Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27017 vs ISO 27018 explained

ISO 27017 vs ISO 27018: 6 Clear Differences and Which You Need

ISO 27017 vs ISO 27018 is a comparison most cloud providers get wrong in the same direction: they treat the two as a pair to be bought together, when each answers a different buyer question. ISO/IEC 27017:2026 is cloud security — implementation guidance on the ISO/IEC 27002:2022 controls for both cloud service providers and cloud service customers, plus a handful of controls that exist only because computing became shared.

ISO/IEC 27018:2025 is cloud privacy — guidance for a public cloud provider acting as a PII processor, extending ISO/IEC 27002 with implementation guidance and an Annex A of additional controls organised by the ISO/IEC 29100 privacy principles. Neither is certifiable on its own; both are audited as extensions to an ISO 27001 certificate. This guide sets out the six differences that decide which one a provider needs, who each standard is written for, what the current editions changed, how the two are evidenced on a certificate, and the three cases where one is enough.

ISO 27017 vs ISO 27018: six differences between the cloud security and cloud privacy standards
Subject · who it is written for · what it adds to ISO 27002 · current edition · how it is audited · the buyer question it answers.

ISO 27017 vs ISO 27018 at a glance

Dimension ISO/IEC 27017:2026 ISO/IEC 27018:2025
Subject Information security controls for cloud services Protection of personally identifiable information (PII) in public clouds
Written for Cloud service providers and cloud service customers — both roles, any deployment model Public cloud service providers acting as PII processors; most guidance also useful to controllers
What it adds to ISO/IEC 27002:2022 Cloud-specific implementation guidance on existing controls, plus dedicated cloud controls (including shared roles and responsibilities, segregation in virtual environments, cloud partner responsibilities, and unauthorised use of cloud services) PII-specific implementation guidance on existing controls, plus Annex A additional controls organised by the ISO/IEC 29100 privacy principles
Current edition Second edition, July 2026, 39 pages; replaced ISO/IEC 27017:2015, dropped the CLD numbering, aligned to 27002:2022 Third edition, August 2025, 35 pages; replaced ISO/IEC 27018:2019, aligned to 27002:2022, added Annex B
Certifiable? No — audited as an extension of an ISO 27001 certificate, named in the scope statement No — the same
Buyer question it answers “Is your cloud service secure, and who is responsible for what?” “What do you do with our personal data, and can we meet our processor obligations through you?”

Difference 1: security against privacy

ISO 27017 is about the confidentiality, integrity and availability of information in a cloud service — any information, for any customer. ISO 27018 is about one category of information, PII, and one legal position, the processor acting under a customer’s instructions. A provider that hosts no personal data has no use for 27018; a provider that hosts personal data still needs 27017, because privacy controls sit on top of security controls, not instead of them. The distinction is the first thing to settle in any ISO 27017 vs ISO 27018 decision. Our guides to ISO 27017 and ISO 27018 cover each on its own.

Difference 2: who it is written for

ISO 27017 addresses both sides of the cloud relationship: its guidance is split, control by control, into what the provider does and what the customer does, which is why the shared responsibility matrix is the document it produces. ISO 27018 addresses one side — the processor — and its introduction says so: the standard is “for organizations acting as public cloud PII processors”, with most controls “also apply[ing] to a PII controller”, who is “subject to additional obligations not specified here”. A SaaS company that decides the purposes of processing for its own product is a controller for that data and outside the standard’s scope for it. Our guide to the shared responsibility matrix covers the 27017 artefact.

Difference 3: what each adds to ISO/IEC 27002

The third ISO 27017 vs ISO 27018 difference is in what each adds. Both standards are built the same way — ISO/IEC 27002:2022’s control set, with sector-specific implementation guidance and additional controls — but the additions differ in kind. ISO 27017’s additions are architectural: shared roles and responsibilities, segregation in virtual computing environments, responsibilities with other cloud partners, detection and prevention of unauthorised cloud use, and a monitoring annex.

ISO 27018’s additions are contractual and procedural: Annex A’s controls, organised by the ISO/IEC 29100 principles — consent and choice, purpose legitimacy, collection limitation, use, retention and disclosure limitation, accuracy, openness, individual participation, accountability, information security and privacy compliance — cover processing only on instruction, no use for marketing or advertising without consent, disclosure of sub-processors, notification of legally binding disclosure requests, breach notification, return, transfer and disposal of PII, and the geographic location of PII. Our guide to PII processor obligations works through them.

Difference 4: the current editions

ISO 27017’s second edition, published July 2026, withdrew the 2015 edition and removed the CLD identifiers that every cloud toolkit was built on; cloud controls now sit inside the 27002:2022 numbering, with a small number of dedicated controls added. ISO 27018’s third edition, published 2025, aligned the text with ISO/IEC 27002:2022 and added Annex B, keeping Annex A. The consequence for a provider carrying both: documentation mapped to 27017’s CLD numbers needs remapping; documentation mapped to 27018’s Annex A mostly does not.

Difference 5: how each is audited

On audit, ISO 27017 vs ISO 27018 is no contest: neither is a management system standard, so neither can be certified alone. Both are assessed as extensions of an ISO 27001 audit: the controls are included in the Statement of Applicability, the certification body audits them as part of the ISMS, and the certificate’s scope statement names the standard. A provider can hold 27001 with 27017 only, with 27018 only, or with both; the certificate says which. Ask any provider claiming “ISO 27018 certified” for the certificate and read the scope. Our guide to the Statement of Applicability covers how extension controls are declared, and the ISO 27017 certification cost post covers what the extension adds to the audit.

Difference 6: the buyer question

The last ISO 27017 vs ISO 27018 difference is the audience. ISO 27017 answers the security questionnaire: architecture, tenancy separation, administrator controls, monitoring, what the customer must configure. ISO 27018 answers the privacy review: purposes, sub-processors, government requests, location, breach notification, deletion. In an enterprise procurement the two reviews are run by different teams — security and legal or privacy — and a provider that holds only one will be asked for the other by the team it does not satisfy.

ISO 27017 vs ISO 27018: when one is enough

Provider Need Why
Infrastructure or platform provider holding no customer PII in a processor role — or unable to know what customers store ISO 27017 Security is the whole question; 27018 obligations cannot be met without visibility of PII
SaaS provider processing customer personal data on instruction — HR, CRM, healthcare, payroll ISO 27017 and ISO 27018 Security and processor privacy are both asked; 27018 without 27017 leaves the security review open
Cloud customer building on a hyperscaler ISO 27017 (customer side) 27017’s customer guidance defines what you must configure; 27018 is the provider’s job
Provider whose customers are mainly EU or UK enterprises ISO 27018 at minimum GDPR Article 28 processor terms are what the privacy team checks; 27018 is the recognised control set for them

Implementing the pair

  1. Start from ISO 27001. Neither extension has anything to attach to without an ISMS and a Statement of Applicability.
  2. Add 27017 first. The shared responsibility matrix and the cloud-specific controls are the base every customer needs.
  3. Add 27018 where you are a processor. Map Annex A to the processing you actually do; the sub-processor register and the disclosure-request log are the two artefacts customers ask to see.
  4. Put both in the SoA and the scope statement. The certificate’s wording is the evidence.
  5. Keep the editions current. 27017:2026 and 27018:2025 are what certification bodies now audit against.

Frequently asked questions

What is the difference between ISO 27017 vs ISO 27018?
ISO 27017 gives cloud security guidance on the ISO 27002 controls for providers and customers, with dedicated cloud controls; ISO 27018 gives privacy guidance for public cloud providers acting as PII processors, with Annex A controls organised by the ISO/IEC 29100 principles. One is security for any data; the other is privacy for personal data in a processor role.

Can I be certified to either?
Not on its own. Both are audited as extensions to an ISO 27001 certificate and appear in its scope statement.

Do I need both?
If you process customer personal data under instruction in a public cloud, yes — security and processor privacy are separate reviews. If you hold no PII in a processor role, ISO 27017 alone answers the question buyers ask.

What are the current editions?
ISO/IEC 27017:2026, the second edition, published July 2026 and replacing the 2015 edition; ISO/IEC 27018:2025, the third edition, aligned to ISO/IEC 27002:2022 with a new Annex B.

Does ISO 27018 satisfy GDPR Article 28?
It provides a recognised control set for processor obligations and audited evidence a customer can rely on; it does not replace the data processing agreement or the legal obligations.

Where this leaves you

Decide ISO 27017 vs ISO 27018 by the question your buyers ask: security for any data means 27017, processor privacy for personal data means 27018, and a SaaS provider handling customer PII usually needs both. Build each as an extension of ISO 27001, declare them in the Statement of Applicability and the certificate scope, and keep the 2026 and 2025 editions as the reference.

References

More on ISO 27017 and ISO 27018

The Shared Roles and Responsibilities Policy, the Shared Responsibility Matrix Template, the PII Processor Policy for Public Cloud, the Sub-processor Register and the PII Breach Notification Procedure are in the ISO 27017 & ISO 27018 Cloud Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.