ISO/IEC 27701:2025 is not a new version of the old standard. It is a different one. The 2019 edition was an extension you bolted onto ISO 27001. The 2025 edition is a standalone privacy management system you can certify on its own — and the clause numbers you have been citing now mean something else entirely.

This assessment scores 48 questions across clauses 4 to 10 and the controller, processor and security control sets. It is free, it saves as you go, and you can stop and come back to it.

What this is

A pass over the 2025 edition as it now reads. We have the background elsewhere — the standard explained, what changed in 2025, the controls, the mandatory documents and how it maps to GDPR. Come here when you want a score.

What it covers

AreaQuestions
Transition and role determination4
4 — Context, interested parties and scope4
5 — Leadership, privacy policy and roles3
6 — Privacy risk assessment, treatment and Statement of Applicability5
7 — Competence, awareness, communication and documents4
8 — Operational risk assessment and treatment3
9 — Monitoring, internal audit and management review3
10 — Improvement and corrective action2
Annex A.1 — PII controller controls10
Annex A.2 — PII processor controls7
Annex A.3 — Information security controls3

What actually changed

It stands alone. ISO 27001 certification is no longer a prerequisite. A companion standard published alongside it gives certification bodies the scheme to certify a privacy management system in its own right — though whether your certification body is accredited for that yet is worth asking directly rather than assuming.

The clause numbers moved completely. In 2019, clauses 7 and 8 held the controller and processor guidance. In 2025 those numbers mean Support and Operation, and the controller and processor content moved into Annex A. A stale reference here does not merely look dated — it points at a different requirement.

Annex A now holds everything. A.1 is the controller control set, A.2 the processor set, and A.3 brings the privacy-relevant information security controls inside the standard, which is what makes standalone certification coherent. You need a Statement of Applicability against Annex A in its own right, not an extension of your ISO 27001 one.

Privacy risk means risk to the individual. This is the substantive change rather than the structural one. An information security risk assessment relabelled as a privacy one, scoring risk to the organisation, no longer satisfies clause 6.1.2. The question is what could happen to the person whose data it is.

What a certificate does not demonstrate

Worth being blunt, because the claim gets made: a 27701 certificate is not a GDPR certification. Only a body accredited under Article 43 can issue an Article 42 certification, and that certifies processing operations rather than an organisation. Even then it carries no presumption of legal conformity.

More practically, three things sit outside what any 27701 assessment tells you. Scope — a management system can be scoped to part of the business, while the law applies to all of it, and that is the most exploited gap in vendor assurance. Lawfulness — the standard checks you have a process to identify and document a lawful basis, not whether the basis you chose is legally right. And transfers — it checks you recorded the mechanism, not whether it would survive challenge.

None of which makes it worthless. It is strong evidence of the accountability machinery, and a useful artefact in due diligence. It is just not the thing people sometimes sell it as.

How the scoring works

StatusWeightMeans
Not started0%No policy, process or activity exists
Planned25%Agreed and scheduled, nothing in place yet
Partially implemented50%In place for part of the scope, or applied inconsistently
Implemented, not evidenced75%Operating as intended, but you could not prove it today
Implemented and evidenced100%Operating as intended, with records someone could sample
Not applicable—A justified exclusion, removed from the score

If you are only a controller, the processor questions are not applicable, and the reverse. If you are both — and more organisations are than realise it — answer both sets.

Free score, or the full report

The assessment and your overall score are free. The full report is a one-off $39 and gives you every question with your status and notes, the score broken down by clause and annex, a prioritised gap list, and the documents from the ISO 27701 Toolkit that close each gap — as a PDF and a working Excel file. The toolkit is built for the 2025 edition.

How long does it take?

About 40 minutes. The controller annex is the longest section and needs someone who knows what processing actually happens, not just what the register says.

What to do with your score

Below 40% — determine your role per processing activity and build the record of processing. Which control set applies follows from the first, and most of the annex questions are unanswerable without the second.

40–70% — look at the privacy risk assessment. If it scores risk to the organisation rather than to the individual, it is the wrong assessment however well built it is.

Above 70% — check your internal audit programme. In integrated systems it routinely covers ISO 27001 and its controls and never samples a privacy clause or a privacy control at all.

Frequently asked questions

Is this assessment really free?

Yes. All 48 questions, the breakdown by clause and annex and your overall score cost nothing. The $39 report is optional.

Do I still need ISO 27001 first?

No. That was the 2019 position. The 2025 edition is standalone, and Annex A.3 brings the relevant security controls inside it. Integrating with an existing ISMS is still the common path and still fully supported.

When does a 2019 certificate have to transition?

Roughly three years from publication, so late 2028 — but published dates differ by a month depending on the accreditation body, so confirm the exact one with your certification body rather than relying on a figure you read.

Can I reuse my 2019 questionnaire?

Not by renumbering the headings. The requirement and guidance boundaries moved, and privacy risk pivoted to risk to the individual, so several questions change substance rather than just reference.

Can I use this for a client?

Yes. Run one assessment per client organisation.

What happens to my answers?

They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.