ISO & Compliance Implementation

ISO/IEC 27701:2025: What Standalone PIMS Certification Changes

Most compliance teams still think of ISO/IEC 27701 as “the privacy add-on to ISO 27001.” The October 2025 revision just made that assumption outdated.

01

What actually changed

ISO/IEC 27701:2025 was published on 10 October 2025, superseding the 2019 edition — and the headline change is…

02

Why standalone certification matters

For organizations that want privacy certification without carrying a full ISO 27001 ISMS, this removes…

03

How to plan the transition

Industry guidance points to roughly a three-year transition window — here’s how to use it.

What actually changed

ISO/IEC 27701:2025 was published on 10 October 2025, superseding the 2019 edition. The single biggest change is structural: 27701 is now a stand-alone management system standard. Under the 2019 edition, it only existed as an extension layered on top of an ISO/IEC 27001 Information Security Management System (ISMS) — you couldn’t certify to 27701 without also certifying, or certifying concurrently, to ISO 27001. Under the 2025 edition, an organization can certify a Privacy Information Management System (PIMS) independently, or keep an integrated PIMS + ISMS if it already holds ISO 27001. The ISO 27001 linkage is now optional, not mandatory.

That structural shift runs through the whole document. Clauses 4–10 were rewritten as full, self-contained management system clauses — previously they were only extension and addition clauses riding on ISO 27001’s clause numbering — so organizations transitioning need to revise internal document references and numbering accordingly. Controls were reorganized and aligned with ISO/IEC 27002:2022: roughly 31 controller-specific controls, 18 processor-specific controls, and about 29 shared controls.

New content was added too: a threat-intelligence control, expanded cloud service and ICT supply-chain governance requirements, and a new clause addressing whether climate change is relevant to the organization’s context. Privacy-specific risk assessment now references ISO/IEC 27557, distinguishing organizational impact from individual (data subject) impact. Regulatory mapping has also broadened beyond EU GDPR to explicitly reference frameworks like CPRA (California), LGPD (Brazil), and PDPA (various APAC jurisdictions).

STEP 01 Gap Assessment Against ISO/IEC 27701:2025 STEP 02 Update Documentation Clause & control renumbering STEP 03 Confirm Roles SoA, controller / processor status STEP 04 Coordinate Transition Audit With your certification body
The practical transition path industry guidance points to — gap assessment first, certification-body coordination last.

Why standalone certification matters

For organizations that want privacy certification but aren’t pursuing — or don’t want to maintain — a full ISO 27001 ISMS, this removes a real barrier that existed under the 2019 edition. A standalone PIMS certification is now a legitimate destination on its own, not a conditional add-on. For organizations that already hold ISO 27001, nothing is lost: an integrated PIMS + ISMS remains fully supported, and may still be the more efficient path where the two management systems share processes, risk registers, and audit cycles.

How to plan the transition

Industry guidance points to roughly a three-year transition period, with certification to the 2019 edition expected to wind down by around October 2028. Certification bodies are still finalizing their exact transition audit procedures, which is itself a reason to start early rather than wait for every detail to settle. A gap assessment against the 2025 text, followed by updates to governance documents and the Statement of Applicability, gives an organization time to confirm its controller/processor role under the new structure and train staff and internal auditors on the revised terminology before scheduling the transition audit itself.

Free download · PDF

Get the complete ISO/IEC 27701:2025 PIMS Readiness Checklist

Seven checks covering what changed and how to plan the transition, with a self-scoring sheet so you know what to fix first.

  • Printable checklist for your team and leadership
  • Scoring by section, so you know what to fix first
  • Option of a free 30-minute gap review with our practitioners

VVnT SeQuor · ISO 9001 & ISO 27001 certified · IAAP Organizational Member

Where should we send it?

All fields are required unless marked optional.

Enter your full name.

We'll email the PDF here.

Enter a valid email, like name@company.com.

Enter your company name.

Select your role.

When do you need to be compliant? (optional)

No spam. One-click unsubscribe.

Check your inbox

Your checklist is on its way to your email. If it hasn't arrived in 5 minutes, check your spam folder.

Want a second pair of eyes on your answers?

Book a free 30-minute gap review

Frequently asked questions

Is ISO/IEC 27701:2025 the same as ISO 27001?

No. ISO/IEC 27701 is a dedicated Privacy Information Management System (PIMS) standard. Under the 2019 edition it only existed as an extension layered on an ISO/IEC 27001 ISMS, so you couldn’t certify to it without also certifying to ISO 27001. The 2025 edition rewrote it as a stand-alone management system standard, so a PIMS can now be certified independently — though an integrated PIMS + ISMS is still fully supported for organizations that already hold ISO 27001.

Do organizations certified to the 2019 edition need to act immediately?

Not immediately. Industry guidance points to roughly a three-year transition period, with certification to the 2019 edition expected to wind down by around October 2028. Certification bodies are still finalizing their exact transition audit procedures, so there’s time to plan — but starting the gap assessment early avoids a rushed transition audit as the window closes.

What’s the single biggest practical change in the 2025 edition?

Standalone certifiability is the headline change, but it comes bundled with a reorganized control set aligned to ISO/IEC 27002:2022 (roughly 31 controller-specific, 18 processor-specific, and 29 shared controls), plus new content — a threat-intelligence control, expanded cloud and ICT supply-chain governance requirements, and a new clause on whether climate change is relevant to the organization’s context.