ISO/IEC 27701 Certification

Verify Certificates

Any CCI certificate, online

120+ Certificates

Issued since 2014

250+ Organizations

Served by our group since 1997

Remote & On-site

Audits per IAF MD 4

ISO/IEC 27701 Certification

ISO/IEC 27701 extends ISO/IEC 27001 with requirements for a Privacy Information Management System (PIMS) — additional controls for managing personally identifiable information (PII) as a Data Controller and/or Processor. It gives organizations a structured way to demonstrate privacy governance and supports (without itself guaranteeing) compliance with regulations such as the EU GDPR. Company Certification International (CCI) certifies PIMS implementations, with every certificate verifiable online.

Who needs ISO 27701 certification?

  • Organizations already certified (or certifying) to ISO 27001 that process significant volumes of personal data
  • SaaS and technology providers acting as a Data Processor for enterprise customers
  • Healthcare, financial services and HR/recruitment organizations handling sensitive personal data
  • Any organization wanting independently verified evidence of privacy governance for customers or regulators

Certification requirements

ISO 27701 certification requires a certified (or concurrently certifying) ISO 27001 ISMS as its base, extended with PIMS-specific controls covering your role as Data Controller and/or Processor, privacy risk assessment, and documented privacy processes. Your organization — or a consultant of your choosing — designs and operates the PIMS; CCI's role is the independent assessment.

How certification works

Stage 1 audit

A documentation and readiness review of your PIMS extension alongside your ISO 27001 ISMS.

Stage 2 audit

An audit of the PIMS in operation, on-site, remote, or blended.

Certification decision

A decision maker independent of the audit team decides whether to certify, in line with ISO/IEC 17021-1.

Annual surveillance and the three-year cycle

ISO 27701 surveillance is normally aligned to your ISO 27001 certification cycle — annual surveillance audits, with a full recertification audit every three years.

Our ISO 27701 services

Our experts deliver ISO 27701 audits through on-site and remote sessions, or a blend of both, per IAF MD 4 guidance — we'll work around the needs of your organization.

What affects your quotation

Audit duration and fees depend on your employee count, number of sites, and the scope of personal data processing in your PIMS — see certification cost and audit duration or request a quote using the form on this page, noting you're certifying alongside ISO 27001.

Accreditation route

See our accreditation and recognition page for CCI's current scheme-specific accreditation status for ISO 27701, and for how our IAR and MRA-recognized (partner) certification routes compare.

SOC 2, ISO 27001, ISO 27701 & GDPR Comparison

Understand the differences between leading security and privacy frameworks.

Feature SOC 2 ISO 27001 ISO 27701 GDPR
Developed by AICPA (American Institute of Certified Public Accountants) ISO (International Organization for Standardization) ISO (International Organization for Standardization) European Union (EU)
Focus Security, availability, processing integrity, confidentiality, and privacy of customer data Information Security Management System (ISMS) Privacy Information Management System (PIMS) Personal data protection and privacy rights
Applicability Primarily for SaaS, cloud, and technology service providers Any organization handling sensitive information Organizations managing personal data (PII) Any organization handling EU residents' personal data
Framework Trust Services Criteria (TSC) ISO 27001 Annex A controls (aligned with ISO 27002) Extension of ISO 27001 with privacy-specific controls Legal framework defining rights, obligations, and penalties
Certification Type No formal certification, only an attestation report by an independent auditor Formal certification (3-year cycle with audits) Formal certification (must have ISO 27001 first) No official certification, but organizations must demonstrate compliance
Assessment Type Type I: Point-in-time audit; Type II: Continuous assessment over time Certification with surveillance audits Certification with periodic audits (linked to ISO 27001) Self-assessment & regulatory audits by data protection authorities
Legal & Compliance Alignment Helps meet HIPAA, GDPR, CCPA, but does not guarantee compliance Aligns with NIST, GDPR, SOC 2, and other security frameworks Supports GDPR, CCPA, LGPD, and other privacy laws Legally binding in the EU, applies to businesses worldwide handling EU personal data
Audit Frequency Typically annual or per client request 3-year certification cycle with annual surveillance audits Linked to ISO 27001 audit cycle No mandatory audits, but data protection authorities can enforce compliance
Key Deliverable SOC 2 Report (Type I or Type II) ISO 27001 Certification ISO 27701 Certification Compliance documentation & evidence for regulators
Data Protection & Rights Focuses on security but does not define specific privacy rights Focuses on confidentiality, integrity, and availability of information Defines privacy-specific roles (Data Controller, Processor) and compliance requirements Grants individuals rights (access, rectification, erasure, portability, etc.)
Enforcement & Penalties No legal penalties; failing SOC 2 can lead to loss of business No direct penalties, but losing certification can impact business No direct legal penalties, but non-compliance impacts ISO 27701 certification Fines up to €20 million or 4% of global annual turnover for violations
Geographical Influence Primarily North America (U.S.) Global (ISO standards apply worldwide) Global (Designed to align with GDPR & privacy laws) EU and global businesses handling EU citizens' data

Why certify with Company Certification International

CCI's role is independent certification: application review, Stage 1 and Stage 2 audits, an independent certification decision, and ongoing surveillance. CCI does not provide management-system consultancy, documentation drafting or implementation support. Engaging ISOXPERT Management & IT Consultants — an independent consulting and technology firm under common ownership with CCI — any other consultant, or no consultant has no bearing on any certification decision.

Frequently asked questions

Do we need ISO 27001 before we can certify ISO 27701? Yes — ISO 27701 extends an ISO 27001 ISMS; the two are typically certified together or ISO 27701 added to an existing ISO 27001 certificate.

How long does ISO 27701 certification take? Typically 6–8 weeks from application to certification decision where combined with an ISO 27001 audit, subject to readiness.

How much does it cost? See certification cost and audit duration or request a fixed quote using the form on this page.

Does ISO 27701 certification guarantee GDPR compliance? No — it demonstrates a structured privacy management approach that supports GDPR compliance efforts, but GDPR compliance itself is a legal determination, not something a certificate can guarantee.

Can we transfer an existing ISO 27701 certificate to CCI? Yes — see transfer of ISO certification.

Get Certified

Free consultation & quotation

Standard(s) Required — tick one, or several for an IMS

We respond within 24 hours

Ready to get ISO/IEC 27701 Certification?

Talk to our team for a scoping discussion and a clear certification quotation — or verify an existing CCI certificate.

ISO/IEC 27701 Certification | Company Certification International