Univate Solutions is a management consulting firm working in governance, risk and compliance, quality, business process re-engineering, service management, information security and business continuity. This page sets out the service families we run from our India practice, names the standard or framework behind each one and links to its detail page. For the standards that apply to a particular sector, see our industries page.
Cybersecurity and information security
ISO/IEC 27001 is the certifiable standard for an information security management system. Annex A of the 2022 edition lists 93 controls in four themes: organisational, people, physical and technological. A certificate from an accredited certification body is valid three years and is maintained through annual surveillance audits. SOC 2 works differently: it is not a certificate but an attestation report prepared by a licensed CPA firm under AICPA attestation standards. PCI DSS is published by the PCI Security Standards Council and applies wherever cardholder data is stored, processed or transmitted.
- ISO/IEC 27001 certification for an information security management system
- SOC 2 attestation against the AICPA Trust Services Criteria
- PCI DSS compliance for cardholder data environments
- Vulnerability assessment and penetration testing
- NIST Cybersecurity Framework gap assessment and implementation
- CISO as a service for organisations without an in-house security lead
The full list, including ISO/IEC 27017 for cloud services and CSA STAR, sits on the cybersecurity services hub.
Data privacy and regulatory compliance
India’s Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) received presidential assent on 11 August 2023 and establishes the Data Protection Board of India. It sits alongside the obligations Indian organisations already carry abroad. The EU General Data Protection Regulation, Regulation (EU) 2016/679, reaches an Indian company that offers goods or services to people in the European Union or monitors their behaviour there. HIPAA is United States federal law and carries no government certification scheme, so compliance is demonstrated by assessment against its Privacy and Security Rules rather than by a certificate.
- DPDP Act compliance readiness and implementation
- GDPR compliance for organisations processing EU personal data
- ISO/IEC 27701 certification for a privacy information management system
- HIPAA compliance assessment for business associates of US covered entities
- Data classification and statutory and regulatory compliance
See the data privacy and compliance hub for the complete set.
CMMI appraisal and process maturity
CMMI is administered by ISACA. A maturity level is awarded through a Benchmark Appraisal led by a Certified Lead Appraiser, the rating is valid for three years, and it is published in ISACA’s Published Appraisal Results System (PARS). CMMI has no Stage 1 or Stage 2 audit and no surveillance audit, because those belong to accredited ISO certification, not to appraisal. Univate Solutions is a CMMI Institute partner and runs appraisals with an in-house Lead Appraiser.
- CMMI for Development (CMMI-DEV)
- CMMI for Services (CMMI-SVC)
- CMMI Benchmark Appraisal
- CMMI Level 5 high maturity training
Ratings we have delivered are recorded in our case studies, and the practice overview is on the CMMI appraisal hub.
IT service management and governance
ISO/IEC 20000-1 is the certifiable service management system standard, so it is the one an IT or managed services organisation can hold a certificate against. ITIL 4 is a body of practice and its certifications are awarded to individuals rather than to organisations. COBIT is published by ISACA as a governance framework for enterprise information and technology, and it is used to define control objectives rather than to certify.
These are covered on the IT service management hub.
Quality, safety and environment certification
These standards share the harmonised structure that ISO applies across management system standards, which is why an organisation can run them as one integrated management system and have them audited together rather than separately. Each certificate follows the same three year cycle with annual surveillance.
- ISO 9001 for quality management systems
- ISO 14001 for environmental management systems
- ISO 45001 for occupational health and safety management systems
- ISO 22301 for business continuity management systems
- ISO 55001 for asset management systems
- ISO 22000 and HACCP for food safety
The quality, safety and environment hub lists the rest.
Assessments, training and advisory
Alongside certification work we run assessments and capability building that do not end in a certificate.
- Trainings for internal auditors, lead auditors and process teams
- SIRI assessment for manufacturing digital maturity
- AI audits for organisations deploying artificial intelligence systems
- TISAX assessment for suppliers to the automotive industry
How a certification engagement runs
- Gap assessment against the clauses and controls of the chosen standard.
- Documentation and process implementation, with the scope statement agreed up front.
- Internal audit and management review, both of which the standard requires before external audit.
- Stage 1 audit by the certification body, which reviews readiness and documentation.
- Stage 2 audit, which tests implementation and effectiveness, followed by the certification decision.
Appraisal engagements follow a different route, because a CMMI Benchmark Appraisal replaces the two stage audit with an evidence review and appraisal conducted by the Lead Appraiser.
Frequently asked questions
Which of these services end in a certificate?
The ISO management system standards do: an accredited certification body issues the certificate. CMMI ends in a maturity level rating published in ISACA’s PARS, not a certificate. SOC 2 ends in an attestation report signed by a CPA firm. HIPAA and the Digital Personal Data Protection Act, 2023 have no certification scheme at all, so those engagements end in an assessment and a remediation plan.
How long does an ISO certificate remain valid?
Three years. The certification body carries out surveillance audits each year within that cycle, and a recertification audit before the certificate expires.
Can several standards be certified in one audit?
Yes. ISO management system standards use a common harmonised structure, so ISO 9001, ISO 14001, ISO 45001 and ISO/IEC 27001 can be built as a single integrated management system and audited in one combined visit, which reduces duplicated documentation and audit days.
Does Univate conduct the CMMI appraisal itself?
Yes. Univate Solutions is a CMMI Institute partner and the Benchmark Appraisal is led by our in-house Certified Lead Appraiser, so gap assessment, process implementation and appraisal are handled by the same team.






