ISO/IEC 27701 Certification

Build Privacy into Your Security Program with ISO/IEC 27701 Certification.

From Secure to Privacy-Assured.

ISO/IEC 27701 is the global extension to ISO/IEC 27001 focused on Privacy Information Management. It adds specific controls and guidance for handling personally identifiable information (PII) and aligns with international privacy regulations like GDPR, CCPA, etc.

Who is ISO/IEC 27701 Certification For?

ISO/IEC 27701 is ideal for organizations that collect, process, or manage PII, especially those operating in regulated or multinational environments. It is relevant to data controllers and processors and must be implemented alongside an existing or in-progress ISO/IEC 27001 ISMS.

Why ISO/IEC 27701 Certify with Securisea CB?

Our team specializes in helping privacy-conscious organizations extend their ISMS to include privacy-specific controls. Securisea CB, LLC ensures your systems, processes, and accountability mechanisms meet global expectations for privacy governance through a thorough, independent audit.

Key Benefits of ISO/IEC 27701 Certification:

  • Demonstrates compliance with global privacy laws and frameworks.

  • Enhances customer and stakeholder trust in how PII is managed.

  • Bridges gaps between security and privacy teams.

  • Builds on your existing ISO/IEC 27001 certification.

  • Processes for granting, refusing, suspending, restoring or withdrawing certification:

    Securisea CB's process for certification decisions are designed to conform with ISO17021-1:2015 and ISO27006. In doing so our process to decide whether to grant or refuse certification to an entity begins with a formal Application for Certification.

    The process includes a number of stages including but not limited to applying for certification, undergoing a Stage 1 and Stage 2 audit and possibly the resolution of one or more non-conformities. Once this process is complete, the client's lead auditor will prepare a certification package with a recommendation to grant or refuse the certification and submit both to the certification committee for a decision. the certification committee will examine the totality of the evidence and grant or refuse the certification. This decision may be appealed according to Securisea CB's appeals process.

    Certifications must be maintained via ongoing surveillance and re-certification audits. In the event that a certificate holder is unable to show ongoing conformance to the requirements of its certification, said certification may be withdrawn. In this case the client may rectify the issues which caused the suspension in order to have the certification restored. All decisions to suspend or restore a certification are made by the audit committee and may be appealed. A certification may also be suspended at the entity's request.

    In the event that a certification is suspended for 6 months or greater the certificaiton will be withdrawn if the client has not filed an appeal. In the event that a suspension has been appealed, it will usually continue to be considered suspended until the appeal is closed, even if this is greater than 6 months.

    Process for expanding or reducing the scope of certification:

    Certification holders may apply for an expansion or reduction of the scope of a certification at any time. Securisea CB, LLC will usually need to conduct a surveillance or re-certification audit prior to the granting of a scope expansion unless the application is relatively minor in nature. The certification may also be reduced by Securisea CB in the event that that information is brough to our attention that the client's existing scope is invalid.

    All decisions to grant an expansion or reduction of certification scope must be approved by the certification committee.

  • Any statements regarding certification by Securisea CB or use of Securisea CB's certification mark may only be made by entities with active granted certification(s) and an active service agreement, in accordance with both the certification's scope and the terms of the service agreement between the client and Securisea CB.

  • Securisea CB maintains a compliants and appeals process. Complaints may be made by submitting a request via the complaints page. and must state the entity making the complaint, contact information including a working phone number, and the nature of the complaint. Valid complains will be examined and addressed by someone not a party to the specific complaint in question. Appeals should be submitted via the appeals page and must include contact information including a working telephone number. All appeal decisions are made by staff who were not involved in the related audit or certification decision.

    Requests for information must included contact information including a working phone number and may be made via the contact page