🇸🇦 Kingdom of Saudi Arabia 📞 +966 549983377 ✉ contact@pristinesaudi.com
24/7 SOC ACTIVE
🌐 عربي Client Portal
Home
About
Services
Solutions
Compliance
Industries
Insights
Home/Compliance/ISO 27001 / 27701
ISO 27001:2022 · ISO 27701 · ISMS · PIMS · International Certification

ISO Certified.
First Attempt.
Every Time.

Pristine InfoSolutions is Saudi Arabia's most experienced ISO 27001:2022 and ISO 27701 certification partner — delivering certified ISMS and PIMS programmes with a 99% first-attempt certification rate, fully aligned to NCA ECC, SAMA CSF, and Saudi PDPL. Bilingual Arabic and English throughout.

99%First-Attempt Rate
93Annex A Controls
2-in-1ISMS + PIMS Together
24 wksTo Certificate
ISO CERTIFICATION PROGRAMME · PRISTINE
IN PROGRESS
// Certification Journey Status
Gap Assessment
93 Annex A controls assessed · 41 gaps identified
COMPLETE
ISMS Design & Policy Library
38 policies — Arabic + English
COMPLETE
Risk Assessment (ISO 27005)
Risk register · SoA · Treatment plan
COMPLETE
Control Implementation
Technical & admin controls — Week 8 of 16
IN PROGRESS
Internal Audit
Scheduled — Week 20
PENDING
Certification Audit (Stage 1+2)
PECB accredited auditor — booked
BOOKED
ISO 27001:2022
PECB Accredited
ISO 27701
Concurrent
ISO 27001:2022 ISMS
ISO 27701 PIMS
93 Annex A Controls
4 Control Themes
NCA ECC 95%+ Aligned
Saudi PDPL Mapped
PECB · BSI · DNV
99% First-Attempt Rate
Statement of Applicability
Risk Assessment ISO 27005
Arabic + English Delivery
2-in-1 Concurrent Delivery
ISO 27001:2022 ISMS
ISO 27701 PIMS
93 Annex A Controls
4 Control Themes
NCA ECC 95%+ Aligned
Saudi PDPL Mapped
PECB · BSI · DNV
99% First-Attempt Rate
Statement of Applicability
Risk Assessment ISO 27005
Arabic + English Delivery
2-in-1 Concurrent Delivery

Two Standards. One Unified Programme.

ISO 27001:2022 and ISO 27701 are designed to work together — the ISMS is the security foundation on which the PIMS is built. Implementing both concurrently with Pristine is 30-40% cheaper than sequential delivery.

◆ Standard 01

ISO/IEC 27001:2022
Information Security
Management System

ISO 27001 is the world's leading standard for information security management. The 2022 edition restructured Annex A to 93 controls across 4 themes with 11 brand new controls covering cloud, threat intelligence, data masking, and secure coding. Transition deadline October 2025 has passed — organisations on 2013 are non-compliant.

PublishedOctober 2022
Controls93 Annex A · 4 Themes
New vs 201311 brand-new controls
NCA ECC Overlap95%+ controls
Certification BodiesPECB · BSI · DNV · SGS
Get ISO 27001 Certified →
◆ Standard 02

ISO/IEC 27701:2025
Privacy Information
Management System

ISO 27701 is the international standard for Privacy Information Management — extending ISO 27001 with privacy controls for PII Controllers and Processors. The 2025 revision made it a standalone certifiable standard. 95%+ mapping to Saudi PDPL — the most structured path to PDPL compliance evidence.

Current VersionISO 27701:2025 (Oct 2025)
Roles CoveredControllers + Processors
PDPL Alignment95%+ article mapping
ISO 27001 RequiredNot required (2025 edition)
Concurrent Delivery30-40% cost saving
Get ISO 27701 Certified →

Mandatory Clauses 4–10 + Annex A Controls

ISO 27001 is structured around 10 clauses plus Annex A. Clauses 4–10 are mandatory. Annex A provides 93 controls from which organisations select applicable controls documented in the Statement of Applicability.

4

Context of the Organisation

Define internal and external context, interested parties, and ISMS scope. The boundary decisions made here shape every subsequent ISMS decision.

Mandatory
5

Leadership

Board commitment, information security policy, and defined roles and responsibilities. SAMA and NCA require board-level ownership evidenced through this clause.

Mandatory
7

Support

Resources, competence, awareness training, and documented information management — policies, procedures, records, and all ISMS evidence controlled and maintained.

Mandatory
9

Performance Evaluation

Internal audit programme, management review, and ISMS effectiveness monitoring. Independent assessment of all clauses and Annex A controls.

Mandatory
10

Improvement

Nonconformity and corrective action process. Continual improvement driven by audit findings, management review, and evolving threats.

Mandatory

93 Controls — Pristine Implements Every Applicable One

ISO 27001:2022 restructured 114 legacy controls into 93 across 4 modern themes — with 11 brand-new controls addressing today's threat landscape.

Theme 5

Organisational Controls

37
Controls

Policies, roles, threat intelligence, asset management, access control, supplier relationships, incident management, BCP, legal compliance. Largest theme.

Theme 6

People Controls

8
Controls

Screening, employment terms, awareness training, disciplinary process, post-employment responsibilities, remote working, confidentiality.

Theme 7

Physical Controls

14
Controls

Security perimeters, entry controls, physical monitoring (NEW), protecting against threats, clear desk, equipment security, cabling, media disposal.

Theme 8

Technological Controls

34
Controls

Endpoint, IAM, cryptography, secure config, DLP (NEW), network, logging, monitoring (NEW), web filtering (NEW), secure coding (NEW), vuln management, cloud (NEW).

ISO 27701 Controllers, Processors & Saudi PDPL

PIMS Management System Clauses 4–10

ISO 27701 extends ISO 27001 Clauses 4–10 with privacy-specific additions. For organisations implementing both concurrently, a single integrated management system satisfies both — reducing documentation by 60-70%.

  • Clause 4: Privacy-specific interested parties, PII processing roles (controller/processor), PIMS scope including all PII processing activities
  • Clause 5: Privacy policy at senior management level. DPO with defined authority. Privacy objectives including DSAR response times and breach notification windows
  • Clause 6: Privacy risk assessment covering risks to data subjects. Legal bases and retention periods for all PII processing activities
  • Clause 8: DPIA process, data subject rights procedures, consent management, cross-border transfer controls, vendor DPA management
Implement ISO 27701 →
PIMS Clause Coverage
✓ PDPL ALIGNED
Context & Scope
100%
Leadership & Policy
100%
Privacy Risk Assessment
100%
Data Subject Rights
100%
PDPL Article Mapping
95%

Annex A — PII Controller Controls

PII Controllers implement Annex A controls covering lawful basis documentation, data subject rights, privacy by design, consent management, and third-party processor management — directly mapped to Saudi PDPL obligations.

  • A.7.2.1 — Lawful Basis: Documented lawful basis for every PII processing activity — directly satisfying PDPL Article 5
  • A.7.3 — Data Subject Rights: Access, correction, deletion, and consent withdrawal — DSAR procedures with PDPL's 30-day response requirement
  • A.7.4.1 — Privacy by Design: DPIAs for new processing. Data minimisation. Retention schedules with technical enforcement
  • A.7.5 — Cross-Border Transfers: PDPL cross-border transfer conditions documented — evidence for SDAIA review
Implement Controller Controls →
Annex A — Controller
✓ PDPL CONTROLLER
Lawful Basis Documentation
100%
Data Subject Rights
100%
DPIA Process
100%
Consent Management
100%
Cross-Border Controls
100%

Annex B — PII Processor Controls

PII Processors implement Annex B controls for processing data on behalf of controllers — covering processing obligations, DSR support, sub-processor management, and breach notification. Essential for Saudi SaaS, cloud, and outsourcing providers.

  • Process PII only on controller instructions — no autonomous use. Contractually and technically enforced
  • Assist controllers with DSR responses within PDPL's required timelines
  • Sub-processor approval and flow-down obligations — register maintained
  • Immediate breach notification to controller enabling PDPL's 72-hour SDAIA notification
Implement Processor Controls →
Annex B — Processor
✓ SAAS READY
Processing Agreements (DPAs)
100%
Sub-Processor Register
100%
DSR Support Procedures
100%
Breach Notification
100%
International Transfers
100%

Saudi PDPL Alignment

Saudi Arabia's Personal Data Protection Law (PDPL) creates specific obligations for organisations processing Saudi personal data. ISO 27701 is the most structured path to PDPL compliance evidence — approximately 95% of PDPL obligations are directly addressed through Annex A and B controls.

  • Lawful Processing (PDPL Art. 5): ISO 27701 A.7.2.1 requires documented lawful basis — directly satisfying PDPL conditions including consent and legitimate purpose
  • Data Subject Rights (PDPL Art. 4, 6, 7): ISO 27701 includes specific controls for access, correction, deletion, and consent withdrawal with PDPL timelines
  • Cross-Border Transfers (PDPL Art. 17): ISO 27701 A.7.5 documents transfer decisions producing the evidence SDAIA requires
  • Breach Notification (PDPL 72-hour): ISO 27701 breach management controls establish the 72-hour SDAIA notification procedure
Map ISO 27701 to PDPL →
Saudi PDPL Mapping
✓ SDAIA READY
Lawful Processing
95%
Data Subject Rights
100%
Cross-Border Controls
97%
72hr Breach Notification
100%
Privacy by Design
98%

From Gap to Certificate — Pristine's 24-Week Pathway

Pristine's structured certification programme delivers a 99% first-attempt success rate. Every phase produces auditor-ready documentation and genuine control implementation.

01

Gap Assessment

All 93 Annex A controls scored. Gap report with risk-prioritised list. ISMS scope boundaries proposed.

Weeks 1–2
02

ISMS Design & SoA

Policy library (38+ docs). Statement of Applicability for all 93 controls. ISO 27701 RoPA if in scope.

Weeks 2–8
03

Risk Assessment

ISO 27005 methodology. Risk register. Treatment plan. Board risk acceptance signed.

Weeks 4–8
04

Control Implementation

All in-scope Annex A controls implemented — technical and administrative. Evidence collected.

Weeks 6–20
05

Internal Audit & Cert

Independent audit. All nonconformities closed. Stage 1 doc audit. Stage 2 on-site certification.

Weeks 20–24
99%
First-attempt certification rate — all Pristine ISO engagements
24 wks
Typical delivery from gap assessment to certification award
2-in-1
ISO 27001 + ISO 27701 concurrently — 30-40% cost saving vs sequential

ISO Programmes for Every Saudi Organisation

Three structured programmes from initial ISO certification to full ISMS+PIMS enterprise transformation aligned to NCA ECC, SAMA, and PDPL.

// Package 01
ISO 27001 Foundation

First ISO 27001:2022 certification for Saudi organisations — full ISMS from gap assessment through to certificate, with NCA ECC control mapping included.

  • Gap assessment — all 93 Annex A controls
  • ISMS scope and policy library (35+ docs)
  • ISO 27005 risk assessment + risk register
  • Statement of Applicability (SoA) — 93 controls
  • Control implementation support
  • Internal audit programme
  • Stage 1 + Stage 2 certification support
  • NCA ECC control mapping included
Enquire — Foundation →
// Package 03
ISO Enterprise

Full enterprise ISO transformation — simultaneous NCA ECC and SAMA, continuous improvement, dedicated programme management, and 3-year maintenance.

  • All Dual Cert features included
  • NCA ECC-2:2024 simultaneous delivery
  • SAMA CSF integrated implementation
  • Dedicated ISO Programme Manager (named)
  • Annual surveillance audit management
  • 3-year certification maintenance plan
  • Monthly compliance dashboard (Arabic+EN)
  • Board quarterly report (Arabic)
Enquire — Enterprise →

Why Saudi Organisations Choose Pristine for ISO

🎯

99% First-Attempt Rate

Every Pristine-prepared organisation that has proceeded to ISO 27001 certification audit has achieved certification at first attempt — zero major nonconformities. Verified track record, not a marketing claim.

🔗

ISO + NCA ECC + SAMA Together

Pristine maps ISO 27001 Annex A controls to NCA ECC sub-controls and SAMA subdomains as standard. Three compliance frameworks from one programme, one evidence set.

📜

2-in-1 Cost Efficiency

ISO 27001 + ISO 27701 concurrently saves 30-40% versus sequential delivery. Shared policies, shared risk methodology, shared internal audit, shared certification audit — one programme, two certificates.

🌐

Arabic-Native Technical Docs

All 38+ ISMS/PIMS policies, SoA, risk register, and board presentations delivered in Arabic by native-speaking consultants — not translated from English. ISO auditors consistently recognise the quality difference.

⚖️

Saudi PDPL Mapped & Evidenced

Pristine produces an explicit PDPL mapping document — article-by-article mapping showing which Annex controls satisfy which PDPL obligations. SDAIA compliance evidence included as standard.

🔄

3-Year Surveillance Managed

ISO is a 3-year cycle with annual surveillance audits. Pristine post-certification management keeps your ISMS and PIMS audit-ready year-round — continuous evidence collection and annual pre-surveillance reviews.

What Saudi ISO Leaders Say

★★★★★

We achieved ISO 27001:2022 certification in 24 weeks with zero nonconformities — having previously failed Stage 2 with another firm due to poor documentation quality. Pristine's Arabic policies were exactly what the auditor expected. The NCA ECC mapping they included saved us months of additional compliance work.

KA
Khalid Al-Anazi
CISO, Saudi Technology Platform
★★★★★

We needed ISO 27001 and ISO 27701 simultaneously — European clients required ISO 27001 and our Saudi government contracts required PDPL compliance evidence. Pristine's concurrent programme achieved both in 22 weeks with zero major nonconformities. The cost saving versus sequential delivery was 35%.

LN
Lena Al-Nasser
CTO, Saudi SaaS Company
★★★★★

Pristine mapped our ISO 27001 Annex A controls to NCA ECC sub-controls as a standard deliverable. When our NCA audit arrived 6 months later, 90% of the evidence was already collected. Zero additional compliance effort. The integrated approach was transformative for our security programme efficiency.

FM
Faisal Al-Mutairi
Head of Compliance, Saudi Enterprise

ISO 27001 & ISO 27701 FAQs

ISO 27001:2022 restructured Annex A from 114 controls across 14 domains to 93 controls across 4 themes — adding 11 entirely new controls covering threat intelligence, cloud security, ICT readiness for BCP, data masking, information deletion, physical security monitoring, and secure coding. The SoA format was updated with attribute categories per control. The transition deadline was October 2025 — organisations still certified against 2013 are non-compliant.
No — the October 2025 revision made ISO 27701 a standalone certifiable standard. Organisations can certify to ISO 27701 without ISO 27001. However, concurrent implementation remains 30-40% more efficient than sequential — shared management system clauses, risk methodology, and audit programme eliminate significant duplication. Pristine recommends concurrent delivery for most Saudi organisations.
For organisations with a moderate gap, Pristine targets 20-26 weeks from gap assessment to certification award. Strong existing foundations can be as fast as 14-16 weeks. Complex large organisations may require 30-36 weeks. We provide a precise timeline after the initial gap assessment. Adding ISO 27701 concurrently adds only 3-5 weeks rather than the 12-18 weeks required sequentially.
ISO 27001 and NCA ECC-2:2024 have approximately 95% control overlap. ISO 27001 Annex A controls map directly to most NCA ECC sub-controls. Achieving ISO 27001 does not automatically satisfy NCA ECC — a formal NCA gap assessment is still required. However, Pristine maps every Annex A control to NCA sub-controls as standard, meaning ISO implementation produces approximately 85-90% of NCA evidence simultaneously.
Pristine is certified-partner with PECB, BSI, DNV, Bureau Veritas, and SGS. PECB offers the most cost-effective certification with strong Middle East presence and Arabic capability — ideal for most Saudi organisations. BSI is recommended where international brand recognition matters (European/US contracts). We guide the selection based on your specific requirements and manage the certification body relationship end-to-end.
Approximately 95% of PDPL obligations are directly addressed through ISO 27701 Annex A and B controls. ISO 27701 certification provides SDAIA with independent, third-party verification of your privacy management programme. Pristine produces an explicit PDPL mapping document as part of every ISO 27701 engagement — mapping which Annex controls satisfy which PDPL articles for use in SDAIA compliance demonstrations.

Get Certified.
First Attempt. Every Time.

Request a free ISO 27001:2022 and ISO 27701 gap assessment — our certified implementation specialists will assess your current ISMS posture and deliver a clear certification roadmap at no cost.

📍 Riyadh, Saudi Arabia

Request Your Free Assessment

A senior Pristine specialist will contact you within 4 business hours.

🔒 Data processed within Saudi Arabia · PDPL compliant · Response within 4 business hours

Explore Related Pristine Services

🇸🇦
NCA ECC & CCC
ISO 27001 Annex A maps 95%+ to NCA ECC controls — delivered simultaneously.
→ Explore
🏦
SAMA Framework
ISO 27001 integrated with SAMA CSF for Saudi financial institutions.
→ Explore
📋
GRC & Compliance
Multi-framework GRC — NCA ECC + SAMA + ISO + PDPL from one programme.
→ Explore
🔍
Penetration Testing
ISO 27001 Clause 6.1 mandates annual penetration testing.
→ Explore