All frameworks
ISOCertification · cloud

ISO 27017 compliance

Prove your cloud is actually secure.

ISO/IEC 27017 is the code of practice for information security in cloud services. The 2026 second edition is realigned to ISO/IEC 27002:2022: it layers cloud-specific implementation guidance on the whole control set and adds four standalone cloud controls, all built around the shared-responsibility model between you as the cloud service customer (CSC) and your provider (CSP). It is certified as an extension to ISO 27001 — and it is the framework where continuous cloud-posture monitoring does most of the work for you.

Start from the basics

The standard

ISO/IEC 27017:2026 — Cloud services information security controls

Who needs it

Any organisation that runs on the cloud and whose customers ask 'how do you secure your cloud?' — SaaS vendors, anyone on AWS/Azure/GCP, and organisations already holding ISO 27001 who want a cloud-specific credential to match. It is increasingly named directly in enterprise security questionnaires.

1000s

cloud checks, auto-mapped

The basics

What is ISO 27017?

An extension of ISO 27002:2022, not a separate control set: cloud-specific guidance on the existing controls, plus four cloud controls — shared roles & responsibilities (5.38/5.39 CLD), segregation in virtual computing environments (8.35 CLD), and detection & prevention of unauthorized cloud use (8.36 CLD).

Built on shared responsibility: for every control you record who operates it — CSC (you), CSP (your provider), or Shared — in a responsibility matrix, which is exactly what an auditor reviews.

Certified alongside ISO 27001 by an accredited body, so a 27017 statement sits on top of your existing ISMS certificate rather than starting a new one.

Why it matters

What ISO 27017 does for your business

It answers the cloud question

'How is your cloud secured?' has no certificate of its own until 27017. It is the recognised, auditable way to demonstrate cloud-specific controls.

It rides on your ISO 27001

The base controls are the ISO 27002:2022 set, so 27017 maps one-to-one to 27001 — if you hold 27001 you are most of the way there.

Evidence collects itself

Because the controls are the 27002:2022 set, continuous cloud-posture scans of your AWS/Azure/GCP accounts satisfy the technical controls automatically.

What it covers

Map responsibility

Record CSC / CSP / Shared for every control across each cloud service — your shared-responsibility matrix.

Secure the platform

Segregation in virtual environments, encryption and key management, logging, and least-privilege cloud IAM.

Detect misuse

Threat detection, anomalous-activity monitoring, and control of unsanctioned cloud services (shadow IT).

Govern the lifecycle

Cloud service selection, supplier agreements, and secure return & deletion of data at exit.

The hard way

Cloud security is a moving target split across you and your providers: who encrypts what, who logs what, who owns segregation, what happens to your data at exit. Working out the shared-responsibility split for every control, then evidencing it and keeping it current as your cloud estate changes, is where cloud-security programmes stall.

The easier way, with Compliance One

  • Ships the full ISO 27017:2026 control set — every ISO 27002:2022 control with cloud guidance plus the four cloud-specific controls — enabled by default with a Statement of Applicability.
  • Captures the shared-responsibility model natively: set CSC / CSP / Shared inline on each control, or manage it all in a dedicated Shared-Responsibility Matrix with export, backed by a clear in-app explainer.
  • Auto-populates evidence: your continuous AWS/Azure/GCP posture scans flow straight into the matching 27017 controls, so the technical controls are evidenced without manual work.
  • Pre-fills the cloud documents: cloud security policy, shared-responsibility matrix, service register, supplier & agreement standard, cryptography & key management, segregation, logging & monitoring, incident-response addendum and cloud exit plan.

Do it once, reuse it everywhere. Evidence you collect for ISO 27017is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

Is ISO 27017 a standalone certification?
It is certified as an extension to ISO 27001 rather than on its own — your 27017 controls sit on top of your ISMS. The 2026 second edition realigns it to ISO 27002:2022.
We already have ISO 27001 — how much extra work?
Much less than a new framework. The base controls are the same ISO 27002:2022 set, so Compliance One maps them one-to-one and carries your existing evidence across; you mainly add the cloud-specific guidance and the four cloud controls.
What is the shared-responsibility model?
For each control you record who operates it: CSC (you, the cloud service customer), CSP (your provider), or Shared. The platform captures this per control and compiles it into a responsibility matrix your auditor can read at a glance.
Does our cloud monitoring count as evidence?
Yes — that is the point. Because 27017's controls are the ISO 27002:2022 set, your continuous cloud-posture scans are cross-mapped to the matching 27017 controls automatically, so the technical controls are evidenced continuously.

Ready to tackle ISO 27017?

See exactly how Compliance One maps ISO 27017 to your environment in a 30-minute walkthrough — and how much of it we handle for you.