ISO/IEC 27001:2022 covers an information security management system. ISO/IEC 27701:2025 covers a privacy information management system for organisations acting as controllers or processors of personal information.
You do not need ISO/IEC 27001 certification simply to use ISO/IEC 27701:2025. ISO confirms that the 2025 privacy standard is an independent management system standard and can be used alone. Whether your organisation needs both depends on the assurance you need to provide, the information you handle and the requirements of your customers.
What is the difference between ISO 27001 and ISO 27701?
ISO/IEC 27001 addresses risks to the confidentiality, integrity and availability of information. That includes personal information, but also information such as financial records, intellectual property and customer business data.
ISO/IEC 27701 focuses on managing personally identifiable information. Its requirements and guidance are designed for controllers and processors, supporting accountable decisions about how personal information is processed.
The distinction is between information security and privacy management. They overlap, but they are not interchangeable.
Does ISO 27701:2025 require ISO 27001?
No. ISO describes ISO/IEC 27701:2025 as an independent management system standard. It can be used alone.
The year matters. Advice that treats ISO 27701 only as an extension to an existing information security management system should be checked against the 2025 edition, rather than carried forward without review.
An organisation with an existing ISO/IEC 27001 system can still align its privacy management with that system. Independence does not prevent integration.
When might you need ISO 27001?
Consider ISO/IEC 27001 when you need to manage information security across your business or demonstrate that management system to customers and other interested parties.
A customer may expressly ask for ISO/IEC 27001 certification during procurement. A privacy certificate should not be assumed to satisfy that request. Read the requested standard, certified scope and any other conditions before choosing a certification path.
When might you need ISO 27701?
Consider ISO/IEC 27701 when your priority is accountable management of personal information and you need to demonstrate the privacy management system behind that work.
That can be relevant where you determine how personal information is processed, process it for clients, or do both across different activities. Your controller and processor roles, processing activities and dependencies should be clear within the proposed scope.
When does using both make sense?
Both may be useful when customers need information security assurance and privacy assurance, or when your organisation wants to manage those related responsibilities together.
Shared management arrangements can support that approach. You still need to address each standard's requirements and be clear about the scope being assessed. Do not assume that holding one certificate automatically demonstrates conformity to the other standard.
Does ISO 27701 certification prove compliance with privacy law?
Certification concerns the management system within its certified scope. It is not a legal compliance opinion or a guarantee that privacy incidents cannot occur.
Privacy obligations still need to be identified and addressed for the activities and jurisdictions relevant to your organisation. Certification and legal advice answer different questions.
How should you choose your certification scope?
Start with the assurance request you are trying to answer. Identify:
- The standard and edition requested by customers or other parties.
- The services, activities and locations that need to be included.
- The information handled and the personal information processing involved.
- Your controller and processor roles, including work performed by suppliers or other parties.
- The management systems already in place and the evidence they produce.
Use that information to discuss the proposed scope before an audit is planned. The right choice is the standard, or combination of standards, that addresses your actual assurance need.
Discuss your proposed scope
Send ACS your proposed scope, locations and approximate headcount. We can explain what an ISO/IEC 27001 or ISO/IEC 27701 engagement would involve and what evidence to prepare.
Related information:
