All resources
Blog 5 min read

You have ISO 27001. ISO 27017 is mostly already done.

C1The Compliance One team29 August 2026

The instinct, when a buyer asks for ISO 27017 on top of your ISO 27001, is to brace for another full project. Relax. 27017 is not a parallel universe of new requirements. It is your existing ISO 27002:2022 controls with cloud-specific guidance layered on, plus four controls made for the cloud. If you hold 27001, you have already done the structural work.

27017 is not a second ISMS. It is your first one, told from the cloud's point of view, with four new controls and one honest question: who operates each of these, you or your provider?

What actually carries across

Because the base controls are identical to Annex A of 27001, everything you have already documented and evidenced maps one-to-one. Access control, cryptography, logging, supplier management: same controls, now read with a cloud lens. Compliance One cross-maps them for you, so the evidence you hold for 27001 shows up against the matching 27017 controls without you lifting a finger.

What is genuinely new

  • The four cloud controls: shared roles and responsibilities, virtual-environment segregation, and detecting unauthorized cloud use.
  • The shared-responsibility record: marking each control CSC, CSP or Shared. This is the real deliverable, and it is data entry, not a research project, especially when the defaults are pre-filled.
  • A handful of cloud-specific documents: a cloud security policy, a service register, an exit and data-deletion plan. All pre-filled in the platform.

The punchline

27017 is certified as an extension to your 27001, not as a separate certificate, which is a fair reflection of how much overlap there is. For most teams already on 27001, the marginal effort is measured in days of decisions, not months of building, because the continuous cloud monitoring you run is already producing the evidence. It is the rare compliance upgrade that is mostly a matter of pressing 'yes'.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map Compliance One to your environment.