- Explains the certificate and accreditation details to verify and identifies recognized routes for confirming certification status.
"ISO does not perform certification"
ISO/IEC 27017 is guidance for cloud security controls, not a standalone certification standard. For management-system certification, ISO/IEC 27001 supplies the certifiable requirements; ISO/IEC 27017 can support cloud-control design and evidence within the stated ISMS scope.
Check the certificate's standard and edition, certified organization, scope, sites, issuing body, accreditation status, validity, and whether the cloud service you rely on is covered. A provider certificate does not prove customer-managed controls.
Structured answer sets in this page tree.
Cited legal and guidance references.
is cloud security control guidance, not a standalone management-system certification standard. An organization can use it within an ISO/IEC 27001 information security management system (), including additional cloud controls in its . The certificate is still issued against ISO/IEC 27001 for a stated scope. ISO develops standards; external certification bodies issue certificates.
No standalone ISO/IEC 27017 management-system certification is established by the standard. provides additional guidance for ISO/IEC 27002 controls and seven additional cloud controls for providers and customers.
ISO/IEC 27001 is the certifiable requirements standard. An organization can use ISO/IEC 27017 in its risk treatment and extend its with the additional cloud controls, but it should describe the claim as ISO/IEC 27001 certification and state the certified scope accurately.
Some certificates, audit reports, or certification-body materials may mention ISO/IEC 27017 as guidance used within the assessment. Read the document rather than treating that wording as a separate ISO certification scheme.
Ask for the certificate and read its exact standard, edition, certified legal entity, scope statement, covered sites, issue and expiry dates, certificate number, and certification body. Verify current status with the issuing certification body, its body, or the recognized database linked by ISO.
Then test relevance to the service. The certified organization may exclude a product, region, subsidiary, data center, or process that the customer uses. Even an in-scope provider does not prove that customer-side identity, configuration, workload logging, backup, or incident duties are operating.
Record what the certificate proves and what it does not. Link the certificate check to the service risk assessment and provider/customer responsibility matrix so reviewers can see where independent assurance ends and customer verification begins.
A certificate can reduce duplicate review where its scope and evidence are relevant. ISO/IEC 27017 also recognizes independent audit evidence when individual customer audits are impractical or could increase security risk, provided there is sufficient transparency. If an independent audit is impractical, the 2015 guidance says the provider should conduct a self-assessment and disclose its process and results to the customer.
Reject wording that calls ISO the certifier, omits the ISO/IEC 27001 edition or certified scope, or presents ISO/IEC 27017 as a standalone management-system certificate. Also reject a claim that turns provider certification into automatic legal compliance for the customer.
Certification is written assurance that specified requirements are met within the assessed scope. It is not a warranty that every control operated without exception after the audit date, that every service is included, or that every customer obligation is satisfied.
Check status before contracting and at renewal, certificate expiry, scope change, provider restructuring, service or region change, major incident, or material change to the control boundary. Update the risk decision if the certified scope no longer matches the service.
As of 24 July 2026, remains current while Edition 2 is under publication. A new guidance edition does not itself change an existing ISO/IEC 27001 certificate; assess the new guidance through the change and risk-treatment process.
Record the certificate status and scope, then collect separate evidence for service-specific and customer-managed controls.
Convert ISO/IEC 27017 Certification Reality into accountable tasks, evidence requests, and review checkpoints.
Review your ISO/IEC 27017 cloud-security scope, evidence gaps, and next implementation steps.
"ISO does not perform certification"
"Information security, cybersecurity and privacy protection — Information security management systems — Requirements"
"Information security controls"
"Code of practice for information security controls based on ISO/IEC 27002 for cloud services"