Management system certification
ISO/IEC 27701:2019
Extends the 27001 management system to cover personal data, mapping controls to controller and processor roles. Frequently used to evidence GDPR accountability.
What you receive
Certificate of Registration (extension)
Issued only by a body accredited to ISO/IEC 17021-1, as an extension to an existing 27001 certification.
Who needs it
Organisations processing personal data at scale, or answering GDPR-driven supplier questionnaires that 27001 alone does not satisfy.
Prerequisites
A current ISO/IEC 27001 certification. 27701 cannot stand alone.
How this engagement is delivered
Audited and certified by Securo Cert LLC.
Accredited artifactThe partner body is named in the proposal before any work begins, and printed on the resulting document alongside the delivery mode.
Frequent questions
What do we actually receive?
Certificate of Registration (extension). Issued only by a body accredited to ISO/IEC 17021-1, as an extension to an existing 27001 certification.
How long is it valid?
Aligned to the underlying 27001 cycle.
What has to be in place first?
A current ISO/IEC 27001 certification. 27701 cannot stand alone.