Market leaders choose Johanson Group:
























Experienced Practitioners
Our audit team brings decades of combined experience across security and compliance frameworks — seasoned practitioners, not junior staff learning on your engagement.
Platform Experts
Former GRC platform experts on staff. We audit inside your existing tools — no manual exports, no spreadsheets.
Our Staff
Every audit is managed and conducted by experienced, qualified professionals with real operational knowledge of the standards being assessed.
Expert Network
Tap into our trusted ecosystem of MSP and vCISO partners to strengthen your full security posture — not just your audit.
Relevant services
Cloud security and privacy certifications built to last.
Johanson Group conducts ISO 27017 and ISO 27018 certification audits as standalone engagements or as extensions of an existing ISO 27001 program. Every audit follows a two-stage process — documentation review first, operating effectiveness testing second — with a dedicated assessor leading the engagement from scoping through certificate issuance.
ISO 27017 Audit
A two-stage certification audit assessing your cloud security controls against ISO 27017 requirements. Stage 1 reviews documentation and readiness; Stage 2 tests operating effectiveness across all applicable cloud-specific controls. Successful completion results in ISO 27017 certification, valid for three years with annual surveillance audits.
- Stage 1: documentation review, ISMS scope confirmation, and readiness determination
- Stage 2: control testing across all cloud-specific ISO 27017 requirements
- Shared responsibility model documentation reviewed and assessed
- Virtual machine security, cloud admin access controls, and monitoring assessed
- 3-year certificate issued on successful completion, with annual surveillance
- Can be conducted concurrently with ISO 27001 or 27018 to reduce total audit effort
ISO 27018 Audit
A two-stage certification audit assessing your PII protection controls in cloud environments against ISO 27018 requirements. Covers consent frameworks, data minimization, retention limits, disclosure restrictions, and PII deletion processes. Successful completion results in ISO 27018 certification, valid for three years with annual surveillance audits.
- Stage 1: documentation review covering PII policies, consent records, and data flows
- Stage 2: control testing across consent, retention, disclosure, and deletion requirements
- PII inventory and data flow mapping reviewed against 27018 scope requirements
- Purpose limitation and data minimization controls assessed for all cloud PII processing
- 3-year certificate issued on successful completion, with annual surveillance
- Supports GDPR compliance for cloud-based personal data processing activities
Sub service
Reporting on controls at service organizations relevant to user entities' internal controls over financial reporting (ICFR). Trusted for financial and payroll processors.
Sub service
Reporting on controls at service organizations relevant to user entities' internal controls over financial reporting (ICFR). Trusted for financial and payroll processors.
Sub service
Reporting on controls at service organizations relevant to user entities' internal controls over financial reporting (ICFR). Trusted for financial and payroll processors.
Sub service
Reporting on controls at service organizations relevant to user entities' internal controls over financial reporting (ICFR). Trusted for financial and payroll processors.
Sub service
Reporting on controls at service organizations relevant to user entities' internal controls over financial reporting (ICFR). Trusted for financial and payroll processors.
Sub service
Reporting on controls at service organizations relevant to user entities' internal controls over financial reporting (ICFR). Trusted for financial and payroll processors.
What Are These Standards
Two cloud-specific extensions of ISO 27001.
ISO 27017 and ISO 27018 are internationally recognized standards that extend ISO 27001 with cloud-specific security and privacy controls. They don't replace ISO 27001 — they build on it, adding guidance and requirements tailored to the unique risks of cloud computing and the handling of personal data in the cloud.
ISO/IEC 27017
ISO 27017 provides implementation guidelines and additional security controls specifically for cloud computing environments. It addresses the shared responsibility model between cloud service providers (CSPs) and cloud service customers — one of the most commonly misunderstood and poorly managed aspects of cloud security.
ISO/IEC 27018
ISO 27018 focuses on the protection of Personally Identifiable Information (PII) in public cloud environments. It establishes controls for cloud service providers that act as PII processors — addressing how personal data is collected, used, retained, disclosed, and deleted in cloud infrastructure.
Additional Services
SOC 2
The standard trust report for technology companies. Demonstrates that your security, availability, and data handling controls meet rigorous AICPA standards.
For: SaaS, cloud, and software companies selling to enterprise buyers
ISO 27001
The internationally recognized information security management standard. Required by enterprise and government buyers globally — and a strong differentiator in competitive deals.
For: Companies operating globally or selling into regulated international markets
ISO 42001
The world's first AI management system standard - helping organizations demonstrate responsible, ethical, and secure use of artificial intelligence to enterprise buyers and regulators.The privacy standard for cloud processors handling personal data — demonstrates to customers and regulators that PII is managed responsibly in your cloud environment.
For: AI companies, ML platforms, and enterprises deploying AI systems
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
Frequently asked questions
Your answer not here? Feel free to contact us for more information.
ISO/IEC 27017 and ISO/IEC 27018 are extensions to an ISO/IEC 27001-certified Information Security Management System (ISMS). Organizations typically pursue them alongside ISO/IEC 27001 or add them to an existing ISO/IEC 27001 certification.
ISO 27017 focuses on cloud security controls — particularly the shared responsibility model between cloud service providers and their customers, virtual environment security, and cloud-specific operational controls. ISO 27018 focuses specifically on the protection of Personally Identifiable Information (PII) processed in cloud environments — covering consent, data retention, disclosure restrictions, and privacy rights. Most organizations pursuing cloud certification pursue both, since they address different but complementary aspects of cloud risk.
ISO 27018 certification supports GDPR compliance — particularly Article 28 obligations for data processors — but it does not guarantee full GDPR compliance on its own. GDPR is a legal regulation with broad organizational requirements that go beyond technical controls; ISO 27018 addresses the PII processing aspects in cloud environments. That said, ISO 27018 certification provides documented, auditor-verified evidence of cloud PII controls that regulators and enterprise clients specifically look for when assessing GDPR compliance posture.
If you already hold an ISO 27001 certification, adding 27017 and/or 27018 as extensions typically takes 2–4 months depending on how many cloud-specific control gaps need to be addressed first. For organizations pursuing all three standards simultaneously from scratch, total time from engagement kickoff to certification is typically 5–9 months. We provide a precise timeline at the start of your engagement based on your current ISMS maturity and cloud control posture.
Yes — and this is generally the most efficient approach. If you already have ISO 27001 and are ready to add 27017 and/or 27018, we can structure the certification audit to run concurrently with your next ISO 27001 surveillance or recertification audit. This avoids separate audit cycles, reduces total time from your team, and often results in a combined certificate issuance that keeps all three standards synchronized on the same renewal timeline.
ISO 27017 applies to both cloud service providers (CSPs) and cloud service customers — but in different ways. CSPs implement it to demonstrate that their cloud infrastructure meets cloud-specific security controls. Cloud customers use it to ensure they are properly managing their responsibilities within the shared model. In practice, certification is most commonly pursued by CSPs — SaaS, IaaS, and PaaS providers — who need to demonstrate cloud security maturity to their enterprise clients. We can advise on how it applies to your specific role in the cloud ecosystem.



.png)
.jpg)
.avif)

