ISO 27701:2025 Transition Guide: What Changed and What to Do Next
In short: ISO/IEC 27701:2025, published on 14 October 2025, turns privacy information management into a standalone management system standard. You no longer need ISO 27001 to certify against it, it follows the same clause 4 to 10 structure as other ISO management system standards, and its controls are aligned with ISO/IEC 27001:2022. If you hold a 2019 certificate, plan your transition now rather than in the final year.
What changed from ISO 27701:2019
| Topic | ISO 27701:2019 | ISO 27701:2025 |
|---|---|---|
| Status | An extension to ISO 27001 and ISO 27002 | A standalone privacy information management system standard |
| Certification | Only alongside an ISO 27001 certificate | Certifiable on its own, or integrated with ISO 27001 |
| Structure | Clauses that modified ISO 27001 requirements | Full management system clauses 4 to 10 |
| Control alignment | Based on ISO 27002:2013 | Aligned with ISO/IEC 27001:2022 and 27002:2022 |
| Controls | Annexes for PII controllers and PII processors | A revised Annex A with privacy controls for PII controllers and processors, plus the security controls a standalone PIMS needs |
Why the standalone model matters
Under the 2019 edition, privacy certification was locked behind an information security certificate. Organisations whose main obligation is data protection, rather than information security, had to build an entire ISO 27001 system first. The 2025 edition removes that barrier. A processor that needs to demonstrate accountability under UK GDPR can now certify its privacy management system directly.
For organisations that already run ISO 27001, the better route is usually an integrated system: one set of leadership, risk, internal audit and management review processes serving both standards. That is the approach we describe in The Triangle of Control.
Transition deadlines
Certification bodies accredited by UKAS are working to a transition deadline of 31 October 2028 for certificates issued against the 2019 edition. After that date, 2019 certificates lapse. In practice, most organisations will transition at a surveillance or recertification audit, and certification body audit slots fill up quickly in the final year, so planning for 2026 or 2027 is sensible.
A five-step transition plan
- Buy the standard and read it properly. Use a licensed copy and compare it against your current system, clause by clause.
- Run a gap analysis. Focus on the new standalone clauses, the restructured Annex A controls and how your records of processing map to them.
- Decide on integration. Choose whether to certify standalone or keep a combined ISO 27001 and ISO 27701 system.
- Update and evidence. Revise your scope, Statement of Applicability, policies and risk treatment, then run an internal audit against the 2025 edition.
- Book the transition audit. Agree timing with your certification body early, ideally alongside a planned surveillance visit.
Frequently asked questions
Do we still need ISO 27001 to certify against ISO 27701:2025?
No. The 2025 edition is a standalone standard. Many organisations will still choose an integrated system, because the two share most of their management system processes.
Is our ISO 27701:2019 certificate still valid?
Yes, until the transition deadline. You will need to transition to the 2025 edition before your certificate lapses.
How long does a transition take?
For a well-run 2019 system, a focused gap analysis and update usually takes weeks rather than months. The bigger task is evidencing the changes before the transition audit.
Planning your ISO 27701 transition? Our ISO 27701 privacy consultancy runs gap analyses against the 2025 edition, or you can book a free scoping call with a senior lead auditor.
