Key Takeaways
- ISO/IEC 27701:2025 replaced the 2019 edition on 14 October 2025 and is now a standalone standard.
- An ISO 27001 certificate is no longer a prerequisite for certifying a Privacy Information Management System.
- Certificates issued to the 2019 edition remain valid until October 2028, then lapse.
ISO/IEC 27701:2025 replaced the 2019 edition on 14 October 2025, and the change is structural rather than cosmetic: ISO 27701 is no longer an extension to ISO 27001. It is now a standalone management system standard, which means a Privacy Information Management System (PIMS) can be built and certified on its own, without an ISO 27001 certificate underneath it. If you hold a certificate issued against the 2019 edition, it stays valid until October 2028 and then lapses.
That single change cascades into everything else. Under the 2019 edition ISO 27701 could assume you already ran an ISO 27001 information security management system, so it borrowed the scope, the risk process, the internal audit programme and the security controls from it and added only the privacy parts. A standalone standard cannot assume any of that, so the 2025 edition brings the whole management system inside itself — and brings a set of information security controls with it.
This guide covers what changed, what your existing documentation carries over, what you have to build, and how long the transition realistically takes.
ISO 27701:2025 vs 2019 at a glance
| ISO/IEC 27701:2019 | ISO/IEC 27701:2025 | |
|---|---|---|
| Status | An extension to ISO/IEC 27001 and ISO/IEC 27002 | A standalone management system standard |
| ISO 27001 required? | Yes — certification only alongside a valid ISO 27001 certificate | No — a PIMS can be certified in its own right |
| Title | “Security techniques — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management” | “Information security, cybersecurity and privacy protection — Privacy information management systems” |
| Controls | Annex A for PII controllers, Annex B for PII processors, layered on the ISO 27002 controls inherited from your ISMS | One consolidated Annex A: A.1 controller controls, A.2 processor controls, A.3 information security controls |
| Security controls | Inherited from the underlying ISMS | Included in the standard, because there may be no ISMS to inherit from |
| Management system | Borrowed from ISO 27001 | Its own clauses 4 to 10 |
| Mapping help | — | Annex F maps every 2019 control to its 2025 equivalent |
| Transition | Certificates valid until October 2028 | Current edition |
Is your ISO 27701:2019 certificate still valid?
Yes, until October 2028, provided you keep meeting the normal surveillance requirements. You are not in breach of anything today and there is no need to panic.
You should not leave it late, though, and the reason is capacity rather than compliance. Certification bodies have their own earlier deadlines for retiring 2019 audits, and as the date approaches audit slots compress. The organisations that struggle will be the ones trying to book a transition audit in 2028 alongside everyone else. Fold it into a scheduled surveillance or recertification visit in 2026 or 2027 instead, and it costs you additional audit days rather than a separate engagement.
Ask your certification body for their cut-off date now. It will be earlier than yours.
Which situation are you in?
You hold a 2019 certificate
Your transition is mostly re-mapping. You already run a management system, because your ISO 27001 ISMS supplied one, so the work concentrates on moving control references to the new Annex A numbering and confirming that what the ISMS covered is properly documented inside the PIMS scope rather than only inside the ISMS scope.
You are part-way through implementing the 2019 edition
Stop and re-baseline against the 2025 edition. There is no value in certifying against a standard with a fixed end date, and your certification body may not be able to offer a 2019 audit for much longer. The privacy artefacts you have already drafted — privacy notices, request handling procedures, records of processing, processor agreements — carry across largely unchanged. It is the structure around them that moves.
You have no ISO 27001 certificate and never wanted one
This is the group the revision was written for. If your obligations are driven by privacy law — the GDPR, the UK regime, CCPA and CPRA, India’s DPDP Act — rather than by customers demanding security assurance, you can now certify a PIMS directly. Previously you had to implement and certify an entire ISMS first, which for many organisations was a disproportionate price of entry. That barrier is gone.
You will need to build the full management system and the Annex A.3 information security controls, because you have no ISMS to inherit them from. That is more work than a 2019 extension would have been — but it is work you now do once, for one certificate.
What carries over and what you have to rebuild
| Area | Status | What to do |
|---|---|---|
| Privacy notices and transparency material | Carries over | Re-reference only. Driven by privacy law, not ISO numbering. |
| PII principal request handling | Carries over | Procedure, forms and response letters all stand. |
| Records of processing | Carries over | Check you hold both controller and processor records where you act as both. |
| Consent and lawful basis records | Carries over | Re-reference only. |
| Processor agreements and due diligence | Minor edits | Point any security criteria at Annex A.3 rather than ISO 27002. |
| Control references throughout | Re-map | Use Annex F. Do it in one pass or cross-references drift. |
| Statement of Applicability | Rebuild | Must now cover the consolidated Annex A, including A.3. |
| PIMS scope and context | Build | Previously inherited from the ISMS scope; now stands alone. |
| Privacy risk methodology | Build | Must score impact on the PII principal, not only on the organisation. |
| Internal audit and management review | Build | Can be combined with existing ISMS activity, but must demonstrably cover the PIMS. |
| Information security controls | Build | Only if you have no ISO 27001. Otherwise map your existing controls to A.3. |
The documentation gap most organisations find late
If your ISO 27701 documentation was assembled as an add-on to an ISMS — which is exactly what the 2019 edition encouraged — then it probably contains no scope statement, no risk assessment methodology, no Statement of Applicability, no internal audit procedure and no management review records of its own. It never needed them. The ISMS had all of that.
Under a standalone standard it does need them. Before you book a transition audit, check whether you can produce each of the following as a PIMS document rather than as an ISMS document that happens to mention privacy:
- A PIMS scope statement, and a record of interested parties and their privacy requirements
- A privacy policy, and documented roles and responsibilities including the privacy lead or DPO
- A privacy risk assessment methodology, its results, and a risk treatment plan
- A Statement of Applicability covering every control in the consolidated Annex A
- Privacy objectives, competence records and a communication plan
- A privacy impact assessment process and its results
- Monitoring results, internal audit reports and management review minutes
- Nonconformity and corrective action records
This is the part that catches people. The control re-mapping is mechanical once you have Annex F; assembling a management system you have never separately documented is not.
How to run the transition in eight steps
- Buy the standard. You cannot plan the transition without Annex F, which maps every 2019 control to its 2025 equivalent.
- Decide your certification model. Standalone PIMS, or integrated with an existing ISO 27001 ISMS? This determines how much you build versus map.
- Run a gap analysis twice. Once at control level using Annex F, once at management-system level against clauses 4 to 10. The second usually finds more.
- Re-map control references in one pass across every document, updating internal cross-references as you go.
- Rebuild the Statement of Applicability against the consolidated Annex A, with a justification for every inclusion and exclusion.
- Fill the management system gaps — scope, risk methodology, internal audit, management review. Reuse ISMS equivalents where you have them.
- Run the system before you are audited. You need at least one internal audit and one management review covering the PIMS.
- Book the transition audit into a scheduled surveillance or recertification visit.
For an organisation with a working 2019 PIMS, this is a matter of months rather than years. Most of it is mapping and gap-filling, not fresh implementation.
Five mistakes to avoid
- Treating it as a renumbering exercise. The control mapping is the easy half. The management system requirements catch organisations whose PIMS was built as an ISMS add-on.
- Waiting until 2028. Certification bodies must complete their own transition well before your deadline, and audit capacity tightens as the date nears.
- Assuming ISO 27001 evidence automatically covers the PIMS. It can, but only if the scope, the risk assessment and the audit programme demonstrably include privacy. An auditor will ask to see that explicitly.
- Renumbering twice. Do the re-mapping once, after you have Annex F, and update every cross-reference in the same pass.
- Forgetting the controls you never had to write. Privacy by design and by default, retention and disposal, and personal data breach notification are commonly thin or missing in documentation built as a 2019 extension.
Frequently asked questions
Do I still need ISO 27001 to certify to ISO 27701?
No. That is the single biggest change in the 2025 edition. A Privacy Information Management System can now be established and certified on its own. If you already hold ISO 27001, running the two together remains the most efficient approach, because they share the same clause structure and you can operate one set of audits and reviews for both.
When exactly does my 2019 certificate expire?
Certificates issued against ISO/IEC 27701:2019 cease to be valid in October 2028, three years after publication of the 2025 edition. Your certification body will have an earlier internal deadline for offering 2019 audits, so confirm both dates with them rather than working to the outer limit.
How much of our existing documentation survives?
More than most people expect. Privacy notices, data subject request procedures, consent records, records of processing and processor agreements are driven by privacy law and carry across with re-referencing only. What has to be built is the management system around them, and only if you were relying on an ISMS to supply it.
What is Annex F and why does it matter?
It is the correspondence table in the 2025 edition mapping every control in the 2019 version to its equivalent in the new consolidated Annex A. It turns the re-mapping from a judgement exercise into a mechanical one, which is why buying the standard before planning the transition saves far more time than it costs.
Can we transition at our normal surveillance audit?
Usually yes, and it is the cheapest route. Certification bodies commonly allow the transition to be assessed at a scheduled surveillance or recertification visit rather than as a separate engagement. Tell them early, because the visit may need additional audit days.
We are a processor, not a controller. Does anything change?
The obligations themselves are broadly stable, but they now sit in Annex A.2 rather than in a separate Annex B, and the information security expectations that used to come from ISO 27002 now sit in Annex A.3. If your security posture was evidenced by pointing at an ISO 27001 certificate, check that it maps cleanly to A.3.
The practical takeaway
ISO 27701 stopped being an add-on and became a standard in its own right. For organisations already certified, that means a transition project measured in months, most of it re-mapping. For organisations that avoided ISO 27701 because they did not want to certify an ISMS first, it means the door is now open.
The deadline is fixed and it is not going to move. Book the transition into a surveillance visit in 2026 or 2027, buy the standard so you can work from Annex F, and start by checking whether your PIMS has a scope, a risk methodology and an audit programme of its own — because if it does not, that is where the time will go.
If you want the background on what a PIMS is and what the standard requires, start with our complete ISO 27701 guide. If you would rather work from prewritten documentation than a blank page, the ISO 27701 Toolkit gives you editable Word and Excel templates aligned to the 2025 edition, and Which ISO toolkit do I need? will help if you are weighing it against the other standards you have to meet.