What is a realistic month-by-month roadmap?
Months 1-2: scoping (entities, systems, processing activities in scope), role determination per activity, gap assessment against the standard, and the business case with certification-body quotes. Months 3-4: PII inventory and data mapping; privacy risk assessment methodology extended from the security risk process; remediation backlog prioritized by audit criticality. Months 5-8: control build, notice and consent mechanics, DSAR workflow with identity verification and deadline tracking, retention schedules with deletion evidence, processor/subprocessor contract remediation, disclosure logging, transfer safeguards, plus mandatory PIMS documentation (scope statement, privacy policy set, statement of applicability). Months 8-10: operate and evidence, run the DSAR process against real or drilled requests, generate consent and disclosure records, complete at least one full internal audit and one management review; auditors will sample this period. Month 10: stage 1 documentation audit; fix findings. Months 11-12: stage 2 implementation audit, nonconformity closure, certificate issue. Compression is possible with an existing mature ISMS and dedicated staffing (6-9 months); companies starting without ISO management-system experience should plan the 15-month end and consider sequencing 27001 first or an integrated build.
How should we scope to control cost without gutting the certificate's value?
Scope is the single biggest cost lever, audit days, control build, and evidence burden all scale with it. Start from the commercial driver: which products, services, and processing activities do customers and regulators actually ask about? Certify those first, typically the flagship SaaS product and its supporting infrastructure, and exclude clearly separable back-office or legacy systems. But respect three boundaries. Credibility: a scope excluding the very processing your customers buy is transparent and gets challenged in diligence, scope statements are public on certificates, and sophisticated buyers read them. Separability: exclusions must be defensible interfaces, if the excluded HR system feeds the in-scope product database, auditors will follow the data. Growth path: design the scope statement so extensions (new products, new regions) are additions at surveillance rather than re-scoping projects. A common pattern: year one covers the primary product and central privacy functions; year two extends to secondary products; acquisitions enter after their integration stabilizes. Document the rationale, stage 1 auditors test whether the scope makes sense before they test anything else.
What evidence must exist before stage 2, and how long an operating period?
Certification bodies generally expect the management system to have operated long enough to generate a meaningful evidence trail, in practice, three months minimum, with a completed internal audit cycle and at least one management review as hard prerequisites. The evidence auditors sample: DSAR records end-to-end (request receipt, identity verification, data location, response, deadline compliance), consent capture and withdrawal records, processing-activity records aligned to actual systems, privacy risk assessment with treatments and acceptance decisions, disclosure and transfer logs, processor contracts and the subprocessor register with flow-down terms, retention execution evidence (deletion logs, not just schedules), training completion, incident and breach-drill records, corrective actions from internal audit findings, and management review minutes showing privacy objectives tracked with decisions made. Two failure patterns dominate: paper systems (policies dated a month before audit with no operating history), and evidence that contradicts the documentation (the retention schedule says 24 months, the database has records from 2015). Run one honest internal audit early enough to fix what it finds, an internal audit that identifies real nonconformities, with closed corrective actions, is stronger stage 2 evidence than a clean one nobody believes.
What do stage 1 and stage 2 audits each test, and what fails them?
Stage 1 is a readiness review, usually 1-3 days, often partly remote: the auditor examines PIMS documentation (scope, SoA, risk assessment, mandatory policies), confirms role determinations, checks internal audit and management review occurred, and assesses whether stage 2 can proceed. Typical stage 1 findings: scope ambiguities, missing role analysis, risk assessments that ignore PII-principal harms, SoA exclusions without justification. Stage 2 tests implementation across the scope, days scale with organization size: interviews with control owners, records sampling, and walkthroughs, with predictable deep dives into DSAR handling, consent validity, subprocessor management, retention execution, and breach readiness. Findings classify as major nonconformities (systemic failure or absent required element, certification blocked until closed, sometimes with re-audit), minor nonconformities (isolated lapses, closed via corrective-action plans), and observations. The most common stage 2 majors: DSAR processes that cannot actually locate data across systems, consent records that do not evidence validity, and processor contracts missing required privacy terms. Certificates issue after nonconformity closure, so budget 4-8 weeks between stage 2 fieldwork and the certificate in the realistic plan.
What does life after certification require?
Three rhythms. Annual surveillance: a reduced-scope audit each year that always covers management review, internal audit, corrective actions, complaint and DSAR handling, and a rotating control sample; surveillance majors can suspend the certificate, and the classic surveillance failure is drift, the program that peaked at stage 2 and decayed. Three-year recertification: a full-scope re-audit; treat year three as a mini-project. Change control between audits: new products, processing purposes, vendors, and jurisdictions must enter the PIMS deliberately (risk assessment updates, SoA changes, scope-extension requests to the certifier when boundaries move); acquisitions are the stress case, decide explicitly whether and when acquired processing enters scope. Sustainment staffing is the honest cost: a named PIMS owner with a standing internal-audit calendar, quarterly control-owner check-ins, and management reviews that make real decisions. The programs that sustain cheaply are the ones that wired PIMS evidence into normal operations (DSAR tooling that logs automatically, deletion jobs that report execution) rather than assembling evidence annually by hand. Budget roughly a third of the implementation-year effort, every year, indefinitely.