2 preparation, and ongoing surveillance support. We also deliver ANAB-accredited Lead Implementer and Lead Auditor training for in-house teams who want to run the programme themselves.

A complimentary scoping call is the easiest place to start. We listen first, then propose.

resources.consultation --book
Want a concrete plan for your context? Book a working session with our Mauritius consultants.