Skip to main content

ISO/IEC 27701 Certification 

Noordbeek Certification is accredited by the Dutch Council for Accreditation to conduct ISO/IEC 27701 audits. That sounds formal, but the difference is significant. You do not get an audit from an intermediary that purchased a licence somewhere. You get an audit from us, with our certificate, which is simply recognised. By clients, procurement teams and everyone who wants to know how you handle personal data.

Call us for no-obligation information or request a quote

Privacy is not leaving the agenda

The GDPR has been in force since 2018. Since then, data protection authorities across Europe have issued fines to organisations that did not have things in order. And yet many organisations are still behind. They know something needs to happen but are not sure exactly what, or they wait until a client asks for it.

That last part is dangerous. Because the moment a client calls with a tender and asks for an ISO/IEC 27701 certificate, it is already too late if you are only just starting.

In October 2025 a new version was also published: ISO/IEC 27701:2025. This is not just an update. The standard has become a standalone certification. That means concretely that you no longer need an ISO/IEC 27001 certificate to get started. Organisations already certified under the 2019 version have until October 2028 to make the transition. Three years sounds comfortable. It rarely is.

Do you deal with NIS2, or the Cybersecurity Act as it is being introduced in the Netherlands? Then ISO/IEC 27701 fits well. It gives structure to exactly the things NIS2 also looks at: how you handle risks, who is accountable and what you do when something goes wrong.

Does this sound familiar?

You are in a sales conversation. It is going well. Then the procurement officer asks: do you have an ISO 27701 certificate? You say you are GDPR-compliant. That is not the same thing. You lose the contract.

Or you already have ISO/IEC 27001. Fine. But a healthcare institution or government client specifically wants something on privacy. What exactly is the difference between those two standards? And does that mean starting an entirely new process?

Maybe you simply process customer data, employee data or medical information. You know the GDPR says something about it. But actually getting started, it just never happens.

We answer those kinds of questions directly. No consultancy language. Just an honest conversation about where you stand.

What is ISO/IEC 27701?

ISO/IEC 27701 is the international standard for a Privacy Information Management System, abbreviated as PIMS. Simply put: it describes how you treat privacy not as a loose obligation but as something that is genuinely organised within your company. Policies, processes, roles, controls and a way to keep improving them.

The standard works with two roles. Are you a data controller? Then you decide yourself for what purpose and how you use personal data. Are you a data processor? Then you do that on behalf of another party. Think of a payroll processor, an IT supplier or a hosting company. ISO/IEC 27701 sets different requirements for both roles and those are sharper and clearer in the 2025 version than in the previous one.

Already have ISO/IEC 27001? Then there is a lot of overlap. We combine the audits. That saves a significant portion of the costs and lead time. Do not have ISO/IEC 27001 yet? No problem anymore. With the new standard you can start purely on privacy, without first having to build a complete information security management system.

Who is it for?

Not just large companies with their own privacy team. Really for any organisation that stores, processes or manages personal data and there are more of those than you might think. Payroll processors and HR service providers. Software companies that hold customer data in their systems. Marketing agencies running campaigns on personal data. Healthcare institutions. Municipalities. Accounting firms. Cloud providers. Educational institutions.

Not sure? Call us. We will check with you free of charge whether it is relevant for your organisation.

Get in touch

What does it get you?

The most direct benefit is access to contracts you are currently missing out on. Large procurement teams, health insurers, government services, they increasingly require an ISO/IEC 27701 certificate. Not as a nice-to-have but as a hard requirement in the first selection round.

But it does not stop there. A large part of what the GDPR requires from you is already built into the standard. So you work on your privacy management and your compliance at the same time, without two separate processes. A properly structured PIMS also forces you to think about what can go wrong. What are the risks? Who has access to which data? What do you do if there is a data breach? Organisations that have this sorted pay less in recovery costs when incidents occur.

Clients and partners notice too. Not because you say so but because an independent party has verified it.

How does it work?

Five steps. No surprises along the way.

Step 1 - Intake One hour, free, no obligation. We look at your organisation together: what you do, what you already have, what still needs to be done. You then receive a tailored quote. No standard price, because no two organisations are the same.

Step 2 - Document review An auditor reviews your privacy policy, procedures, risk analysis, processing registers and your statement of applicability. You receive a report detailing exactly what does not yet comply, so you can adjust it before the on-site audit.

Step 3 - On-site audit We come to you. Conversations with people, reviewing systems and processes. The core question is always the same: does what is written on paper match how things actually work in practice?

Step 4 - Certification committee Three senior auditors assess the file independently from one another. No single person ever decides alone. That is what keeps the value of our certificate intact.

Step 5 - Certificate Valid for three years. Followed by recertification. In between, an annual surveillance audit, a lighter check to confirm the PIMS is still working as it should.

Schedule an ISO/IEC 27701 certification intake, free and no obligation

What does it cost?

It depends on the size of your organisation, the scope and how far along you already are. There is no fixed price. Request a quote. Then you know exactly where you stand without committing to anything.

Why Noordbeek?

We are small. That is deliberate. You always speak to the same auditor, not a rotating team that opened your file the evening before. Our accreditation is granted by the Dutch Council for Accreditation, which is part of the international IAF-MLA network. That means our certificate is recognised outside the Netherlands as well.

Our auditors know ISO/IEC 27701 well, including the 2025 version. They understand what is going on at a SaaS company or an HR service provider and they ask questions that go further than ticking boxes on a checklist.

You reach a real person. No queue, no ticket number. And before you start you know what it costs.

Frequently asked questions

How long does the process take? If you already have things like policies, processing registers and a risk analysis in place, you are typically looking at three to six months. If nothing is in order yet, preparation will take closer to six to nine months. A gap analysis at the start saves a lot of delays later on. We carry that out together during the intake.

Do I need ISO/IEC 27001?

Previously yes. But with ISO/IEC 27701:2025 that has changed. You can now certify purely on privacy without first having built a complete information security management system. Already have ISO/IEC 27001? Then we combine the audits. That saves you money and time.

Is this the same as GDPR compliance?

No. But there is significant overlap. ISO/IEC 27701 gives you a system that aligns with what the GDPR requires. A certificate is not legal proof of GDPR compliance but it is the strongest signal that you are taking it seriously. Data protection authorities view certification as positive evidence of responsible privacy management.

I have a certificate based on the 2019 version. What do I need to do?

Nothing mandatory for now. You have until October 2028 to make the transition. But do not start the gap analysis too late. The structure of the standard has changed and that requires adjustments to your documentation and your Statement of Applicability. We strongly advise starting well ahead of that deadline.

Can I combine this with ISO/IEC 27001 or NEN 7510?

Yes. Where there is overlap we combine the audits. You do not have to pay separately for three individual processes.

What if we do not pass the audit?

You receive a report with the points that do not comply. You are given the opportunity to resolve them. A follow-up check then takes place on exactly those specific points. You only pay for the additional hours required.

First step?

The intake costs you nothing. No obligation, no sales pitch. Just an honest conversation about where you stand right now and what it takes to get certified.

Get in touch with your specialist


Contact

Noordbeek Certification B.V.
Rijndijk 235
2394 CD Hazerswoude
Chamber of Commerce 80529585

This email address is being protected from spambots. You need JavaScript enabled to view it.


© Noordbeek Certification B.V.  All rights reserved.