Photo: Unsplash
Learning how to get ISO 27701 certified starts with understanding that certification evaluates an operating privacy information management system (PIMS), not a collection of documents. Your team must define scope, implement controls, produce evidence, audit itself, correct weaknesses, and demonstrate effectiveness to an independent certification body.
This guide covers:
- The sequence from gap analysis through certification
- Owners, deliverables, and evidence at every step
- What happens during Stage 1 and Stage 2 audits
- Realistic timeline factors and audit preparation
- How to maintain certification through surveillance

GIF via GIPHY
Key takeaways
- Certification depends on your ISO 27001 foundation. ISO 27701 extends an ISMS, so align scopes, shared processes, and audit cycles early.
- A gap analysis must produce an executable plan. Every gap needs risk, priority, owner, due date, dependency, and expected evidence.
- Operating history is essential. Auditors typically sample actual assessments, requests, reviews, training, incidents, metrics, and corrective actions.
- Stage 1 and Stage 2 answer different questions. Stage 1 evaluates design and readiness; Stage 2 evaluates implementation and effectiveness.
- Certification starts a cycle. Surveillance audits, management reviews, risk updates, and continual improvement continue after the initial decision.
Before you start
ISO/IEC 27701 is an extension to ISO/IEC 27001 and related security control guidance. If you already operate a certified ISO 27001 ISMS, you may be able to reuse governance, document control, risk, supplier, incident, training, internal audit, management review, and corrective-action processes.
If you do not yet have an ISMS, plan an integrated implementation. Trying to build a standalone PIMS without the management system foundation can create gaps in leadership, risk treatment, competence, performance evaluation, and improvement.
Read The ultimate ISO 27001 guide and ISO 27001 vs ISO 27701: what’s the difference? before fixing scope or audit dates.
Set a project charter that identifies:
- Executive sponsor and PIMS lead
- Business reason and expected outcome
- Proposed products, entities, systems, and locations
- ISO 27001 certification status and scope
- Budget for implementation, internal audit, and certification
- Target audit window and major dependencies
Do not market a target date as guaranteed. Certification timing depends on implementation quality, auditor availability, findings, and certification-body review.
Step 1. Define scope and leadership
The PIMS lead should run scoping workshops with privacy or legal, security, product, engineering, HR, procurement, support, and operations. Document:
- In-scope services, processes, legal entities, locations, teams, and systems
- Categories of individuals and PII
- Data flows, vendors, subprocessors, and international locations
- Controller and processor roles by processing purpose
- Interfaces with out-of-scope activities
- Relevant legal, contractual, customer, and internal requirements
Top management should approve the scope, privacy policy, responsibilities, objectives, resources, and risk acceptance authority. A narrow scope may reduce initial effort, but it must remain credible and cannot omit dependencies that are necessary to deliver the scoped service.
Deliverables: approved scope statement, context and interested-party register, role matrix, privacy objectives, project plan, and governance calendar.
Evidence owners: the PIMS lead maintains governance records; process and system owners validate boundaries and data flows; leadership records approvals and resource decisions.
Step 2. Run a gap analysis
Assess each applicable ISO 27701 requirement and privacy control against current design and operation. Interviews alone are insufficient—request evidence and sample it.
For each requirement, classify the state:
- Implemented and effective: documented, operating, and supported by representative records.
- Partially implemented: some teams, systems, or records do not follow the process.
- Designed but not operating: documentation exists, but evidence is not yet available.
- Not implemented: no reliable process or control exists.
- Not applicable: exclusion is supported by scope, role, risk, and rationale.
Convert findings into a remediation register. Include requirement, issue, risk, action, owner, reviewer, due date, dependency, and evidence expected at closure. Prioritize foundational items such as PII inventory, controller/processor mapping, risk methodology, product intake, rights requests, retention, suppliers, and incidents.
A workshop commonly takes one to three weeks for a modest scope, but remediation may take months. Use The ISO 27701 compliance checklist to make sure the review reaches operating workflows.
Step 3. Implement the PIMS
Build the management system and privacy controls as integrated workflows.
Establish PIMS documentation
Create or revise:
- PIMS scope, privacy policy, objectives, and governance procedure
- PII inventory and data-flow method
- Privacy risk and impact-assessment method
- Controller and processor applicability mapping
- Privacy by design and change-review procedure
- Individual rights, retention, supplier, incident, and complaint procedures
- Training, monitoring, internal audit, management review, and corrective-action procedures
Documentation should specify who performs each step, what triggers it, required inputs, approvals, service targets, escalation, and retained records.
Implement technical and organizational controls
Legal and privacy interpret obligations, but operational teams execute controls. Engineering may implement deletion and access restrictions; product may maintain purpose and feature decisions; support may coordinate rights requests; procurement may enforce vendor gates; and security may manage access, incidents, and technical safeguards.
Use a control matrix to connect each requirement to:
- Applicability and rationale
- Process and control owner
- Implementing system or workflow
- Policy and procedure
- Evidence examples
- Test method and frequency
- Related risks and requirements
Avoid manufacturing duplicate privacy processes where an ISMS process can be extended. For example, add privacy impact and notification fields to incident management rather than creating an isolated incident queue with unclear handoffs.
Step 4. Operate controls and collect evidence
Auditors need evidence from the period before the audit. Run workflows through normal business activity and retain complete records.
Common operating samples include:
- New product or feature privacy assessments
- Approved PII inventory updates
- Privacy risk treatment and acceptance
- Completed rights requests and response approvals
- Retention configuration, deletion jobs, or exception tickets
- Processor due diligence and contract reviews
- Subprocessor change records
- Privacy incident triage or tabletop exercise
- Training completion and role-based competence
- Metrics, complaints, exceptions, and improvement actions
The PIMS lead should hold weekly evidence reviews during implementation. Ask: Is the record complete? Does it match procedure? Is the owner identifiable? Are dates and approvals clear? Does it cover the defined scope?
There is no universal minimum operating period stated as a simple number for every organization. Certification bodies commonly expect enough representative evidence to evaluate effectiveness. Discuss sampling expectations early, then choose the audit date based on process maturity rather than calendar pressure.
Step 5. Complete internal audit and management review
An internal audit is required to evaluate conformity and effectiveness before certification. The auditor must be competent and sufficiently independent of the work being audited. Smaller organizations may use a qualified external internal auditor to avoid self-review.
The audit plan should cover:
- PIMS and ISMS clauses within scope
- Applicable controller and processor controls
- Representative teams, systems, and processing activities
- Previous issues and high-risk areas
- Document review, interviews, and record samples
Report nonconformities with objective evidence and criteria. Control owners should analyze root cause, define correction and corrective action, set dates, and provide closure evidence. The internal auditor or designated reviewer verifies effectiveness.
Management review should then consider changes in context, interested-party requirements, objectives, risk, audit outcomes, incidents, complaints, supplier performance, resources, and improvement opportunities. Retain minutes showing decisions and assigned actions.
Do not schedule Stage 1 merely because internal audit occurred. Confirm findings have been evaluated and material readiness gaps are closed or under credible control.
Step 6. Select a certification body
Compare certification bodies based on relevant accreditation, ISO 27701 capability, sector knowledge, geographic coverage, scheduling, audit approach, and total cycle cost. Verify claims directly with the body and applicable accreditation sources.
Provide accurate scope, headcount, sites, processing complexity, ISMS status, outsourced activities, and desired audit dates. These factors may influence audit duration and team competence.
| Selection factor | Question to ask | Why it matters |
|---|---|---|
| Scope fit | Can you certify our combined ISMS/PIMS boundaries? | Prevents certificate or audit-plan surprises |
| Auditor competence | What privacy and sector experience will the team have? | Supports relevant, efficient sampling |
| Audit sequence | Can ISO 27001 and ISO 27701 audits be integrated? | May reduce duplicated interviews and evidence |
| Availability | What dates are realistic for Stage 1, Stage 2, and review? | Protects launch and buyer commitments |
| Findings process | How are corrective actions reviewed and timed? | Affects certification decision timing |
Independence matters: the certification body cannot design and then certify your management system as if it were your implementation consultant.
Step 7. Complete the Stage 1 audit
Stage 1 focuses on documented design, scope, context, readiness, and planning for Stage 2. The auditor commonly reviews:
- Scope and integration with ISO 27001
- PIMS documentation and applicability mapping
- Privacy risk assessment and treatment
- PII inventory and role determination
- Internal audit and management review
- Sites, teams, systems, and processing complexity
- Readiness and availability of Stage 2 evidence
Assign one audit coordinator and a backup. Prepare an evidence index, stakeholder schedule, secure sharing method, and scope briefing. Owners should answer from actual practice and retrieve records rather than overstate maturity.
Stage 1 may identify areas of concern or nonconformities that must be addressed before Stage 2. Log each issue, clarify expected closure evidence, assign an owner, and preserve root-cause analysis and approval.
Step 8. Complete the Stage 2 audit
Stage 2 evaluates whether the PIMS is implemented and effective. Auditors interview leadership and control owners, trace workflows, and sample records across the certification scope.
Expect tests such as:
- Select a processing activity from the inventory and trace its data flow, role, risk, notice, suppliers, retention, and controls.
- Select a privacy assessment and verify that mitigations reached product or engineering work.
- Select a supplier and review diligence, contract, approval, monitoring, and offboarding.
- Select a rights request or incident and compare timestamps and decisions with procedure.
- Trace objectives and metrics into management review and improvement decisions.
Keep a live request log with request, owner, due time, status, link, and auditor response. Quality-check files for scope, completeness, and unintended unrelated information before sharing.
If findings arise, correct the specific issue and analyze why the system allowed it. Corrective action may require process, ownership, training, tooling, or oversight changes. Certification is granted only after the certification body's process is complete; the audit closing meeting is not necessarily the final decision.
Step 9. Maintain certification
After certification, continue the PIMS cycle:
- Monitor objectives, control performance, requests, incidents, and complaints
- Review PII inventories and risks after change and on schedule
- Conduct planned internal audits and management reviews
- Track changes in products, vendors, processing roles, and requirements
- Resolve nonconformities and verify corrective-action effectiveness
- Prepare for surveillance and eventual recertification audits
Assign each audit-cycle commitment to an owner and due date. Quarterly evidence health checks can identify stale policies, overdue assessments, broken links, untested deletion, or personnel changes before surveillance.
Certification scope and status must be represented accurately in marketing and sales. Train customer-facing teams to share the certificate, scope, and limitations consistently.
ISO 27701 certification timeline
| Maturity profile | Typical planning range | Main schedule risk |
|---|---|---|
| Mature certified ISMS and established privacy workflows | Commonly several months | Aligning scope and producing privacy-specific samples |
| Mature ISMS but informal privacy operation | Commonly 4–8 months | Inventory, ownership, and workflow evidence |
| Building ISMS and PIMS together | Commonly 6–12+ months | Shared management-system and technical remediation |
| Complex, multi-entity or global scope | May exceed 12 months | Data mapping, jurisdictional variation, and audit logistics |
These are planning ranges, not guarantees. Team availability, technical changes, certification-body scheduling, and finding closure can materially change timing.
Build milestones backward from Stage 2: allow time after Stage 1 for remediation, before Stage 1 for internal audit and management review, and before those activities for representative operation.
Build your evidence package
Organize evidence by process and requirement, not as an unstructured folder dump. Maintain:
- A master index with owner, period, scope, and access.
- Foundational documents: scope, policy, objectives, roles, risk method, and control mapping.
- Operating samples: inventory, assessments, requests, suppliers, retention, incidents, and training.
- Assurance records: metrics, internal audit, management review, findings, and corrective actions.
- Audit administration: agendas, stakeholder list, request log, and approved sharing location.
Run mock walkthroughs with process owners. Each owner should explain the trigger, inputs, decisions, handoffs, records, exceptions, metric, and recent improvement. The goal is not scripted answers—it is consistent understanding of a process that genuinely operates.
Streamline ISO 27701 certification with SecureSlate
SecureSlate helps teams keep certification work assigned, current, and audit-ready.
- Map ISO 27701 requirements to controls, owners, and evidence
- Track gap remediation, privacy risks, and corrective actions
- Centralize policies, assessments, records, and audit requests
- Monitor readiness through certification and surveillance cycles
Get started for free: Create your SecureSlate account
FAQ: ISO 27701 certification
Can ISO 27701 be certified without ISO 27001?
ISO 27701 is designed as an extension to ISO 27001. Certification is commonly integrated with an ISO 27001-certified ISMS. Confirm your circumstances and scope with an accredited certification body.
What is the difference between Stage 1 and Stage 2?
Stage 1 reviews system design, documentation, scope, and readiness. Stage 2 samples implementation and operating effectiveness across the scope.
How much evidence do auditors need?
There is no single universal count. Auditors choose samples based on scope, risk, volume, locations, and audit objectives. Maintain representative records across processes and time periods.
What happens if an auditor finds a nonconformity?
You typically must correct the issue, analyze root cause, implement corrective action, and submit evidence within the certification body's required timeline. Severity may affect the certification decision.
Does certification guarantee legal compliance?
No. It provides independent assurance over the scoped PIMS. Legal obligations require separate, jurisdiction-specific analysis.
Disclaimer (legal note)
SecureSlate is not a law firm, and this article does not constitute or contain legal advice or create an attorney-client relationship. When determining your obligations and compliance with respect to relevant laws and regulations, you should consult a licensed attorney.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds
