ISO 27017/18

4.9
Based on 100+ G2 reviews

Cloud security and privacy certified.

As more organizations rely on cloud services, customers need proof that their data is secure. ISO 27017 and ISO 27018 are the international standards that provide it — built on top of ISO 27001, and designed specifically for the cloud.

Market leaders choose Johanson Group:

Experienced Practitioners

Our audit team brings decades of combined experience across security and compliance frameworks — seasoned practitioners, not junior staff learning on your engagement.

Platform Experts

Former GRC platform experts on staff. We audit inside your existing tools — no manual exports, no spreadsheets.

Our Staff

Every audit is managed and conducted by experienced, qualified professionals with real operational knowledge of the standards being assessed.

Expert Network

Tap into our trusted ecosystem of MSP and vCISO partners to strengthen your full security posture — not just your audit.

Relevant services

Cloud security and privacy certifications built to last.

Johanson Group conducts ISO 27017 and ISO 27018 certification audits as standalone engagements or as extensions of an existing ISO 27001 program. Every audit follows a two-stage process — documentation review first, operating effectiveness testing second — with a dedicated assessor leading the engagement from scoping through certificate issuance.

What Are These Standards

Two cloud-specific extensions of ISO 27001.

ISO 27017 and ISO 27018 are internationally recognized standards that extend ISO 27001 with cloud-specific security and privacy controls. They don't replace ISO 27001 — they build on it, adding guidance and requirements tailored to the unique risks of cloud computing and the handling of personal data in the cloud.

ISO/IEC 27017

ISO 27017 provides implementation guidelines and additional security controls specifically for cloud computing environments. It addresses the shared responsibility model between cloud service providers (CSPs) and cloud service customers — one of the most commonly misunderstood and poorly managed aspects of cloud security.

ISO/IEC 27018

ISO 27018 focuses on the protection of Personally Identifiable Information (PII) in public cloud environments. It establishes controls for cloud service providers that act as PII processors — addressing how personal data is collected, used, retained, disclosed, and deleted in cloud infrastructure.

Additional Services

SOC & ATTESTATION

SOC 2

The standard trust report for technology companies. Demonstrates that your security, availability, and data handling controls meet rigorous AICPA standards.

For: SaaS, cloud, and software companies selling to enterprise buyers

ISO Standards

ISO 27001

The internationally recognized information security management standard. Required by enterprise and government buyers globally — and a strong differentiator in competitive deals.

For: Companies operating globally or selling into regulated international markets

ISO Standards

ISO 42001

The world's first AI management system standard - helping organizations demonstrate responsible, ethical, and secure use of artificial intelligence to enterprise buyers and regulators.The privacy standard for cloud processors handling personal data — demonstrates to customers and regulators that PII is managed responsibly in your cloud environment.

For: AI companies, ML platforms, and enterprises deploying AI systems

Customer Success Stories

Cryptocurrency Exchange

Bitkub Exchange Becomes Thailand's First Digital Asset Exchange to Achieve SOC 2 Type II

Thailand's leading digital asset exchange became the country's first to earn SOC 2 Type II — validating security across all five Trust Services Criteria.

6 weeks
Biotech Company

Scisco Genetics Secures Data with SOC 2 Compliance

Seattle-based Scisco Genetics Inc. is a leader in genetic analysis, offering fast and accurate high resolution genotyping of complex immune regions.

4.9
Based on 100+ G2 reviews

Don't just take our word for it.

"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

David Patrick
Director of Security and Compliance

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."

Björn Schwenzer
COO, WunderGraph

"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""

Daryl Pinkal
CTO, Clozd

"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

Ram Ganesan
Co-Founder, Kaboom AI

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

Chintan Shukla
Founder & CEO, Infotech Houston Health

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."

Sheryl Briggs
CEO, Classapps

"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

David Patrick
Director of Security and Compliance

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."

Björn Schwenzer
COO, WunderGraph

"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""

Daryl Pinkal
CTO, Clozd

"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

Ram Ganesan
Co-Founder, Kaboom AI

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

Chintan Shukla
Founder & CEO, Infotech Houston Health

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."

Sheryl Briggs
CEO, Classapps

"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

David Patrick
Director of Security and Compliance

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."

Björn Schwenzer
COO, WunderGraph

"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""

Daryl Pinkal
CTO, Clozd

"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

Ram Ganesan
Co-Founder, Kaboom AI

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

Chintan Shukla
Founder & CEO, Infotech Houston Health

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."

Sheryl Briggs
CEO, Classapps

"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

David Patrick
Director of Security and Compliance

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."

Björn Schwenzer
COO, WunderGraph

"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""

Daryl Pinkal
CTO, Clozd

"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

Ram Ganesan
Co-Founder, Kaboom AI

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

Chintan Shukla
Founder & CEO, Infotech Houston Health

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."

Sheryl Briggs
CEO, Classapps

"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

David Patrick
Director of Security and Compliance

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."

Björn Schwenzer
COO, WunderGraph

"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""

Daryl Pinkal
CTO, Clozd

"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

Ram Ganesan
Co-Founder, Kaboom AI

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

Chintan Shukla
Founder & CEO, Infotech Houston Health

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."

Sheryl Briggs
CEO, Classapps

Frequently asked questions

Your answer not here? Feel free to contact us for more information.

ISO/IEC 27017 and ISO/IEC 27018 are extensions to an ISO/IEC 27001-certified Information Security Management System (ISMS). Organizations typically pursue them alongside ISO/IEC 27001 or add them to an existing ISO/IEC 27001 certification.

ISO 27017 focuses on cloud security controls — particularly the shared responsibility model between cloud service providers and their customers, virtual environment security, and cloud-specific operational controls. ISO 27018 focuses specifically on the protection of Personally Identifiable Information (PII) processed in cloud environments — covering consent, data retention, disclosure restrictions, and privacy rights. Most organizations pursuing cloud certification pursue both, since they address different but complementary aspects of cloud risk.

ISO 27018 certification supports GDPR compliance — particularly Article 28 obligations for data processors — but it does not guarantee full GDPR compliance on its own. GDPR is a legal regulation with broad organizational requirements that go beyond technical controls; ISO 27018 addresses the PII processing aspects in cloud environments. That said, ISO 27018 certification provides documented, auditor-verified evidence of cloud PII controls that regulators and enterprise clients specifically look for when assessing GDPR compliance posture.

If you already hold an ISO 27001 certification, adding 27017 and/or 27018 as extensions typically takes 2–4 months depending on how many cloud-specific control gaps need to be addressed first. For organizations pursuing all three standards simultaneously from scratch, total time from engagement kickoff to certification is typically 5–9 months. We provide a precise timeline at the start of your engagement based on your current ISMS maturity and cloud control posture.

Yes — and this is generally the most efficient approach. If you already have ISO 27001 and are ready to add 27017 and/or 27018, we can structure the certification audit to run concurrently with your next ISO 27001 surveillance or recertification audit. This avoids separate audit cycles, reduces total time from your team, and often results in a combined certificate issuance that keeps all three standards synchronized on the same renewal timeline.

ISO 27017 applies to both cloud service providers (CSPs) and cloud service customers — but in different ways. CSPs implement it to demonstrate that their cloud infrastructure meets cloud-specific security controls. Cloud customers use it to ensure they are properly managing their responsibilities within the shared model. In practice, certification is most commonly pursued by CSPs — SaaS, IaaS, and PaaS providers — who need to demonstrate cloud security maturity to their enterprise clients. We can advise on how it applies to your specific role in the cloud ecosystem.