Get Demo
↑

ISO 27701 Certification: Process, Cost Drivers and Timeline

ISO/IEC 27701 certification path for 2019 (ISMS-linked) and 2025 (standalone) — stages, cost drivers, and transition notes. No fabricated pricing.

Published: September 2026 Compliance · Privacy 8–12 min read

ISO 27701 certification is issued by an accredited certification body after Stage 1 and Stage 2 audits of your PIMS. Under 2019, programmes typically required an ISO 27001 ISMS foundation. Under ISO/IEC 27701:2025 (published 14 October 2025), PIMS certification does not require ISO 27001 as a prerequisite.

Related: 2025 changes · Checklist.

Correct the old headline: “Requires ISO 27001” applied to the typical 2019 path. For 2025, treat PIMS as standalone. Many organisations still keep ISO 27001 for security assurance—optional, not mandatory for 2025 PIMS certification.

Typical Process

  1. Scope PII processing and organisational boundaries
  2. Gap assessment vs Clauses 4–10 and applicable privacy controls
  3. Implement policies, inventory, rights, vendors, security measures
  4. Internal audit + management review
  5. Stage 1 (documentation) and Stage 2 (implementation) with an accredited CB
  6. Surveillance audits on the certificate cycle

Cost Drivers (Qualitative)

Budget drivers include scope size, number of processing locations, maturity of existing ISMS/privacy programme, multi-site sampling, consultant support, and CB day-rates. We do not publish fabricated price tables—request quotes from accredited CBs against a written scope.

Timeline

Ready organisations with an existing privacy programme may reach Stage 2 in a few months; greenfield programmes often take longer. Transition from 2019 certificates commonly follows CB guidance of roughly three years from the 2025 publication date (often cited through about October 2028).

How CyberSilo Helps

CSA prepares evidence packs; CyberSilo does not issue ISO certificates or act as your CB.

Prepare Before You Book the CB

Close inventory, rights, and security evidence gaps before Stage 1.

Frequently Asked Questions

Does 2025 certification require ISO 27001?

No. The 2025 edition is standalone. Confirm your CB’s accreditation scope for ISO/IEC 27701:2025.

How much does ISO 27701 cost?

It varies by scope and CB. Treat cost as quote-driven; avoid relying on anonymous price lists.

Can software certify us?

No. Software organises evidence. An accredited CB issues the certificate.

Explained · ISO 27001 hub · CSA Privacy

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!