Insights | Cybercontrols

ISO 27701:2025 Transition Guide: What Changed

Written by Marius van Aswegen | Oct 4, 2026, 7:32:28 PM

In short: ISO/IEC 27701:2025, published on 14 October 2025, turns privacy information management into a standalone management system standard. You no longer need ISO 27001 to certify against it, it follows the same clause 4 to 10 structure as other ISO management system standards, and its controls are aligned with ISO/IEC 27001:2022. If you hold a 2019 certificate, plan your transition now rather than in the final year.

What changed from ISO 27701:2019

TopicISO 27701:2019ISO 27701:2025
StatusAn extension to ISO 27001 and ISO 27002A standalone privacy information management system standard
CertificationOnly alongside an ISO 27001 certificateCertifiable on its own, or integrated with ISO 27001
StructureClauses that modified ISO 27001 requirementsFull management system clauses 4 to 10
Control alignmentBased on ISO 27002:2013Aligned with ISO/IEC 27001:2022 and 27002:2022
ControlsAnnexes for PII controllers and PII processorsA revised Annex A with privacy controls for PII controllers and processors, plus the security controls a standalone PIMS needs

Why the standalone model matters

Under the 2019 edition, privacy certification was locked behind an information security certificate. Organisations whose main obligation is data protection, rather than information security, had to build an entire ISO 27001 system first. The 2025 edition removes that barrier. A processor that needs to demonstrate accountability under UK GDPR can now certify its privacy management system directly.

For organisations that already run ISO 27001, the better route is usually an integrated system: one set of leadership, risk, internal audit and management review processes serving both standards. That is the approach we describe in The Triangle of Control.

Transition deadlines

Certification bodies accredited by UKAS are working to a transition deadline of 31 October 2028 for certificates issued against the 2019 edition. After that date, 2019 certificates lapse. In practice, most organisations will transition at a surveillance or recertification audit, and certification body audit slots fill up quickly in the final year, so planning for 2026 or 2027 is sensible.

A five-step transition plan

  1. Buy the standard and read it properly. Use a licensed copy and compare it against your current system, clause by clause.
  2. Run a gap analysis. Focus on the new standalone clauses, the restructured Annex A controls and how your records of processing map to them.
  3. Decide on integration. Choose whether to certify standalone or keep a combined ISO 27001 and ISO 27701 system.
  4. Update and evidence. Revise your scope, Statement of Applicability, policies and risk treatment, then run an internal audit against the 2025 edition.
  5. Book the transition audit. Agree timing with your certification body early, ideally alongside a planned surveillance visit.

Frequently asked questions

Do we still need ISO 27001 to certify against ISO 27701:2025?

No. The 2025 edition is a standalone standard. Many organisations will still choose an integrated system, because the two share most of their management system processes.

Is our ISO 27701:2019 certificate still valid?

Yes, until the transition deadline. You will need to transition to the 2025 edition before your certificate lapses.

How long does a transition take?

For a well-run 2019 system, a focused gap analysis and update usually takes weeks rather than months. The bigger task is evidencing the changes before the transition audit.

Planning your ISO 27701 transition? Our ISO 27701 privacy consultancy runs gap analyses against the 2025 edition, or you can book a free scoping call with a senior lead auditor.