ISO 27701
ISO 27701 implementation and internal audit, built to the 2025 standalone standard.
ISO/IEC 27701 is the international standard for a Privacy Information Management System (PIMS): the management system that organises how your company handles personal data. Since October 2025 it has been a standalone management system standard, so certification no longer requires ISO 27001 first, a change most of the market has not caught up with (ISO, iso.org standard 85819 and product-page FAQ, checked 14-08-2026).
Atoro delivers ISO 27701 implementation support and independent internal audits for software companies, and the outcome is a privacy management system ready for accredited certification.
Built for software companies implementing the 2025 edition
ISO 27701 implementation
Independent internal audit
Standalone 2025 edition
Certification-ready PIMS
ISO 27701, current edition
27701
PIMS
Standalone since October 2025Certification no longer requires ISO 27001 first (iso.org, checked 14-08-2026).
Implementation supportGap analysis through to a PIMS that is actually operating.
Independent internal auditRun by Atoro practitioners who were not involved in your build.
Certification stays separateThe certification audit is performed by an accredited certification body, not by Atoro.
No 2019 assumptionsBuilt to ISO/IEC 27701:2025, not the withdrawn extension model.
Still quoting the withdrawn edition
As of 14-08-2026, these pages still describe the 2019 extension model.
- Amtivo Ireland: “Prior certification to ISO/IEC 27001 is necessary” (amtivo.com/ie).
- Hicomply: “Yes. ISO 27701 cannot be implemented standalone” (hicomply.com).
- Bastion: “You cannot achieve ISO 27701 certification without an underlying ISO 27001 certification” (bastion.tech).
- Quality Veritas sells “ISO/IEC 27701:2024”, an edition that does not exist (qvcert.co.uk).
The first three are true of the withdrawn 2019 edition and false of the current one. The only editions are 2019 and 2025 (editions confirmed at iso.org, checked 14-08-2026).
02 Recognition
ISO/IEC 27701:2025 is a standalone standard, and most of the market has not caught up
ISO published ISO/IEC 27701:2025 (Edition 2) in October 2025, and its foreword states the document “has been redrafted as a stand-alone management system standard” (ISO Online Browsing Platform record for standard 85819, checked 14-08-2026). The 2019 edition, whose full title described it as an extension to ISO/IEC 27001 and ISO/IEC 27002, is withdrawn (ISO, iso.org standard 71670, status withdrawn, checked 14-08-2026).
ISO’s own product page answers the question buyers actually ask. Can the standard be implemented independently of ISO/IEC 27001? “Yes, as it is an independent management system standard (MSS).” (iso.org, ISO/IEC 27701 product page FAQ, checked 14-08-2026.) ISO’s package page puts the buyer story in one sentence: “The 2025 edition is now a standalone standard that enables organizations with less complex frameworks to implement and certify privacy controls independently of ISO 27001” (iso.org, PUB200277, checked 14-08-2026). Integration with ISO 27001 remains supported and is presented by ISO as the aligned path for organisations that already run an ISMS.
Most of what ranks for “iso 27701” has not absorbed this. If a proposal you are reading assumes the extension model, ask which edition it is quoting.
03 Proof
Why Atoro
Atoro is an Irish AI governance and cyber compliance consultancy for software companies, and the first consultancy in Europe certified against ISO 42001 (certificate AIMS-AT-120224, issued by A-LIGN under ANAB accreditation). Atoro’s own site states more than 200 certifications delivered (atoro.io, checked 08-08-2026).
Two things to be plain about. First, Atoro delivers ISO 27701 implementation and internal audit; Atoro does not itself hold ISO 27701 certification, and this page does not claim otherwise. Second, the certification decision always sits with an accredited certification body, not with us.
What you get from Atoro is a PIMS built to the current edition by practitioners who work in management system standards every day, and an internal audit honest enough to find your gaps before the certification body does.
Certified. Independent. Current.
First in Europe for ISO 42001Certificate AIMS-AT-120224, issued by A-LIGN under ANAB accreditation.
More than 200 certifications deliveredAtoro’s own site, checked 08-08-2026.
Atoro does not itself hold ISO 27701 certificationWe deliver the implementation and the internal audit. The certificate is not ours to claim.
Not a certification bodyThe certification audit is run by an accredited body working to ISO/IEC 27706:2025.
Built to the 2025 editionNo carry-over assumptions from the withdrawn 2019 extension model.
04 System
When software companies need ISO 27701
You need ISO 27701 when your company processes personal data and needs a managed, auditable system for doing it, not just policies on a shared drive. ISO’s own definition of who the standard serves: “personally identifiable information (PII) controllers and processors, who hold responsibility and accountability for processing PII” (iso.org, “What is ISO/IEC 27701?”, checked 14-08-2026).
The triggers we see, in buyers’ own words:
You are a controller, a processor, and usually both.
A software company is typically the PII controller for its employee and client contract data and the PII processor for the customer data flowing through its product. One implementer at a software company put it exactly: “Please note that I act as a PII Controller for employee data and client contract data. I also act as a PII Processor for my solution, which is hosted on a cloud infrastructure.” (r/cybersecurity thread, language source only, checked 14-08-2026.) Role determination decides which requirements apply to you, so it is where an engagement starts.
You run ISO 27001 and privacy work keeps outgrowing it.
The phrasing recurs: “We are being told to model our PIMS after the 27001 ISMS. So does that mean i have the same policies but from a privacy perspective?” (r/privacy thread, language source only, checked 14-08-2026.) The ISMS gives you the management system machinery; the PIMS adds the PII-specific roles, controls and records. Where an ISMS exists, ISO presents alignment with it as the streamlined implementation path (iso.org product page listed benefit, checked 14-08-2026).
You hold a 2019 certificate.
Certification bodies state that certificates against ISO/IEC 27701:2019 must transition by end of October 2028: Brand Compliance gives “1 October 2028” as the end of the transition period (brandcompliance.com, checked 14-08-2026); Schellman, citing ANAB Heads Up #550, gives 31 October 2028 for organisations to transition formally (schellman.com, checked 14-08-2026); ISMS.online states the same three-year transition and notes that a lapsed holder “would need to certify against the 2025 edition as a new certification rather than a transition, which may require a full Stage 1 and Stage 2 audit” (isms.online, checked 14-08-2026). Treat this as certification-body consensus, not an ISO or IAF statement: no IAF mandatory transition document specific to ISO/IEC 27701:2025 was located on iaf.nu in our research (checked 14-08-2026). If you hold a 2019 certificate, your certification body’s own transition letter is the document that binds you.
You need to show GDPR accountability in a structured way.
ISO’s framing, and the only framing we will use: ISO/IEC 27701 “helps demonstrate compliance with global privacy regulations such as GDPR” (iso.org product page listed benefit, checked 14-08-2026). It is not GDPR compliance in itself, and it is not certification under GDPR Article 42; ISO claims neither anywhere on its own pages (iso.org, checked 14-08-2026).
05 Plan
How delivery works
The work runs in phases, with named Atoro practitioners doing the delivery and your team providing the access.
1
Scope and gap analysis
We define which products, teams and data sets the PIMS will cover, and score current practice against the 2025 requirements. You provide an internal owner and access to the people who handle personal data.
2
Role determination and design
We settle controller versus processor responsibilities per data set and design the PIMS around them, aligned to your ISMS where one exists.
3
Build and operate
Policies, controls and records go live and start generating evidence. This phase sets the timeline, and it is your team’s calendar, not ours, that paces it.
4
Independent internal audit and management review
Atoro auditors independent of the build run the internal audit; your top management sits the management review.
5
Certification audit
The accredited certification body runs Stage 1 and Stage 2. We manage the booking, prepare your team, and sit in the room.
Honest note on duration: we found no published, verifiable timeline figures for ISO/IEC 27701:2025 engagements. Vendor-published figures that exist describe the withdrawn 2019 extension model and are marketing claims, not facts: UK platform Hicomply suggests 3 to 6 months to extend an existing ISO 27001 (hicomply.com, checked 14-08-2026, describes the 2019 model), and an India-market consultancy claims 4 to 12 weeks on the same basis (pricoris.com, checked 14-08-2026, tier 2 marketing claim).
We scope duration per engagement rather than quoting figures we cannot stand over.
06 Included
What the engagement covers
Atoro delivers two things for ISO 27701: implementation support that takes you from gap analysis to an operating PIMS, and an independent internal audit ahead of certification. The certification audit itself is performed by an accredited certification body working to ISO/IEC 27706:2025 under ISO/IEC 17021-1; Atoro is a consultancy, not a certification body, and the two roles stay separate (ISO, ISO/IEC 27706:2025 standard page, “specifies the requirements for bodies that audit and certify Privacy Information Management Systems (PIMS) based on ISO/IEC 27701”, checked 14-08-2026).
Included
Gap analysis against the 2025 requirements
The standard “sets out requirements for establishing, implementing, maintaining, and continually improving a Privacy Information Management System (PIMS)” (iso.org, “What is ISO/IEC 27701?”, checked 14-08-2026). We score your current privacy practice against those requirements and separate “we do this” from “we do this and can show it”.
Included
Controller and processor role determination
Which PII you control, which you process, for which products and which data sets. This decides which parts of the standard apply to you and is the question buyers ask first (“Are we a PII controller, a PII processor, or both?”, buyer phrasing from r/cybersecurity threads, language source only, checked 14-08-2026).
Included
PIMS design and documentation
Scope statement, policies, records and controls sized to your roles. Where you already run ISO 27001, the PIMS aligns with the ISMS rather than duplicating it, which is how ISO itself frames the combined path (iso.org product page, checked 14-08-2026). Where you do not, the 2025 edition is built to stand alone (iso.org product-page FAQ, checked 14-08-2026).
Included
Operating evidence
A PIMS has to run before it can be certified. We build the evidence habits, access reviews, processing records, incident handling, into ordinary work so the records exist when an auditor samples them.
Included
Independent internal audit
Performed by Atoro practitioners who were not involved in your build, so the audit tests the system rather than marking its own homework.
Included
Certification audit preparation and management
Certification body selection, scheduling, and support through the Stage 1 and Stage 2 audits the certification body runs.
One deliberate omission: we do not print control counts or annex structures for the 2025 edition here, because published sources conflict on them and the published standard text is the only authority.
You get the structure from the standard, applied to your scope, not from a blog table.
07 Price
Pricing honesty
We do not publish Atoro’s prices, because a credible ISO 27701 price depends on your scope, your roles and whether an ISMS already exists, and any figure quoted before that scoping would be invented.
Market context, labelled for what it is: UK platform Hicomply publishes indicative ranges for the 2019-edition extension model, certification body fees of GBP 3,000 to 10,000 for SMEs extending an existing ISO 27001, GBP 10,000 to 25,000 and above for larger organisations, and annual surveillance audits of GBP 1,500 to 5,000 (hicomply.com, UK vendor, figures in GBP, checked 14-08-2026). These figures describe the withdrawn extension model, not standalone 2025 certification, and they are one vendor’s marketing-page ranges, so treat them as a rough order of magnitude for certification body fees, not a quote. We found no published UK or Ireland pricing for standalone ISO/IEC 27701:2025 certification in our research (checked 14-08-2026).
The honest next step is a scoping conversation: what PII you handle, which roles you hold, what already exists. Price follows scope.
08 FAQ
ISO 27701 FAQs
Do we need ISO 27701 on top of ISO 27001?
Not as a prerequisite, no. Under the withdrawn 2019 edition, ISO 27701 certification always rode on an ISO 27001 certificate; under ISO/IEC 27701:2025 it is an independent management system standard, and ISO’s own FAQ confirms it can be implemented without ISO 27001 (iso.org, checked 14-08-2026). If you already run ISO 27001, integrating the PIMS with your ISMS is the aligned path ISO recommends. Whether you need ISO 27701 at all depends on whether you process PII as a controller or processor and need a managed, certifiable system for it.
Can we get ISO 27701 certified without ISO 27001?
Yes. ISO’s product-page FAQ answers this directly: “Yes, as it is an independent management system standard (MSS).” (iso.org, checked 14-08-2026.) This changed with the October 2025 edition; several ranking pages still describe the old extension model, including certification bodies, so check the edition any provider is quoting. Certification is delivered by accredited bodies working to ISO/IEC 27706:2025, the companion standard for PIMS auditors (iso.org, checked 14-08-2026).
Does ISO 27701 make us GDPR compliant?
No, and be suspicious of any page that implies it does. ISO’s own wording is that ISO/IEC 27701 “helps demonstrate compliance with global privacy regulations such as GDPR” (iso.org, checked 14-08-2026). Certification is not GDPR compliance in itself, and it is not certification under GDPR Article 42; ISO claims neither. What it gives you is a management system that organises and evidences the privacy work GDPR expects.
Are we a PII controller, a PII processor, or both?
Most software companies are both. You are typically the controller for employee data and client contract data, and the processor for customer data your product handles, exactly as one implementer at a cloud-hosted software company described their position (r/cybersecurity, language source only, checked 14-08-2026). The distinction matters because the standard applies different requirements to each role. Role determination is one of the first work products of any implementation engagement.
What happens to our ISO 27701:2019 certificate after October 2028?
Certification bodies state that 2019-edition certificates stop being valid at the end of the transition period: Brand Compliance gives 1 October 2028, and Schellman, citing ANAB Heads Up #550, gives 31 October 2028 (both checked 14-08-2026). ISMS.online adds that a holder who misses the deadline would certify against the 2025 edition as a new certification, potentially with full Stage 1 and Stage 2 audits (checked 14-08-2026). This is certification-body consensus, not an ISO or IAF statement, so confirm the exact terms in your own certification body’s transition letter.
Should our privacy gap analysis be based on GDPR or on ISO 27701 controls?
Both, in that order. GDPR is the law you answer to, so the assessment starts from your obligations under it; ISO 27701 is the management system you operate, so it is then tested against the standard’s requirements. Buyers phrase this exact confusion (“should we base it on the data protection regulations for specific regions, like GDPR or CCPA, or should it be based on the ISO 27701 controls?”, r/gdpr thread, language source only, checked 14-08-2026). An engagement with us starts from the regulation and lands on the standard.
Is ISO 27701 certification a personal qualification or a company certification?
A company certification. ISO 27701 certifies an organisation’s privacy information management system, not a person; as one privacy attorney put it when correcting the mix-up, “It’s a standard utilized by companies. It is not a test.” (r/privacy thread, language source only, checked 14-08-2026.) Personal credentials such as lead auditor courses exist in a separate training market. If your goal is the certificate your company shows customers, that is organisational certification against the 2025 edition.
How long does ISO 27701 take if we already have ISO 27001?
We found no verified published timeline for ISO/IEC 27701:2025. Figures that circulate describe the withdrawn 2019 extension model and are vendor marketing claims: Hicomply suggests 3 to 6 months to extend an existing ISO 27001, and an India-market consultancy claims 4 to 12 weeks (hicomply.com and pricoris.com, both checked 14-08-2026). Your real timeline is set by how much privacy machinery you already operate and by the certification body’s calendar, which is why we scope duration per engagement rather than quoting a number we cannot defend.
Talk to Atoro about ISO 27701
If you already hold ISO 27001, or plan to, the common pairing is Atoro’s ISO 27001 implementation service.
If you want a scoped view of ISO 27701 for your company, the route is a conversation with Atoro, not a form quote.
No published price before scoping. No 2019-edition assumptions. No certificate we do not hold.
We’ll review
What PII you handle, and for which products and data sets.
Which roles you hold, PII controller, PII processor, or both.
What already exists, including any ISO 27001 ISMS.
Whether you hold a 2019 certificate and need to transition.