ISO 27001 vs ISO 27701 stopped being a sequencing question in October 2025. For six years the answer was simple and slightly unsatisfying: you did ISO 27001 first, because ISO 27701 was an extension bolted onto it. The second edition removed that dependency, and most of the advice still circulating online was written before it did.
If you are deciding where a certification budget goes this year, or a customer has put both standards into a security questionnaire, this ISO 27001 vs ISO 27701 guide sets out what each one certifies, what genuinely overlaps, and how to choose without buying twice.
What this guide covers
- ISO 27001 vs ISO 27701: the short answer
- What changed in October 2025
- ISO 27001 vs ISO 27701 compared side by side
- Which one do you actually need?
- Where ISO 27001 vs ISO 27701 overlap in practice
- What ISO 27701 will not do
- If you already hold a 2019 certificate
- Frequently asked questions
- Getting the documentation together

ISO 27001 vs ISO 27701: the short answer
ISO/IEC 27001:2022 certifies an information security management system. Its subject is information of every kind — source code, pricing, contracts, customer records, anything the organization decides is worth protecting. Our guide to ISO 27001 covers that system in full.
ISO 27701 certifies a privacy information management system, or PIMS. Its subject is narrower and much more specific: personally identifiable information, and whether you process it lawfully, transparently, and in a way that lets the people it describes exercise their rights.
The working rule is short. ISO 27001 answers is our information protected? ISO 27701 answers is personal information handled properly? A locked filing cabinet settles the first question and tells you nothing at all about the second.
Since the 2025 edition you can certify either one without the other. Before it, the ISO 27001 vs ISO 27701 decision was not really a decision.
What changed in October 2025
ISO/IEC 27701:2025 — Information security, cybersecurity and privacy protection — Privacy information management systems — Requirements and guidance — was published in October 2025 as edition 2, running to 64 pages. It withdrew the 2019 edition.
Three changes drive the ISO 27001 vs ISO 27701 decision now:
- It is standalone. ISO’s own description is explicit: the requirements can be implemented as a stand-alone privacy information management system, no longer dependent on implementing ISO/IEC 27001 or ISO/IEC 27002. An accredited PIMS certificate can now sit on its own.
- It has its own management system clauses. The 2025 edition follows the harmonized structure, clauses 4 to 10 — the same skeleton as ISO 27001, ISO 9001 and every other modern ISO management system standard. Context, leadership, planning, support, operation, performance evaluation, improvement: a full set, not a supplement.
- It brought security controls inside. Annex A now holds three tables — controls for PII controllers, controls for PII processors, and information security controls that apply to both — with implementation guidance moved to Annex B. We break the tables down in our guide to the ISO 27701 controls.
The third point is the one that gets missed. A standalone standard cannot assume controls it does not contain, so the security controls ISO 27701 used to inherit from whatever ISO 27001 implementation sat underneath it had to be written into the standard itself.
ISO 27001 vs ISO 27701 compared side by side
| ISO/IEC 27001:2022 | ISO/IEC 27701:2025 | |
|---|---|---|
| What it certifies | Information security management system (ISMS) | Privacy information management system (PIMS) |
| Current edition | 2022, third edition | 2025, second edition, 64 pages |
| Subject matter | All information in scope | Personally identifiable information |
| Core question | Is it protected? | Is it processed lawfully and fairly? |
| Controls | Annex A: 93 controls in 4 themes — 37 organizational, 8 people, 14 physical, 34 technological | Annex A: three tables — controller controls, processor controls, shared security controls |
| Prerequisite | None | None since the 2025 edition (an ISO 27001 certificate was required under the 2019 edition) |
| Statement of Applicability | Mandatory under clause 6.1.3 | Applicability statement covering the Annex A tables that apply to your role |
| Role matters? | No | Yes — controller, processor, or both, determines which tables apply |
| Who typically asks for it | Enterprise procurement, security questionnaires, insurers | Controllers assessing processors, privacy-led procurement, DPO functions |
| Regulatory status | Not a legal requirement anywhere | Evidence of accountability; not a GDPR certification under Article 42 |
One figure is deliberately absent from that table: a headline control count for ISO 27701. Published tallies disagree, because subclauses can be counted more than one way — BSI’s guidance counts 34 controller controls, 21 processor controls and 31 shared controls, while other published counts are lower. Take the number from the copy of the standard you are certifying against, because that is the list your applicability statement has to answer.
Which one do you actually need?
Four situations cover most of the organizations weighing ISO 27001 vs ISO 27701.
Enterprise deals are stalling on security questionnaires. Go to ISO 27001. It is the certificate procurement teams name, the one insurers recognize, and the one that unblocks a vendor review. Privacy questions inside those questionnaires are usually answerable from an ISMS plus a competent privacy program — they rarely require a second certificate. Our ISO 27001 certification cost breakdown sets out what that route costs.
Personal data is the product. If you run an HR platform, a marketing data business, a health app or an ad-tech pipeline, privacy is your risk and privacy is what your buyers interrogate. Since 2025 you can go straight to ISO 27701 without an ISMS certificate first. Whether you should still depends on who is asking: if their questionnaire says “ISO 27001”, a PIMS certificate will not close that field for you.
You are a processor under pressure from controllers. Tables A.2 and A.3 are written for you — documented instructions, sub-processor engagement, assisting the controller with rights requests, return and disposal at the end of a contract. This is the clearest new use of the standalone route, because a processor’s obligations are contractual and specific, and a PIMS evidences them directly.
You already hold ISO 27001 and privacy keeps coming up. Extend rather than restart. The management system clauses are effectively shared, so the incremental work is the privacy controls, the role determination and the applicability statement — not a second internal audit program.
Where ISO 27001 vs ISO 27701 overlap in practice
The overlap is larger than the marketing on either side suggests, and it sits in three places.
The management system runs once. Clauses 4 to 10 are the harmonized structure in both standards. Interested parties, scope, leadership commitment, risk and opportunity planning, competence, documented information, internal audit, management review and nonconformity handling can be one set of processes serving two scopes. Duplicating them is the most common way organizations overspend on the ISO 27001 vs ISO 27701 pairing.
The security controls are the same controls. Where a shared control in ISO 27701’s Annex A corresponds to an ISO 27002 control you already operate, it is the same implementation. What you add is a scope statement — that the control covers the systems processing personal data. What you do not get to do is skip the evidence, because the auditor assessing the PIMS wants to see it operating on the PIMS scope.
Both need an applicability statement. ISO 27001’s Statement of Applicability is mandatory under clause 6.1.3 and has to justify inclusions and exclusions against all 93 Annex A controls. ISO 27701 needs the equivalent for the tables your role pulls in. Two documents, one discipline.
The failure mode to watch is scope drift. When both certificates are held, the ISMS scope and the PIMS scope are set at different times by different people and quietly diverge — and the gap between them is where an auditor finds systems processing personal data that nobody put inside the privacy system.
What ISO 27701 will not do
Three limits are worth stating plainly, because they change the ISO 27001 vs ISO 27701 answer and vendors are vague about them.
It is not GDPR certification. Certification under Article 42 GDPR requires a scheme approved by the competent supervisory authority, and ISO 27701 is not one. It is strong evidence of accountability that a regulator can weigh; it is not a legal shield, and no certificate makes you GDPR compliant. We set out the wider relationship in ISO 27001 vs GDPR.
It does not replace legal advice. Lawful basis, international transfer mechanisms and retention periods are legal determinations. The standard requires you to make them and record them; it does not tell you what the right answer is in your jurisdiction.
It does not answer a question that asked for ISO 27001. Procurement fields are literal. If the requirement says ISO 27001, a PIMS certificate is a good story and a failed checkbox.
If you already hold a 2019 certificate
This is where the ISO 27001 vs ISO 27701 question has a deadline attached. The 2019 edition is withdrawn. Certification bodies are working to a transition deadline of 31 October 2028 for certificates issued against it, after which they lapse — confirm the exact date and audit slot with your own certification body rather than relying on a blog, including this one, because bodies publish slightly different internal milestones.
The transition is not a re-badge. The clause structure is new, the controls are reorganized, and the applicability statement has to be rebuilt against the 2025 Annex A. Our guide to ISO 27701:2025 vs 2019 walks the changes and the eight steps.
Frequently asked questions
Do I still need ISO 27001 before ISO 27701?
No. Since the 2025 edition, ISO 27701 can be implemented and certified as a standalone management system. An ISO 27001 certificate was a prerequisite under the 2019 edition and no longer is.
Is ISO 27001 vs ISO 27701 an either/or choice?
Not usually. Most organizations processing personal data at any scale end up with both, because customers ask different questions in different procurement processes. The choice is about sequence and budget, not exclusivity.
Can one audit cover both?
Yes, and it usually should. Certification bodies run combined or integrated audits against both standards, which shares the management system sampling and cuts audit days. Ask for it when you request a quote rather than after the first certificate is issued.
Does ISO 27701 make us GDPR compliant?
No. It gives you the management system, records and control set that make compliance demonstrable and repeatable, but GDPR compliance is a legal state assessed against the regulation, and ISO 27701 is not an approved Article 42 certification mechanism.
Which is more work?
ISO 27001 is broader; ISO 27701 is deeper in a narrow area. If you are starting from nothing, ISO 27001 is the bigger build because it covers all information and all 93 Annex A controls. If you already run an ISMS, adding a PIMS is a fraction of that effort — which is why the ISO 27001 vs ISO 27701 order you choose changes the total bill.
Getting the documentation together
Whichever way the ISO 27001 vs ISO 27701 decision goes, the work an auditor sees is documented: policies, procedures, registers, records and an applicability statement that survives challenge. Our ISO 27001 Toolkit is 165 editable templates covering the ISMS end to end, and our ISO 27701 Toolkit covers the PIMS side with 75+ templates. Both are $99, both are editable, and both are built to be filled in rather than admired.
If you are running the two together, build one management system and give it two scopes. That is the version of the ISO 27001 vs ISO 27701 answer that costs the least and audits the best.