By the Aegentra Security Team — NV1-cleared privacy and security practitioners · Published 1 August 2026
Privacy became a job title in Australia before it became a standard anyone could certify against on its own. This guide covers the credential behind it — the PECB Lead Implementer pathway for ISO/IEC 27701: the tiers, the experience and PIMS project hours each one needs, the exam, the cost, and the roles it opens.
To become a PECB Certified ISO/IEC 27701 Lead Implementer you complete the official ISO 27701 Lead Implementer training, pass the PECB exam — 80 multiple-choice questions across seven competency domains, open book, three hours, 70% to pass — then meet the experience tier you are claiming: five years of professional experience with two in privacy management, plus 300 hours of PIMS project activity for the full Lead Implementer credential. The entry tier, Provisional Implementer, needs only the exam. Aegentra Academy is an official PECB authorised training partner and runs the course for $849 + GST self-paced or $928 + GST with eLearning, with the exam voucher and a free 12-month retake included.
ISO/IEC 27701:2025 is the international management-system standard for privacy — and since the October 2025 revision it is stand-alone, no longer requiring an ISO 27001 ISMS underneath it. A Lead Implementer is the person who builds and runs that system: the records of processing, the privacy policy, the risk assessment, the Statement of Applicability, the 78 Annex A controls, and the audit readiness. The detail on the standard itself is in our ISO 27701 certification guide; this page is about the individual credential and the career behind it.
Two clarifications. First, the Lead Implementer builds the system and the Lead Auditor assesses it — separate credentials, separate career tracks. Second, a great deal of published guidance still describes the 2019 edition, which required ISO 27001 first and split the controls across Annex A and Annex B. Neither is true of the 2025 edition, where Annex A is one consolidated annex of 78 controls across three tables and Annex B is implementation guidance.
Aegentra Academy is an official PECB authorised training partner and delivers the ISO 27701 Lead Implementer course online and self-paced. Foundation-level grounding is available through the ISO 27701 Foundation course.
“Lead Implementer” is the third rung of a four-tier ladder. All four sit the same exam; what separates them is the professional experience and the hours of hands-on PIMS work you can evidence.
| Credential tier | Total experience | In privacy management | PIMS project hours |
|---|---|---|---|
| Provisional Implementer | None | None | None |
| Implementer | 2 years | 1 year | 200 hours |
| Lead Implementer | 5 years | 2 years | 300 hours |
| Senior Lead Implementer | 10 years | 7 years | 1,000 hours |
Above these sits PECB Certified ISO/IEC 27701 Master — 20 years of professional experience with 10 in a leadership role, 5,000 hours of combined audit and project activity, and passing both the ISO/IEC 27701 and Lead Auditor exams. Confirm current criteria on the official PECB ISO/IEC 27701 page.
Two things are counted separately. Professional experience is your years of work, with a minimum specifically in privacy management. Project activity hours are hands-on hours doing the PIMS work itself — the part people underestimate and then cannot evidence later.
No Australian law names ISO 27701. Demand arrives through the Privacy Act, enterprise procurement, and the 2025 revision itself.
Indicative Australian ranges from public privacy, GRC and risk salary guides — a market guide, not a quote:
| Role | Indicative range (AUD) |
|---|---|
| Privacy Analyst | $100,000 – $135,000 |
| Privacy Officer | $120,000 – $160,000 |
| Data Protection Officer | $145,000 – $195,000 |
| Privacy & Compliance Manager | $150,000 – $200,000 |
| Head of Privacy | $185,000 – $245,000 |
No — and since the October 2025 revision that is true of the standard itself, not just the credential. ISO/IEC 27701:2025 is a stand-alone management system standard; PECB states the 2025 edition introduces a stand-alone PIMS, no longer requiring ISO/IEC 27001-based security management. Guidance telling you otherwise is describing the superseded 2019 edition.
80 multiple-choice questions across seven competency domains, open book, three hours, 70% to pass. The domains follow the implementation lifecycle: fundamental principles and concepts of a PIMS; initiation; planning; implementation; monitoring and measurement; continual improvement; and preparing for a PIMS certification audit. Scenario items are still multiple-choice.
Aegentra Academy runs the official PECB ISO 27701 Lead Implementer course for $849 + GST as self-study and $928 + GST with eLearning. Both include the official PECB exam voucher and one free retake within 12 months — PECB states the training fee includes a first exam attempt and one retake — so there is no separate exam fee.
Almost certainly both, and it is decided per processing activity. You are a controller for your own employee records, recruitment and marketing. You are a processor for data your customers put into your platform. The determination selects which Annex A table applies: Table A.1 for controllers (31 controls), Table A.2 for processors (18), and Table A.3 shared security controls (29) which apply either way.
Take Lead Implementer if you will build the PIMS; take Lead Auditor if you will assess someone else’s. Both exams are 80 questions over seven domains, but the domains differ: implementation phases versus audit phases.
Both, and they are separate things. Individuals earn a professional credential. Organisations get certified by building a PIMS and passing an audit by an accredited certification body — and since the 2025 revision that certificate can stand alone or extend an existing ISO 27001 certificate.
Ready to start? Aegentra Academy runs the official PECB ISO 27701 Lead Implementer course for $849 + GST, exam voucher and free retake included. If your organisation needs the PIMS built rather than a person trained, that is our ISO 27701 implementation service.