A customer's security team sends over a vendor questionnaire, and one line asks whether you hold ISO 27701. You have ISO 27001. You've never heard the second number before, and the two are close enough that it's tempting to assume it's a typo.
It isn't. ISO 27701 is a privacy extension to ISO 27001, adding requirements for a Privacy Information Management System, or PIMS, on top of the information security management system ISO 27001 already covers. It tells a customer, an auditor, or a regulator that you manage personal data with the same rigor you already apply to information security.
That answers what ISO 27701 is at the surface level. The harder part, and the reason most guides on this topic run long, is what it actually asks an organization to do, and how much of that overlaps with work you've probably already done for ISO 27001.
By the end of this, you'll know what ISO 27701 actually requires, how the certification path changed in 2025, what it realistically costs (and why every vendor quotes a different number), and whether ComplyJet supports it alongside ISO 27001.
Here's what's ahead:
- What ISO 27701 is, and how it's different from ISO 27001, ISO 27017, and ISO 27018
- The 2025 update that removed the old ISO 27001-first requirement
- Why it matters for a SaaS business closing enterprise deals
- The clauses, annexes, and controls that make up the standard
- Two different certification paths, depending on where you're starting from
- What certification actually costs, and why the estimates vary so much
- Common mistakes companies make pursuing it
- Which platforms actually support both ISO 27701 and ISO 27001
What Is ISO 27701?
ISO/IEC 27701 is a Privacy Information Management System standard. It extends ISO 27001's Information Security Management System with a specific set of requirements for handling Personally Identifiable Information, or PII.
That single sentence covers the mechanics, but not the intent. ISO 27001 tells you how to protect information in general: confidentiality, integrity, availability. ISO 27701 asks a narrower question on top of that foundation: are you handling personal data responsibly, in a way that holds up against privacy law, not just general security practice?
It applies whether your company is a PII controller (you decide how and why personal data gets used) or a PII processor (you handle data on someone else's behalf, the way most B2B SaaS vendors do). The standard has a dedicated annex for each role, which matters more than it sounds like it should. Most of the requirements a controller needs to satisfy don't apply the same way to a processor, and vice versa.
Laid out visually, the relationship between the two standards and the two annexes looks like this:
Who Actually Needs ISO 27701
If your company already holds (or is pursuing) ISO 27001 and handles personal data as part of delivering your product, this is worth a real look. That covers most SaaS companies with any EU or California customer base, any company processing employee or customer data at scale, and specifically, anyone who's started fielding privacy-specific questions in security reviews rather than the general security ones ISO 27001 alone already answers.
The controller-versus-processor split gets its own full breakdown later in this guide. For now, the short version: figure out which role you're actually playing before you plan the rest of the certification path, since it changes what you need to demonstrate.
There's a version of this decision that's easy to get wrong early: assuming that because ISO 27001 already covers "security," a customer's privacy-specific ask is already answered. It usually isn't.
A security questionnaire that asks about encryption and access control is a different question than one asking how long you retain personal data after a customer offboards, or how you'd respond to a data subject access request. ISO 27701 exists specifically to give a documented, auditable answer to the second kind of question.
ISO/IEC 27701:2025: The Standalone Certification Update
For years, the practical reality of ISO 27701 was that you needed ISO 27001 certification first. The 2025 revision changed that. ISO 27701 can now be certified on its own, without an existing ISO 27001 certificate as a prerequisite.
That's a real shift, not a technicality. Several vendor guides covering this topic still write as if ISO 27001 certification is a hard gate before ISO 27701 is even on the table. It isn't anymore. An organization that wants privacy certification specifically, without taking on the full scope of a general information security management system, now has a path to get there.
For most SaaS companies, pairing the two still makes practical sense. The standards share a structure, and a lot of the evidence you'd collect for one directly supports the other. But the update removes a real blocker for organizations that want privacy certification faster, or that don't need (or want) the broader ISMS scope ISO 27001 requires.
Side by side, the before-and-after is a simple swap:
One thing worth flagging plainly: the exact publication date of the 2025 revision varies by source, and we haven't independently verified a single authoritative date against ISO's own catalog. Confirm the specific version and date directly with ISO's official ISO/IEC 27701 listing before citing it in anything customer-facing.
What this practically changes for planning purposes: an organization evaluating ISO 27701 for the first time no longer has to treat "get ISO 27001 first" as step zero. It can evaluate the privacy standard on its own timeline, and decide whether pairing it with ISO 27001 still makes sense given its specific customer base.
For most SaaS companies selling into enterprise accounts, the answer will still be to pursue both. That's simply because the overlap in evidence makes doing them separately the more expensive path, not because the rule requires it anymore.
Why ISO 27701 Matters for a SaaS Business
Nobody pursues ISO 27701 out of curiosity. It shows up because a customer's procurement team asked for it, or because the SOC 2 report and the ISO 27001 certificate stopped being enough to close a deal that touches EU personal data.
Enterprise buyers increasingly separate "you secure information well" from "you handle my customers' personal data well," and ISO 27701 is one of the few standards built to answer the second question directly rather than as an afterthought bolted onto a general security framework.
That distinction shows up concretely in procurement cycles. A security team reviewing a vendor for a contract touching EU personal data will often ask a privacy-specific question that a SOC 2 report or an ISO 27001 certificate alone doesn't fully answer: how is data subject access handled, what happens to personal data after a contract ends, who besides you touches it.
ISO 27701 gives a documented, auditable answer to exactly that set of questions, which is why it increasingly shows up as its own line item rather than an assumed extra.
Founders treat ISO 27701 like a nice-to-have extension until the exact moment a deal stalls on it. By then it's a scramble instead of a plan, which is the same mistake we've watched happen with ISO 27001 and SOC 2 both. — Upendra Varma, CTO at ComplyJet
ISO 27701 GDPR Compliance: How the Two Work Together
ISO 27701 includes an annex that maps its own privacy controls directly to GDPR's requirements, which is exactly why it comes up so often in the same breath as GDPR compliance work.
It's worth being precise about what that mapping does and doesn't mean. ISO 27701 certification demonstrates that you run a management system for privacy, one that's auditable and consistent. It doesn't automatically mean full GDPR compliance on its own; GDPR has legal requirements (lawful basis for processing, breach notification timelines, data subject rights) that sit outside what any ISO standard certifies. Treat the certification as strong supporting evidence in a GDPR compliance program, not a replacement for one.
ISO 27701 GDPR alignment is exactly why auditors and legal teams treat the certification as meaningful evidence in a broader compliance program, rather than a checkbox exercise separate from it. If your GDPR program already has documented data flows and a lawful-basis assessment, a lot of that evidence directly supports the PIMS requirements covered later in this guide, instead of duplicating the work.
The reverse is also true, and worth knowing before assuming ISO 27701 alone closes out a GDPR conversation. A regulator or a customer's legal team asking about GDPR specifically wants to see the legal mechanics: a valid lawful basis, a data processing agreement with the right clauses, a real breach-notification timeline. ISO 27701 certification is strong supporting evidence that those mechanics are backed by an operating management system, not a substitute for having them in the first place.
ISO 27701 vs 27001: What Actually Changes
The two standards get confused constantly, mostly because of how close the numbers sit. The actual distinction is simple once it's laid out directly.
| ISO 27001 | ISO 27701 | |
|---|---|---|
| What it covers | Information security management (confidentiality, integrity, availability) | Privacy-specific management on top of ISO 27001's foundation |
| What you build | An Information Security Management System (ISMS) | A Privacy Information Management System (PIMS) |
| Who it targets | Any organization handling sensitive information | Organizations handling PII, as a controller or processor |
| Certification requirement | Standalone, no prerequisite | Standalone since the 2025 update; commonly still paired with ISO 27001 |
| Typical audience asking for it | General security reviews, most enterprise procurement | Privacy-specific reviews, GDPR-adjacent due diligence |
The ISO 27701 vs 27001 distinction really comes down to scope, not competition between the two. One covers information security broadly, across any kind of sensitive data. The other narrows in specifically on personal data, and asks a more targeted set of questions that general security controls don't fully cover on their own: consent handling, data subject rights, retention limits tied to purpose.
If you're weighing ISO 27701 against other framework choices entirely, ComplyJet's ISO 27001 vs. SOC 2 comparison is a useful next read for the broader "which framework actually fits my sales motion" question.
ISO 27701 Requirements: Clauses, Annexes, and Who's Covered
Strip away the marketing language most guides wrap around this, and ISO 27701's structure is genuinely simple. It has ten clauses. The first three are introductory. The remaining seven, Sections 4 through 10, are the actual auditable core.
The ISO 27701 requirements below follow the same Annex SL structure ISO 27001 already uses, which is deliberate. If your organization has already been through an ISO 27001 audit, this structure will look immediately familiar; the clause numbers and general shape carry straight over, with the privacy-specific content layered on top rather than replacing anything.
| Clause | Focus | What it actually asks for |
|---|---|---|
| 4. Context of the Organization | Scope | Define which parts of the business the PIMS covers, and how it relates to the existing ISMS |
| 5. Leadership | Ownership | Named responsibility for privacy management, not diffused across the team |
| 6. Planning | Risk | Objectives and a documented privacy risk assessment |
| 7. Support | Resources | The tools, training, and documentation the PIMS actually needs to function |
| 8. Operation | Execution | Ongoing privacy risk assessment and day-to-day operational controls |
| 9. Performance Evaluation | Monitoring | Regular review of whether the PIMS is actually working, not just documented |
| 10. Improvement | Iteration | A defined process for fixing what performance evaluation finds |
Layered on top of the clauses are six annexes, split cleanly by role: some apply to every organization, and two (Annex A and Annex B) apply specifically depending on whether you're a controller or a processor.
For a small SaaS team, Clauses 4 and 5 are usually the fastest to satisfy on paper and the easiest to under-invest in practically. Defining scope and naming an owner sounds administrative, but auditors treat both as substantive: a PIMS with no named accountable owner, or one whose scope quietly excludes a product line that actually touches personal data, is a real finding, not a formality to skip past.
ISO 27701 Controls: The Full Breakdown
Scope-wise, it helps to know roughly how big this actually is before committing to a timeline. Per Sprinto's own published breakdown of the standard, ISO 27701 totals 184 controls, with about 135 amending or extending existing ISO 27001 controls and the remaining 49 being entirely new, PII-specific guidance. Treat that split as directionally useful rather than an exact figure to cite elsewhere; it's one vendor's accounting of the standard, not a number pulled from ISO's own text.
Some competing guides group those controls into five practical categories: security management, incident management, information security controls, business continuity, and privacy risk management. That's a reasonable lens for organizing implementation work, not a structure ISO itself mandates.
Getting a real handle on ISO 27701 controls early, rather than discovering the scope mid-implementation, is what prevents the timeline surprises covered in the certification section below. Most of the surprise isn't in the security-adjacent controls, which usually already exist if ISO 27001 is in place. It's in the privacy-specific ones: documented data subject request handling, sub-processor tracking, and retention schedules tied to actual purpose rather than a blanket policy.
ISO 27701 Checklist: PII Controllers vs. PII Processors
This is the split that actually determines what your organization needs to do, and it's the part most generic guides gloss over. Use the ISO 27701 checklist below to figure out which annex actually applies to your organization before scoping any implementation work; building against the wrong one wastes real time without adding any audit value.
| PII Controllers (Annex A) | PII Processors (Annex B) | |
|---|---|---|
| Who this is | Organizations that decide how and why personal data gets used | Organizations handling personal data on someone else's behalf (most B2B SaaS vendors) |
| Core obligation | Establish a lawful basis, honor data subject rights, manage consent | Process data only per the controller's documented instructions |
| Documentation focus | Privacy notices, consent records, data subject request handling | Processing agreements, sub-processor management, data return/deletion procedures |
| Typical ComplyJet-ICP fit | Companies that own end-user relationships directly | B2B SaaS platforms processing customer data within a larger product |
Most early-stage SaaS companies land primarily in the processor role, since they're handling their customers' end-user data rather than owning that relationship directly. Confirm which one actually applies before scoping a PIMS; building against the wrong annex wastes real implementation time.
How to Get ISO 27701 Certified
So, what is ISO 27701 certification actually going to look like in practice, beyond the clause-by-clause summary above? The honest answer is that the certification path looks different depending on where an organization is starting from, and treating it as one uniform process is where a lot of planning goes wrong.
Starting From Scratch: Pursuing ISO 27001 and 27701 Together
For an organization with no existing ISMS, the realistic path runs through both standards at once, since most of the groundwork overlaps:
- Readiness and gap assessment against both ISO 27001 and the added PIMS requirements
- Build the management system, covering both information security and privacy controls together
- Internal audit to catch gaps before an external auditor does
- Stage 1 external audit, a documentation review
- Stage 2 external audit, the substantive review of whether the system actually operates as documented
- Certification, followed by ongoing surveillance audits to maintain it
This is deliberately a high-level view, not a granular week-by-week plan; the point here is understanding the shape of the process well enough to scope it, not a substitute for working with an auditor.
The part organizations most often underestimate isn't the audit stages themselves; it's step 2, building the management system. That's where the actual privacy-specific work lives: mapping what personal data you hold, documenting a lawful basis for processing it, and building the operational habits (like a working data subject request process) that an auditor will actually test rather than just read about.
Already ISO 27001-Certified? The Shorter Path to ISO 27701
If the ISMS already exists, most of the heavy lifting is done. What's left is a gap assessment against the specific PIMS requirements ISO 27701 adds, implementing whatever's missing, and a lighter-weight audit that extends the existing certification rather than starting a parallel process from zero.
Realistic timelines vary widely by vendor account, from several months to closer to a year depending on organizational readiness and how much of the privacy-specific work is genuinely new versus already covered by existing ISO 27001 evidence. Take any single fixed number with real skepticism; it depends heavily on your starting point, not a fixed formula.
In practice, the shorter path still requires someone to own it. A gap assessment against the PIMS-specific requirements only surfaces real gaps if someone actually walks through each clause against what the organization currently does, rather than assuming existing ISO 27001 evidence automatically covers the privacy-specific additions. It usually covers most of it. Not all of it.
A common pattern: an organization's existing ISMS already documents access control and incident response well, since ISO 27001 has been auditing those for years. What it usually doesn't already document is a working data subject request process, or a clear record of every sub-processor that touches personal data downstream. Those gaps are small in count but real in effort, and they're exactly what the shorter path still has to close before certification.
What Does ISO 27701 Certification Actually Cost?
Ask three different sources what ISO 27701 certification costs, and you'll get three different answers that don't agree with each other. That's worth naming directly instead of picking one number and presenting it as settled.
| Source | Cited range |
|---|---|
| Sprinto | $2,000–$5,000 |
| Scrut | $4,000–$30,000+ |
| ISMS.online | An 8-tier table by organization size, roughly £2,850–£14,250 (≈$3,600–$18,000) |
None of these figures cite an independent, audited source. All three are vendor estimates, and the spread between the low and high end is roughly sixfold. That's not a rounding difference.
It reflects how much certification cost genuinely depends on variables that don't reduce to one number: organization size, whether an ISMS already exists, whether the implementation uses an automation platform versus a fully manual or consultant-led process, and the certification body's own audit fees on top of internal implementation effort.
The one thing worth budgeting for regardless of the final number: certification-body audit fees are separate from implementation cost, and both scale with the size of the organization and the scope of personal data actually being processed day to day.
For a company already ISO 27001-certified, a more useful question than "what does ISO 27701 cost" is "what does the incremental gap cost," since a real share of the certification-body fee and internal effort was already spent getting the ISMS in place. Ask any quote to break out the incremental work specifically, rather than accepting a total figure that implies starting from zero.
Common Mistakes Companies Make Pursuing ISO 27701
Most of the mistakes below aren't exotic. They're the same handful of scoping and ownership errors showing up across nearly every organization pursuing this for the first time, regardless of size, and nearly all of them trace back to treating the privacy-specific work as an afterthought bolted onto an already-running ISO 27001 program.
- Treating it as a checkbox rather than an operational system. A PIMS that exists only in a binder doesn't survive a Stage 2 audit; auditors check whether the controls actually run day to day.
- Assuming ISO 27001 certification alone covers privacy expectations. It doesn't. General information security and privacy-specific management are different questions, which is the entire reason ISO 27701 exists as its own standard.
- Scoping the PIMS wider or narrower than the existing ISMS. The PIMS has to align with the ISMS scope, not exceed it or leave parts of it uncovered; systems outside the ISMS boundary can't simply be folded into the PIMS after the fact.
- Underestimating documentation requirements. Consistent, clear documentation of how personal data is handled isn't optional overhead; it's a core auditable requirement, not paperwork bolted on afterward.
- Not distinguishing controller obligations from processor obligations. Building against the wrong annex, or trying to cover both fully when only one actually applies, burns real implementation time for no audit benefit.
- Assuming the certification cost or timeline from someone else's guide applies directly. As the cost section above shows, vendor estimates vary by roughly sixfold; a number written for a different company's size and starting point isn't a reliable budget for yours.
- Waiting until a deal is actually blocked on it to start. ISO 27701, like ISO 27001 and SOC 2 before it, takes real months to stand up properly. Starting the gap assessment only after a customer's procurement team asks the question directly turns a plannable project into a scramble against a deal timeline you don't control.
Platforms Supporting ISO 27701 and ISO 27001
Platforms supporting ISO 27701 and ISO 27001 together are rarer than the marketing copy of most compliance-automation vendors suggests. Most of them write about ISO 27701 to promote their own support for it, without ever answering the more useful question directly: which platforms actually support both in one place, so the overlapping evidence between the two doesn't have to be managed twice.
That distinction matters operationally, not just as a buying checkbox. Managing ISO 27001 evidence in one tool and ISO 27701 evidence in a separate spreadsheet or process defeats a lot of the point of pairing the two standards in the first place, since so much of the underlying evidence genuinely overlaps.
If you're already evaluating platforms for ISO 27001 specifically, ComplyJet's ISO 27001 guide for startups covers that framework in more depth on its own.
FAQs
Is This the Same Thing as ISO 27001?
No. ISO 27701 is a privacy-specific extension built on top of ISO 27001's information security foundation. They're related and often pursued together, but they answer different questions: one covers information security broadly, the other covers personal data handling specifically.
Is Certification Mandatory?
No. It's not a legal or regulatory requirement anywhere. It's increasingly expected contractually in enterprise procurement and vendor security reviews, but there's no law that requires it the way GDPR itself is a legal requirement.
How Much Does ISO 27701 Certification Cost?
Estimates vary widely by vendor, roughly from $2,000 to $30,000 or more depending on organization size and starting point. See the cost section above for the full breakdown and why the numbers disagree so much.
How Long Does Certification Take?
It depends heavily on whether an ISO 27001 ISMS already exists. Vendor estimates range from several months to close to a year. Organizations already ISO 27001-certified generally move faster, since much of the groundwork is already in place. The single biggest variable within that range is how quickly the privacy-specific documentation (data subject request handling, retention schedules, sub-processor tracking) gets built, since that's rarely covered by existing ISO 27001 evidence.
What Changed in the 2025 Update?
ISO 27701 became certifiable as a standalone standard, removing the previous requirement to hold ISO 27001 certification first. Most SaaS companies still pair the two in practice, but the update removes what used to be a hard prerequisite.
Do I Need ISO 27001 First?
Not anymore, technically. Since the 2025 revision, ISO 27701 can be certified independently. In practice, most SaaS companies still pursue both together, since the standards share structure and a lot of the same evidence.
Which Platforms Support Both?
See the section above for the full answer. ComplyJet supports both ISO 27001 and ISO 27701 as part of its framework coverage.
How Does This Relate to GDPR?
ISO 27701 includes an annex mapping its privacy controls to GDPR's requirements, making it useful supporting evidence for a GDPR compliance program. It's not a substitute for GDPR compliance itself, since GDPR includes legal requirements that sit outside what any ISO certification covers.
What's the Difference Between a PII Controller and a PII Processor?
A controller decides how and why personal data gets used. A processor handles personal data on someone else's behalf, which describes most B2B SaaS vendors. ISO 27701 has a separate annex for each role, since the actual obligations differ meaningfully between the two. Getting this wrong early is one of the more common planning mistakes covered above, since it changes which documentation and controls actually apply.
Related Reading
- ISO 27001 vs. SOC 2: Which Framework Actually Fits, for readers weighing ISO 27701 against other framework choices, not just against ISO 27001 alone.
- ISO 27001 Certification Cost, a parallel cost breakdown for the parent standard.
- ISO 27001 Checklist, for readers pursuing ISO 27001 alongside ISO 27701.
- ISO 27001 for Startups, ICP-matched framing for the same audience this guide targets.
- Is SOC 2 a Certification? Attestation vs. Certification, Explained, the attestation-versus-certification distinction this guide's certification framing parallels.
- GDPR Compliance, for the GDPR relationship section's natural next read.


