What changed
The structure has been aligned more closely with ISO/IEC 27001:2022 and with the ISO/IEC 27002 control set, which makes it easier to run one integrated system rather than two parallel ones.
What to do
- Check which edition your current certificate references.
- Ask your certification body when they will be ready to audit to the 2025 edition.
- Align the privacy controls with your ISO/IEC 27001:2022 documentation.
- Plan the transition alongside a surveillance audit to reduce cost.
What this means for you
If you already hold a 2019-edition certificate, the transition is not urgent this year — but it is cheaper to do alongside a surveillance audit than as a standalone project in 2028.
Sources
ISO/IEC 27701:2025 standard page — iso.org
UKAS and SAC transition notices — ukas.com, sac-accreditation.gov.sg