ISO published an updated version of ISO 27701 in October 2025, and the change is bigger than a routine revision. The standard is now a standalone certification. Previously, an organization needed ISO 27001 in place before it could pursue ISO 27701. That requirement no longer applies.
For organizations handling personal data, this removes a real barrier. Organizations can now certify their privacy management on its own terms, independent of their broader information security certification path. An organization that never pursued ISO 27001, whether because it wasn’t relevant to their business or because the investment didn’t make sense, can now build a certified privacy management system without that step first.
What Changed in ISO 27701:2025?
The 2025 revision restructures more than the entry requirements. Annex A, the control set, is now organized into three separate tables: one covering controls for organizations acting as PII controllers, one for organizations acting as PII processors, and one covering information security controls that apply to both roles. A new Annex B provides implementation guidance, and Annex F gives a direct correspondence between the 2019 and 2025 control sets for organizations working through the migration.
One catch: because ISO restructured the control set rather than simply renumbering it, a control that satisfied the 2019 edition doesn’t automatically satisfy its 2025 counterpart. Organizations migrating need to rebuild their statement of applicability against the new Annex A structure rather than carrying the old one forward as-is.
When Do You Need to Migrate to ISO 27701:2025?
Organizations already certified under the 2019 version of ISO 27701 have until October 31, 2027 to complete migration to the 2025 version. After that date, a certificate still on the 2019 standard is no longer valid. Reinstatement at that point requires a full new initial certification audit against the 2025 edition, not a lighter transition process.
New certifications issued after October 31, 2026 must already be against the 2025 version, so any organization pursuing 27701 for the first time from that point forward is certifying directly against the current standard.
How Long Does the ISO 27701 Migration Take?
Timing the migration well matters operationally, not just administratively. Accreditation rules set a minimum additional audit time: half a day when the transition is paired with a scheduled recertification audit, and a full day when it’s paired with a surveillance audit or handled as a standalone transition audit. The actual time depends on scope, sites, and complexity, but pairing with recertification is the only path that gets the shorter minimum.
Why ISO 27701 Matters for AI and PII Compliance
Most of the current conversation around AI and compliance centers on the EU AI Act. Less attention goes to the personal data questions that come with AI systems themselves, even though those questions often surface earlier in a product’s lifecycle than broader AI governance requirements do. The 2025 revision reflects this directly, expanding its coverage to address AI-driven data processing and cross-border data transfers, both increasingly common wherever AI features touch personal data.
Any organization building or deploying AI features that touch personal data is already operating in privacy management territory, whether or not that’s been formally recognized internally. A standalone ISO 27701 certification gives that work a clear, independently assessed structure, separate from and no longer dependent on a broader information security certification.
What Should Organizations Do Now?
For organizations already certified under 27701:2019, the priority is timing the migration around a recertification audit where possible, since that’s the only path with the reduced audit-time minimum. For organizations that haven’t pursued 27701 yet, especially ones with AI or GDPR exposure, the standard is now more directly accessible than it was before 2025, without the ISO 27001 prerequisite that previously stood in the way.
Have Questions About Your Own Timeline?
If you’re currently certified under ISO 27701:2019, or considering ISO 27701 for the first time, our team is happy to talk through what the transition looks like for your organization specifically. Get in touch here to start that conversation.