Hold more than one standard? One audit.
ISO/IEC 27017 shares its structure with ISO/IEC 27001, ISO/IEC 27018. We audit them together — one team, one visit, one report.
Security controls for cloud service providers and cloud customers — the extension of ISO/IEC 27001 that cloud buyers ask for.
ISO/IEC 27017 adds cloud-specific guidance to Annex A controls: shared responsibility, virtual machine hardening, tenant isolation, monitoring of cloud services and removal of customer assets on contract end.
Roles of provider and customer defined.
Segregation in virtual environments.
Configuration of virtual machines.
Customer visibility of service operation.
Return and deletion of assets at exit.
ISO/IEC 27017 is audited against these requirement areas. Open each one to see what auditors look for in your company.
ISO/IEC 27017 shares its structure with ISO/IEC 27001, ISO/IEC 27018. We audit them together — one team, one visit, one report.
Scroll the steps — the bar shows where you are in the process. Every step has a named coordinator and a fixed timeline.
You send a short application; a coordinator sizes the audit and sends a fixed offer.
→ Offer with audit planDocumentation review and readiness check — remote or on site. Gaps are listed, not penalised.
→ Readiness reportOn-site assessment of implementation and effectiveness with a team that knows your sector.
→ Audit reportIndependent certification decision; the certificate is issued and entered into the public register.
→ ISO/IEC 27017 certificateAnnual surveillance keeps the certificate in force; re-certification in year three.
→ Certificate maintainedTick what you already have. You do not need a perfect system to apply — you need a working one.
Based on the items ticked on the left. Indicative — the Stage 1 audit gives the formal picture.
Apply for ISO/IEC 27017 →Did not find yours? Call us — a coordinator answers within the same business day.
+38 (044) 332-30-76Send an application — we define scope and audit duration, and issue a fixed offer within one business day.