Get Demo
↑

ISO 27701:2025 — What Changed and the Move to a Standalone Standard

ISO/IEC...

Published: September 2026 Compliance · Privacy 8–12 min read

ISO/IEC 27701:2025 was published on 14 October 2025. The headline change: PIMS is no longer framed only as an extension of ISO 27001/27002. It is a standalone Privacy Information Management System standard with requirements and guidance.

Related: Certification · Explained.

Publication fact: ISO/IEC 27701:2025 — published 14 October 2025. Organisations can pursue PIMS certification without requiring ISO 27001 as a prerequisite under the 2025 edition.

What Changed

Transition

Certification and accreditation bodies commonly describe an approximately three-year transition from publication—often cited through about October 2028. Confirm the exact end date and dual-certificate rules with your accredited CB; treat the window as accreditation-path guidance, not a separate legal mandate from ISO.

What To Do Now

  1. Ask your CB which edition they will audit next surveillance/recertification
  2. Remap your SoA to 2025 structure
  3. Decide whether to keep ISO 27001 for security buyers even if PIMS no longer requires it

Remap Your SoA for 2025

Align evidence objects before your next CB surveillance window.

Frequently Asked Questions

When was ISO 27701:2025 published?

14 October 2025.

Is the transition exactly three years?

Bodies commonly describe ~3 years from publication (often through ~October 2028). Use your CB’s written transition plan as authoritative for your certificate.

Must we drop ISO 27001?

No. Many keep both. 27001 is optional for 2025 PIMS certification, not forbidden.

Requirements · Checklist · CSA Privacy

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!