ISO/IEC 27017:2026 & 27018:2025 — Cloud Security and Privacy

Cloud-specific security and privacy control extensions to ISO 27001. They settle who is responsible for what between provider and customer.

ISO and IEC. Certified as an extension to an ISO/IEC 27001 scope by accredited certification bodies. Current editions are ISO/IEC 27017:2026 (second edition) and ISO/IEC 27018:2025 (third edition), both aligned to the ISO/IEC 27002:2022 control set.

What it is

ISO/IEC 27017 and ISO/IEC 27018 are cloud-specific control sets that extend an ISO/IEC 27001 information security management system. Neither is a standalone management system standard: both are certified as an extension to the 27001 scope, not instead of it.

ISO/IEC 27017 — cloud security

It applies the ISO/IEC 27002:2022 controls to the provision and use of cloud services, with cloud-specific implementation guidance for both providers and customers. It adds controls for the matters unique to cloud: shared roles and responsibilities between provider and customer, segregation in virtual computing environments, and detection and prevention of unauthorised use of cloud services, plus guidance on monitoring cloud service activity.

ISO/IEC 27018 — personal information in public cloud

It applies where an organisation processes personal information as a processor on behalf of its customers, and covers consent and choice, restrictions on using data for the provider's own purposes such as marketing, disclosure to law enforcement, data location transparency, and obligations on return and deletion. The 2025 edition realigns the controls to ISO/IEC 27002:2022 and adds extended implementation guidance.

The recurring theme in both is the shared responsibility boundary — making explicit which control each party operates. That boundary is precisely where most real cloud security failures occur, because both sides assumed the other had it.

Who it's for

Organisations on either side of a cloud service relationship where data sensitivity makes the boundary matter.

SaaS and cloud-native platforms

Whose customers ask how tenant data is segregated, who can access it administratively, and what happens to it when the contract ends. These questions appear in nearly every enterprise security review.

Cloud providers holding personal information as a processor

Where 27018 provides the recognised control set for demonstrating that customer data is not used for the provider's own purposes.

Organisations with Australian data residency commitments

Whether contractual, regulatory or driven by government-adjacent work, 27018 supplies the documented controls behind the claim.

Organisations already certified to ISO 27001

Whose buyers are pressing for cloud-specific assurance beyond the base certificate.

Why implement it

  • It resolves the shared responsibility argument. The most common cause of cloud security gaps is both parties assuming the other handled it. These standards force the boundary to be written down and agreed.
  • It answers cloud-specific due diligence. Tenant isolation, administrative access, data location and deletion on termination — the controls address exactly the questions enterprise questionnaires ask.
  • It sits on the existing certificate. Because they extend an ISMS, they are added to the certification scope without a separate programme or a separate audit.
  • It supports data sovereignty positioning where onshore residency matters commercially or for government-adjacent work.
  • It is cheap to add. Where ISO 27001 is already in place or in progress, the marginal cost is small relative to the credibility gained.

How implementation works

Four to eight weeks as an extension where ISO 27001 exists or is in progress.

1. Determine role and applicability

Establish whether the organisation is a cloud service provider, a cloud service customer, or both, since the control guidance differs. 27018 applies only where personal information is processed in public cloud on a customer's behalf.

2. Map shared responsibility

Document precisely which controls are operated by the provider, which by the customer, and which are shared. This is the substantive work and the part auditors examine most closely.

3. Extend the Statement of Applicability

Add the cloud controls, with justification consistent with the existing risk assessment.

4. Build the delta

Virtual segregation, administrative access controls, cloud activity monitoring, asset return and deletion procedures, and for 27018 the personal information handling commitments and location transparency.

5. Fold into the existing audit programme

Internal audit and certification are extensions of the ISO 27001 scope, assessed in the same Stage 1 and Stage 2 rather than as a separate audit.

How Soveriq helps

Soveriq scopes the cloud extensions alongside the ISO 27001 build rather than as a bolt-on afterwards, which is materially cheaper than returning to extend a finished ISMS. The shared responsibility mapping is done as a working document your engineering team can actually use, not an artefact produced for the auditor and then filed.

On internal audit. Where Soveriq has built your management system, we do not then audit it and present that as an independent internal audit. What we provide is readiness validation, labelled as such. Where an independent internal audit is needed after a Soveriq build, it is performed by someone independent of that build and disclosed to you in writing.

What we will not do. Soveriq does not issue certificates, is not a certification body, and does not promise a certification outcome.

What the engagement looks like

  • Module 01 — Gap analysis including role determination and shared responsibility mapping.
  • Module 02 — Build. The additional cloud controls and the extended Statement of Applicability.
  • Module 03 — Internal audit, folded into the ISO 27001 audit programme, subject to the impartiality position above.
  • Module 04 — Audit representation, assessed within the same Stage 1 and Stage 2.
  • Module 05 — Continuous compliance alongside the ISMS.

Price floors are published on the pricing page. Certification body fees are separate and paid directly to that body.

Common questions

Can we certify to 27017 or 27018 on their own?

No. Both extend an ISO 27001 certification scope. You need the ISMS first, or in progress alongside. Anyone offering standalone certification against either is not describing how the scheme works.

Which one do we need?

27017 if you provide or consume cloud services and the security boundary matters. 27018 additionally if you process personal information in public cloud on behalf of your customers. Many organisations need both, and they are usually scoped together.

How much does it add to an ISO 27001 programme?

Four to eight weeks as an extension, and less if scoped in from the start of a first-time ISMS build. The marginal cost is small relative to the credibility it carries with cloud buyers.

Does this help with data sovereignty claims?

Yes. 27018 covers data location transparency and the obligations on return and deletion, which is the documented control set behind an onshore residency commitment rather than just an assertion in a contract.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope