Use ISO/IEC 27017 for cloud security responsibilities and ISO/IEC 27018:2025 when a public cloud provider processes PII for a customer.
The standards complement each other. Neither replaces applicable privacy law, the controller's duties, the processing contract, or service-specific risk assessment.
ISO/IEC 27017:2015 covers cloud information security for providers and customers. ISO/IEC 27018:2025 covers protection of personally identifiable information (PII) in public cloud services when the provider acts as a . Apply ISO/IEC 27017 to the service's broader cloud security boundary and add ISO/IEC 27018 only where the public-cloud, PII, and processor conditions are met.
Side-by-side comparison
ISO/IEC 27017 vs ISO/IEC 27018: scope, duties, evidence, and decision rule
Compare the service scope, actor test, control focus, evidence, and limits of reuse between the two standards.
The cloud service provider and cloud service customer each receive guidance; their actions depend on the agreed security responsibility allocation and service model.
The public cloud provider is the and the cloud customer is normally the party giving processing instructions. Controller duties and any provider processing for its own purposes need separate analysis.
ISO/IEC 27018 adds privacy guidance for public-cloud processor activities, including support for PII principals' rights, instructions, disclosures, transfers, return or deletion, and PII breach handling.
Evidence includes the service and responsibility scope, agreements, provider assurance, customer configurations, access reviews, logs, backup tests, vulnerability records, change notices, and incident records.
Evidence adds the processing and role record, instructions, PII location and transfer records, subprocessors, disclosures, assistance requests, deletion or return results, and PII breach records.
ISO/IEC 27017 can support an ISO/IEC 27001 control environment, certification scope, internal audit, contract, or customer assurance, but it is not legislation or a standalone certification scheme.
ISO/IEC 27018 can support privacy control design and assurance for its stated scope, but it does not replace binding privacy law or decide controller and processor roles.
Security records under ISO/IEC 27017 can support overlapping ISO/IEC 27018 controls, including access, logging, incident, supplier, and deletion-related evidence.
If ISO/IEC 27018 does not apply, keep the privacy analysis under the relevant law, contract, and other applicable standards rather than forcing this control set onto the service.
The cloud service provider and cloud service customer each receive guidance; their actions depend on the agreed security responsibility allocation and service model.
The public cloud provider is the and the cloud customer is normally the party giving processing instructions. Controller duties and any provider processing for its own purposes need separate analysis.
ISO/IEC 27018 adds privacy guidance for public-cloud processor activities, including support for PII principals' rights, instructions, disclosures, transfers, return or deletion, and PII breach handling.
Evidence includes the service and responsibility scope, agreements, provider assurance, customer configurations, access reviews, logs, backup tests, vulnerability records, change notices, and incident records.
Evidence adds the processing and role record, instructions, PII location and transfer records, subprocessors, disclosures, assistance requests, deletion or return results, and PII breach records.
ISO/IEC 27017 can support an ISO/IEC 27001 control environment, certification scope, internal audit, contract, or customer assurance, but it is not legislation or a standalone certification scheme.
ISO/IEC 27018 can support privacy control design and assurance for its stated scope, but it does not replace binding privacy law or decide controller and processor roles.
Security records under ISO/IEC 27017 can support overlapping ISO/IEC 27018 controls, including access, logging, incident, supplier, and deletion-related evidence.
If ISO/IEC 27018 does not apply, keep the privacy analysis under the relevant law, contract, and other applicable standards rather than forcing this control set onto the service.
Use ISO/IEC 27017 for the security of providing and using a cloud service, whether the service is public, private, community, or hybrid and whether or not it processes PII. It addresses provider and customer responsibilities across the cloud service.
Add ISO/IEC 27018:2025 when the service is a public cloud, PII is processed, and the provider acts as a under contract to the customer. For example, a multi-tenant SaaS provider processing a customer's employee records only on that customer's instructions can meet those scope conditions. The same provider's separate use of account contact data for purposes it determines can place that activity outside the processor scope. A provider acting as a controller, or a private-cloud arrangement outside that scope, needs separate privacy analysis even if some guidance remains useful.
Record the standard edition and the organization's role for each service. ISO/IEC 27018:2019 was withdrawn when the 2025 third edition was published; the 2025 edition aligns with ISO/IEC 27002:2022 and adds extended implementation guidance in Annex B.
Test four facts for ISO/IEC 27018: public cloud, PII processing, provider acting as processor, and processing under contract for the customer.
Apply ISO/IEC 27017 to the broader service security boundary and map overlap without dropping privacy-specific controls.
Check applicable privacy law and contract separately; an ISO claim does not decide the legal role or establish legal compliance.
ISO/IEC 27017 evidence should show how provider and customer security duties work across the service. ISO/IEC 27018 evidence should additionally show the public-cloud scope and the privacy controls applied to processing on the customer's behalf.
Some records support both standards, such as the contract, access controls, incident records, deletion results, supplier information, and independent assurance. Reuse them only when the entity, service, role, data, location, control, period, and exception coverage match.
ISO/IEC 27017: responsibility matrix, cloud agreement, service description, customer configuration, access review, logs, backup or restore tests, change notices, and incident records.
ISO/IEC 27018: processing scope, processor instructions, PII locations and transfers, subprocessor records, disclosure handling, data-subject assistance, return or deletion evidence, and PII breach records.
Shared assurance: exact entity and service, applicable criteria, assessment period, exceptions, subservice organizations, and customer actions.
Decision record: role analysis, applicable edition, gaps, owner, remediation or risk decision, and review trigger.
First scope the cloud service and allocate security responsibilities under ISO/IEC 27017. Then identify PII, determine whether the service is public cloud, and document whether the provider acts as processor for the relevant processing.
Where ISO/IEC 27018 applies, add its privacy-specific control set and extended guidance. Map overlapping controls to shared evidence, but retain separate tasks for privacy purpose, instructions, disclosures, data-subject support, return or deletion, and other processor-specific outcomes.
Scope the service, deployment model, provider chain, data, regions, agreement, and provider/customer security boundary.
Identify PII processing and document controller or processor roles for each purpose rather than for the organization as a whole.
Map security and privacy controls, owners, evidence, gaps, and applicable legal or contractual duties.
Review the result when processing purpose, data, role, subprocessor, location, service, or contract changes.
Do not apply ISO/IEC 27018 to every cloud service merely because it stores account data. The scope depends on public-cloud processing of PII by a provider acting as processor. A service can contain several processing activities with different roles.
Do not treat ISO/IEC 27018 as a replacement for ISO/IEC 27017 or privacy law. It narrows the subject to public-cloud protection, while ISO/IEC 27017 covers broader cloud security and law supplies binding duties.
Do not use the withdrawn 2019 edition as the current baseline without a documented transition reason.
Do not infer the provider's processor role from a certificate; determine the role from the actual purposes and contract.
Do not assume security evidence covers processor-specific privacy controls.
Do not claim that either standard by itself establishes compliance with a jurisdiction's privacy law.
When should applicability and evidence be reviewed?
Review before onboarding and after changes to processing purpose, PII categories, controller or processor role, public-cloud status, region, subprocessor, service architecture, contract, or assurance scope. A PII breach or failed deletion test should trigger a targeted review.
For organizations moving from ISO/IEC 27018:2019, record how the 2025 edition's alignment with ISO/IEC 27002:2022 and extended implementation guidance affect the control map, evidence, and open remediation.
Keep the applicable standard edition in the service and control registers.
Recheck the legal role by processing purpose when the service or contract changes.
Track gaps to remediation or an authorized risk decision without presenting that decision as legal compliance.
Official ISO scope and lifecycle page for the published third edition, ISO/IEC 27018:2025, covering PII protection in public clouds where the provider acts as a PII processor.
"Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"