All resources
Blog 6 min read

ISO 27017 vs 27018 vs 27701: which cloud and privacy standard do you need?

C1The Compliance One team30 August 2026

ISO 27017, ISO 27018 and ISO 27701 sound like sequential version numbers. They are not. They answer three different questions, and picking the right one saves you from certifying against something your buyers were not asking for.

27017 is about securing the cloud. 27018 is about protecting personal data in the cloud when you are the processor. 27701 is about running privacy as a whole management system. Same family, different jobs.

The one-line version of each

  • ISO 27017: cloud security controls. How you and your provider secure cloud services: segregation, encryption, logging, shared responsibility. For anyone running on the cloud.
  • ISO 27018: PII protection in the public cloud, for processors. How you protect the personal data your customers entrust to you: breach notice, sub-processing, return and deletion, data location. For a SaaS holding customer data.
  • ISO 27701: a privacy information management system (PIMS). A full management system for privacy, for controllers and processors, mapped to the GDPR. The broadest of the three.

How to choose

If buyers ask 'how is your cloud secured', you want 27017. If they ask 'how do you protect our users' personal data', you want 27018. If they ask 'show me your privacy programme' or 'are you GDPR compliant', you want 27701. Many companies end up with more than one, because the questions come from different people.

The good news: all three are built on the same ISO 27002:2022 control set, so they overlap heavily. In Compliance One they are cross-mapped, so the evidence you produce for one counts toward the others. You are not running three programmes, you are running one and pointing it at three questions.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map Compliance One to your environment.