Cloud-specific security and privacy control extensions to ISO 27001. They settle who is responsible for what between provider and customer.
ISO/IEC 27017 and ISO/IEC 27018 are cloud-specific control sets that extend an ISO/IEC 27001 information security management system. Neither is a standalone management system standard: both are certified as an extension to the 27001 scope, not instead of it.
It applies the ISO/IEC 27002:2022 controls to the provision and use of cloud services, with cloud-specific implementation guidance for both providers and customers. It adds controls for the matters unique to cloud: shared roles and responsibilities between provider and customer, segregation in virtual computing environments, and detection and prevention of unauthorised use of cloud services, plus guidance on monitoring cloud service activity.
It applies where an organisation processes personal information as a processor on behalf of its customers, and covers consent and choice, restrictions on using data for the provider's own purposes such as marketing, disclosure to law enforcement, data location transparency, and obligations on return and deletion. The 2025 edition realigns the controls to ISO/IEC 27002:2022 and adds extended implementation guidance.
The recurring theme in both is the shared responsibility boundary — making explicit which control each party operates. That boundary is precisely where most real cloud security failures occur, because both sides assumed the other had it.
Organisations on either side of a cloud service relationship where data sensitivity makes the boundary matter.
Whose customers ask how tenant data is segregated, who can access it administratively, and what happens to it when the contract ends. These questions appear in nearly every enterprise security review.
Where 27018 provides the recognised control set for demonstrating that customer data is not used for the provider's own purposes.
Whether contractual, regulatory or driven by government-adjacent work, 27018 supplies the documented controls behind the claim.
Whose buyers are pressing for cloud-specific assurance beyond the base certificate.
Four to eight weeks as an extension where ISO 27001 exists or is in progress.
Establish whether the organisation is a cloud service provider, a cloud service customer, or both, since the control guidance differs. 27018 applies only where personal information is processed in public cloud on a customer's behalf.
Document precisely which controls are operated by the provider, which by the customer, and which are shared. This is the substantive work and the part auditors examine most closely.
Add the cloud controls, with justification consistent with the existing risk assessment.
Virtual segregation, administrative access controls, cloud activity monitoring, asset return and deletion procedures, and for 27018 the personal information handling commitments and location transparency.
Internal audit and certification are extensions of the ISO 27001 scope, assessed in the same Stage 1 and Stage 2 rather than as a separate audit.
Soveriq scopes the cloud extensions alongside the ISO 27001 build rather than as a bolt-on afterwards, which is materially cheaper than returning to extend a finished ISMS. The shared responsibility mapping is done as a working document your engineering team can actually use, not an artefact produced for the auditor and then filed.
On internal audit. Where Soveriq has built your management system, we do not then audit it and present that as an independent internal audit. What we provide is readiness validation, labelled as such. Where an independent internal audit is needed after a Soveriq build, it is performed by someone independent of that build and disclosed to you in writing.
What we will not do. Soveriq does not issue certificates, is not a certification body, and does not promise a certification outcome.
Price floors are published on the pricing page. Certification body fees are separate and paid directly to that body.
No. Both extend an ISO 27001 certification scope. You need the ISMS first, or in progress alongside. Anyone offering standalone certification against either is not describing how the scheme works.
27017 if you provide or consume cloud services and the security boundary matters. 27018 additionally if you process personal information in public cloud on behalf of your customers. Many organisations need both, and they are usually scoped together.
Four to eight weeks as an extension, and less if scoped in from the start of a first-time ISMS build. The marginal cost is small relative to the credibility it carries with cloud buyers.
Yes. 27018 covers data location transparency and the obligations on return and deletion, which is the documented control set behind an onshore residency commitment rather than just an assertion in a contract.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope