Skip to main content
—
Framework library
Framework module · iso-27701-2025

ISO/IEC 27701

The certifiable privacy information management system. The 2025 second edition made it standalone — an organization no longer needs a certified ISMS first.

2025 · ISO/IEC 27701:2025 · published 2025-10-14

Standing today
Directory entry

00Answer

from the registry record
What is ISO/IEC 27701?
The certifiable privacy information management system. The 2025 second edition made it standalone — an organization no longer needs a certified ISMS first.
Who does ISO/IEC 27701 apply to?
ISO/IEC 27701 applies to all sectors, global, per ISO/IEC 27701:2025.
What is the current version of ISO/IEC 27701?
The current edition is 2025, issued by ISO/IEC 27701:2025 and published 2025-10-14. Source: https://www.iso.org/standard/27701.
What does an assessment under ISO/IEC 27701 require?
No control catalog has been ingested for ISO/IEC 27701 yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

ISO/IEC 27701 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Licensed standard — purchase from ISO or a national member body and obtain software-use rights before verbatim ingestion.

02Registry record

checked 2026-08-30
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
PIMS requirements · Controller guidance · Processor guidance
Applies to
all sectors · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-30

03Version ledger

2 editions
2019Supersededdate not published
2025Current edition · supersedes 20192025-10-14

05Change history

06Related frameworks

scored from registry facts
  1. GDPRRegulation (EU) 2016/679

    Also applies to all sectors · The EU's baseline for processing personal data — lawful basis, data-subject rights, controller and processor duties, and cross-border transfers.

  2. Texas Data Privacy and Security ActHB 4 (Texas Business and Commerce Code Chapter 541)

    Also applies to all sectors · Texas's comprehensive consumer-privacy statute, pulled out of the generic state-privacy bundle because of its own enforcement record — the Texas AG has reached the two largest single-state privacy settlements in US history — and because TRAIGA now amends it with AI-specific processor duties.

  3. UK GDPRUK GDPR + DPA 2018, as amended by DUAA 2025 (in force via Commencement No. 6, SI 2026/82)

    Also applies to all sectors · The UK's post-Brexit data protection regime, materially reshaped by the Data (Use and Access) Act 2025 — new recognised legitimate interests, narrower automated-decision protections, and a pausable DSAR clock. The core amending provisions were brought into force by the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82), effective 2026-02-05.

  4. Also applies to all sectors · Cloud-specific information security guidance for both cloud customers and providers, extending ISO/IEC 27002 with shared-responsibility and cloud-control guidance. It is guidance, not a standalone certification or a claim about ControlFrame's cloud environment.

ISO/IEC 27701 | ControlFrame