Skip to content
SecuriFii

Choosing

ISO 27701 no longer needs ISO 27001 underneath it — and what that changes

Until recently the answer was a flat no: a privacy information management system could only be certified as an extension to a certified ISMS. The 2025 edition changed that, and it changes the calculation for any organisation whose customers are asking about privacy rather than security generally.

Facts checked2026-09-11

What changed between the editions

2019 edition2025 edition
StandingAn extension to ISO/IEC 27001 and 27002.A standalone management system standard.
PrerequisiteA certified ISMS was required underneath it.None. It can be implemented and certified on its own.
StructureSupplemented the ISO 27001 clauses with privacy requirements.Follows ISO’s harmonised high-level structure, clauses 4 to 10.
Who it suitsOrganisations already committed to ISO 27001.Also organisations whose driver is privacy alone.

ISO/IEC 27701:2025 was published on 14 October 2025. A transition period for 2019-edition certificates runs into October 2028 — the precise cut-off and mechanics come from the IAF transition requirements, and published summaries differ by a few weeks, so confirm the date with your certification body rather than relying on a blog.

What actually changed, and why it matters

The 2019 edition of ISO/IEC 27701 was explicitly an extension. It took the ISO/IEC 27001 clauses and added privacy requirements on top, which meant a privacy information management system was not a thing you could hold on its own — you needed a certified ISMS underneath, and the privacy certificate sat on that foundation.

The 2025 edition, published on 14 October 2025, restructured it into a standalone management system standard following ISO’s harmonised high-level structure. Its application no longer depends on implementing ISO/IEC 27001 or 27002, and it can be certified independently.

The practical effect is that privacy stopped being an add-on purchase. An organisation can now build and certify an auditable privacy programme without first standing up a full information security management system — which is a real change for firms whose commercial pressure comes from data protection questions rather than from security questionnaires.

Who should actually take the standalone route

The clearest case is an organisation where privacy is the obligation customers keep raising and information security certification is not being asked for. Some sectors are like this — research, analytics, health-adjacent services, marketing technology — where the questions arriving are about lawful basis, retention, rights handling and cross-border transfer rather than about ISMS governance.

The second case is an organisation that is a processor for European or Indian customers and is being asked to demonstrate privacy capability specifically. A PIMS produces the records of processing, the rights-handling process, the retention decisions and the processor arrangements that those questions are actually about.

The case against is simpler than it looks: if your buyers are asking for ISO 27001, standalone 27701 does not answer them. It is a privacy certificate, and a security questionnaire wants a security certificate. Certifying the wrong one because it was newly available would be the same mistake as choosing between SOC 2 and ISO 27001 by preference rather than by pipeline.

When doing both is still the cheaper answer

If you already hold ISO/IEC 27001, adding a PIMS remains substantially cheaper than either certificate alone, and the standalone change does not alter that.

The reason is that management system machinery is shared in substance even though the standards are now structurally independent. You have a scope, a risk method, document control, internal audit, management review and corrective action already running. What a PIMS adds on that base is mostly the privacy-specific work — role determination, records of processing, rights handling, retention and deletion, transfer arrangements, impact assessments — rather than another layer of governance scaffolding.

Conversely, if you know both are coming, doing them together is cheaper than doing them consecutively for the same reason it is with SOC 2: one management system, one internal audit programme, one set of evidence habits, assessed against two sets of requirements.

The decision that shapes everything inside it

Whether you are a controller or a processor, per processing activity. Privacy obligations divide along that line, and 27701 is built around the distinction — the requirements that apply to you depend on which role you hold for which data.

Most organisations are both, simultaneously, for different data. You are a processor for the personal data your customers put into your platform, and a controller for your own employee records, your marketing list, and the account details of your customers’ staff who log in to use your service.

Settle that first and write it down, because getting it wrong is expensive in both directions. Accepting controller obligations you do not hold creates duties you cannot discharge; accepting processor terms for data you actually control leaves a real obligation unowned. This is also the first thing an auditor will want to see reasoned rather than asserted.

What it does not do

It does not make you compliant with any law. No certificate does — compliance with the GDPR or the DPDP Act is a legal conclusion reached against those statutes, and that remains a question for a lawyer looking at your specific processing.

What certification does is build and evidence the machinery those laws assume you have: knowing what personal data you hold and why, being able to find one individual’s data across your systems, handling a rights request inside a deadline, deleting what you no longer need, and being able to show all of it happened.

That is the difference between demonstrating compliance and excavating it under time pressure when a customer or a regulator asks — and it is why customers accept a 27701 certificate as an answer even though it does not, and cannot, certify compliance with their law.

Common questions

Can we certify ISO 27701 without ISO 27001?

Yes, since the 2025 edition. ISO/IEC 27701:2025, published on 14 October 2025, is a standalone management system standard whose application no longer depends on ISO/IEC 27001 or 27002. Under the 2019 edition it could only be certified as an extension to a certified ISMS.

What changed in ISO 27701:2025?

It became standalone and adopted ISO’s harmonised high-level structure across clauses 4 to 10, aligning it with other management system standards rather than supplementing the ISO 27001 clauses.

When do 2019-edition certificates stop being valid?

A transition period runs into October 2028. The exact cut-off and the mechanics come from the IAF transition requirements, and published summaries differ by a few weeks — so confirm the date with your certification body rather than trusting a secondary source, including this one.

Should we do 27701 standalone or alongside ISO 27001?

Standalone if privacy is what your customers are actually asking about and nobody is asking for ISO 27001. Alongside if you already hold ISO 27001, since the management system work is shared and the marginal cost is mostly the privacy-specific requirements. Certifying the privacy standard will not answer a security questionnaire.

Does ISO 27701 make us GDPR or DPDP compliant?

No. Compliance with a statute is a legal conclusion, not a certificate. ISO/IEC 27701 builds and evidences the records of processing, rights handling, retention decisions and processor arrangements those laws assume — which is what makes demonstrating compliance straightforward rather than archaeological.

What is the first decision in a PIMS?

Whether you are a controller or a processor, determined per processing activity and written down. The requirements that apply depend on it, and most organisations are both at once — a processor for customer data, a controller for their own employee and marketing data.

The bottom line

You can now go straight at a PIMS, and should if privacy is the question your customers are raising. If you already hold ISO 27001, it remains the cheaper starting point — and either way, settle controller versus processor per processing activity before anything else.

Related insights