← ISO and SOC Certifications

ISO/IEC 27017

Code of practice for information security controls for cloud services. Updated: September 29, 2026.

ISO/IEC 27017 is guidance rather than a standalone management system. It takes the controls of ISO/IEC 27002 and adds cloud-specific implementation guidance, plus a set of controls that exist only in a cloud context. It is written for both sides of the relationship: the cloud service provider and the customer using the service.

What It Adds

The distinctive contribution is that it forces the shared responsibility question to be answered explicitly rather than assumed. Its additional cloud controls cover ground like the division of responsibilities between provider and customer, removal of customer assets when a contract ends, segregation between tenants in a shared environment, the customer's ability to monitor their own use of the service, and the administrative operations the customer can perform.

The recurring failure it addresses is the one everybody has seen: a customer assuming the provider backs up their data, and the provider's contract saying the opposite. 27017 makes that conversation a documented control rather than an assumption discovered during an incident.

How It Is Certified

Because it is a code of practice rather than a requirements standard, it is not certified on its own. In practice certification bodies assess it as an extension to an existing ISO/IEC 27001 certification, audited at the same time, with the 27017 controls reflected in your Statement of Applicability. That means the effort is incremental rather than a separate programme — usually additional audit days rather than an additional audit.

Who Actually Needs It

For an organisation that simply uses a few SaaS products, it is usually not worth a separate certification — the relevant controls already sit inside 27001's supplier management.

Related

ISO/IEC 27018 covers the personal-data side of the same territory, and ISO/IEC 27001 is the management system both attach to. Our work on deployment models and dependency mapping covers the practical side of knowing where responsibility sits.

Written from an infrastructure perspective. We are not a certification body, an audit firm or a legal adviser, and this is not legal advice. Standards are revised on a cycle — confirm the current edition before you commit.