ISO27K

ISO 27017 and ISO 27018 for cloud services

Neither ISO 27017 nor ISO 27018 is a management system standard. They are codes of practice that an accredited body can certify as an extension to an existing ISO 27001 certificate, and for most Canadian software companies the extension is worth less than the sales team hopes.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

ISO/IEC 27017 and ISO/IEC 27018 are guidance documents, not management system standards, and you cannot hold either one on its own. What you can hold is an ISO 27001 certificate whose scope statement records that the control set was extended with 27017, 27018, or both. That extension typically adds one to three audit days, which is roughly $2,500 to $9,000 CAD on top of a first certification, and it changes nothing about the underlying requirement to run a working management system.

The question worth asking before you buy either is which of the two roles you are being asked about, because a Canadian software company is usually both at once.

1 to 3 Extra audit days for the extension

$2,500 to $9,000 Added to a first certification, CAD

0 Standalone certificates that exist for either

What is ISO 27017 and what is ISO 27018?

ISO/IEC 27017
A code of practice for information security controls for cloud services. It takes a subset of the ISO 27002 controls and adds cloud-specific implementation guidance to each, then adds a set of extended controls that exist only in the cloud context: who administers what, how the shared responsibility split is documented, virtual machine hardening, segregation in virtual environments, alignment of security management between the provider and the customer, and how data is removed and returned when the contract ends.
ISO/IEC 27018
A code of practice for protecting personally identifiable information in public clouds acting as a processor. It is narrower: it addresses the cloud provider that handles someone else's personal information on instruction, and it covers consent, purpose limits on the provider's own use of the data, disclosure to law enforcement, sub-processor transparency, return and deletion, and notification of breaches to the customer.
The relationship to ISO 27001
Both are written against the ISO 27002 control numbering. Neither contains clauses 4 through 10, so neither has a management system to certify. They ride on an ISO 27001 certificate, and the additional controls are recorded in the Statement of Applicability alongside the 93 Annex A controls.

Am I a cloud service provider or a cloud service customer?

Both, and this is the part most readers get wrong. ISO 27017 is addressed to both roles and treats them differently, and the guidance you have to implement depends on which side of a given relationship you are standing on.

The same Canadian SaaS company in two roles under ISO 27017
RelationshipYour roleWhat the guidance asks of you
You sell software to your business customersCloud service providerPublish the shared responsibility split, document what you administer and what the customer does, define data return and deletion at contract end, and tell customers about incidents and changes that affect their security.
You run on AWS, Azure or Google CloudCloud service customerKnow your own side of that same split, monitor and log within your own tenancy, harden your virtual machines and images, and hold the provider's own certification evidence rather than assuming it.
You resell or embed a third-party model or serviceBoth, per serviceThe split has to be documented twice, and the sub-processor disclosure to your own customers is the control people miss.

The role framing matters beyond 27017. The same per-service role question is the first thing a certification body asks about an AI management system, which is why the ISO 42001 page opens on it. Getting into the habit here makes that conversation shorter later.

What do they add to an ISO 27001 audit?

Less than the fee suggests, if your ISO 27001 scope was written properly in the first place. Annex A already contains a control on information security for use of cloud services, and the supplier group in A.5 already covers agreements, supply chain security and ongoing monitoring. The Annex A controls page sets out where those sit. What 27017 adds is depth on the split of responsibility and the virtualisation controls, and what 27018 adds is an explicit processor-side privacy posture that Annex A gestures at in one control.

What the extension changes on a first certification, CAD
LineISO 27001 aloneWith 27017 and 27018
Stage 1 and stage 2 audit days4 to 105 to 13
Certification body fee$15,000 to $40,000$17,500 to $49,000
Additional controls in the Statement of Applicability0Roughly 10 to 15
Additional internal hours030 to 80
Realistic added cost, first cycleBaseline$5,000 to $18,000

The added internal hours are the part that surprises people. The extension does not fail on the audit fee, it fails because somebody has to write the shared responsibility documentation, and at most companies that document does not exist and nobody owns it.

Who should not bother with the extension?

Most Canadian software companies under 200 people, and this is worth saying plainly because nobody selling the extension will.

  1. Read the email that triggered the question. If it says cloud security certification, the sender almost always means ISO 27001 or SOC 2 and has never heard of 27017. Ask before you spend anything.
  2. If the request names 27017 or 27018 specifically, ask whether it is a requirement or a preference. In tenders it is usually a scored line rather than a gate, and the score is small.
  3. If you are a genuine infrastructure or platform provider, meaning your customers build on top of you and inherit your controls, the extension does real work and you should do it.
  4. If you are a business application handling customer personal information as a processor and your buyers are European, ISO 27018 is the more defensible of the two, and ISO 27701 is probably the better purchase again.
  5. Otherwise, spend the money on the scope and the evidence quality of the ISO 27001 certificate you already have to earn.

Your cloud provider's certificate is not yours

AWS, Azure and Google Cloud hold ISO 27017 and ISO 27018 certification for their own services, and every year somebody points at that on a security questionnaire as though it answered the question. It does not. Their certificate covers their side of the shared responsibility split, and the control you are being asked about lives on yours. What their certificate does legitimately do is satisfy the supplier and cloud service controls in A.5, which is why holding a copy of it and reviewing it annually is a real piece of evidence.

What do these add under Canadian privacy law?

Nothing directly, and that is the same honest answer that applies to every certificate. Neither document makes you compliant with PIPEDA, with Alberta or British Columbia PIPA, or with Quebec Law 25. What ISO 27018 does is line up neatly with the accountability expectations those statutes place on a service provider handling personal information on someone else's behalf: knowing what you hold, using it only as instructed, disclosing sub-processors, notifying the customer of a breach, and deleting on request.

Law 25 is the one where the alignment is closest and still not sufficient. Quebec requires a privacy impact assessment before communicating personal information outside Quebec and requires specific contractual terms with a service provider. An ISO 27018 extension gives you good evidence for the security half of that assessment and does not conduct it for you. The Quebec certification page covers what the certificate does and does not carry there.

Common questions

Can you be certified to ISO 27017 or ISO 27018 on their own?

No. Neither document contains management system requirements, so there is no standalone certificate. Accredited certification bodies offer them as an extension to the scope of an ISO 27001 certificate, and the resulting document names ISO 27001 with the additional codes of practice recorded. A vendor offering a standalone ISO 27017 certificate is selling something unaccredited.

What is the difference between ISO 27017 and ISO 27018?

ISO 27017 covers information security for cloud services generally and is addressed to both the provider and the customer of a cloud service. ISO 27018 covers the protection of personally identifiable information in public clouds and is addressed to the provider acting as a processor of someone else's personal information. If your customers send you their users' data, 27018 is the one they care about.

How much does adding ISO 27017 to our certification cost?

Expect one to three additional audit days, which is roughly $2,500 to $9,000 CAD in certification body fees, plus 30 to 80 internal hours to produce the shared responsibility documentation the guidance expects. Adding it at the same time as an initial certification is cheaper than adding it later, because a scope extension mid-cycle usually needs its own visit.

Do we need ISO 27017 if we are just a SaaS company on AWS?

Usually not. Annex A of ISO 27001 already contains a control on information security for use of cloud services plus five supplier controls, and for a business application that covers the ground your buyers are asking about. The extension earns its cost when your customers build on top of your platform and inherit controls from you, or when a tender names the document by number.

Does ISO 27018 make us GDPR compliant?

No. It gives useful evidence for the security obligations in Article 32 and for parts of the processor obligations in Article 28, and it does nothing about lawful basis, data subject rights, records of processing or international transfers. The same limit applies to ISO 27001, and the GDPR page maps article by article which parts a certificate actually helps with.

Should we do ISO 27018 or ISO 27701?

ISO 27701, in most cases. Since its 2025 revision it is a standalone privacy information management system standard with its own certificate, which is a stronger thing to hand a European procurement team than a code of practice recorded in someone else's scope statement. ISO 27018 is cheaper and lighter, so it remains a reasonable answer when a single customer has asked for it by name.