Side-by-sideGlobalISO/IEC 27018

ISO/IEC 27018 ISO/IEC 27018 vs SOC 2 Privacy

Use ISO/IEC 27018 to design public-cloud processor controls and a SOC 2 report with Privacy to evaluate auditor-tested controls for a defined system, date, or period.

ISO/IEC 27018:2025 is the current edition. Clause-level examples here come from the withdrawn 2019 edition. A generic SOC 2 claim does not show that Privacy was included, and neither framework replaces applicable law or contract terms.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use ISO/IEC 27018:2025 to choose and operate controls for a public-cloud provider acting as a PII processor. Use the actual SOC 2 report to see which Trust Services Criteria, system, controls, subservice organizations, customer controls, exceptions, date, and period an independent CPA examined. If Privacy is not listed in the report's scope, do not call it .

Side-by-side comparison

ISO/IEC 27018 vs SOC 2 Privacy: scope, duties, evidence, and decision rule

Compare control guidance for a public-cloud PII processor with a CPA attestation report that includes Privacy. Check the exact system, criteria, period, tests, exceptions, subservice treatment, and customer controls before reusing evidence.

Review all sources
First framework
ISO/IEC 27018

Public-cloud PII processor guidance that can shape controls and evidence; it is not a SOC 2 report and does not define a SOC reporting period or auditor opinion.

Second framework
SOC 2 Privacy

A CPA attestation report on controls for a defined service-organization system against selected Trust Services Criteria. Privacy must be explicitly included; Type 1 addresses a date and Type 2 addresses a period.

Comparison row 1

Scope and covered activity

ISO/IEC 27018

Public-cloud providers processing customer PII under instruction; separate provider-controller activity and additional controller duties remain outside the direct scope.

SOC 2 Privacy

A CPA attestation report on a defined service organization's system and selected Trust Services Criteria. Privacy is a separate category and is not established by a generic SOC 2 claim.

Operational implication

Read the report's selected criteria. If Privacy is absent, the report may still provide useful security evidence but it is not .

Comparison row 2

Who must act

ISO/IEC 27018

Provider privacy, security, legal, cloud operations, supplier, incident-response, and service owners operate the controls; customers retain authority over instructed processing.

SOC 2 Privacy

Service-organization management describes the system and asserts that controls meet the criteria; control owners operate them; an independent CPA examines the assertion; user entities operate complementary controls.

Operational implication

Read complementary user-entity controls and determine whether each subservice organization is included or carved out before assigning responsibility.

Comparison row 3

Trigger or threshold

ISO/IEC 27018

Adopt when a public-cloud processor and customer need a recognized privacy-control baseline, or when a contract or assurance request names the standard.

SOC 2 Privacy

Commissioned when management and intended users need a CPA attestation for a defined system, selected criteria, and either a specified date or operating period.

Operational implication

A badge does not disclose the criteria, report type, opinion, period, exceptions, carve-outs, or customer controls. Review the report.

Comparison row 4

Core obligations

ISO/IEC 27018

Guidance supplements ISO/IEC 27002 controls with public-cloud processor responsibilities for instructions, purpose, customers, security, subcontracting, disclosure, incidents, and disposal.

SOC 2 Privacy

Management describes the system and controls and makes an assertion. The CPA evaluates the description, control design, and, for Type 2, operating effectiveness over the stated period.

Operational implication

Map ISO guidance to the exact Trust Services Criteria and tested controls. SOC 2 is an attestation, not a certification of ISO/IEC 27018.

Comparison row 5

Evidence and records

ISO/IEC 27018

Scope and role records, control applicability, contracts, operating samples, subprocessor and country notices, disclosure and incident records, deletion evidence, findings, and corrections.

SOC 2 Privacy

Auditor opinion, management assertion, system description, selected criteria, controls, tests and results, exceptions, subservice treatment, complementary user-entity controls, and subsequent-event information.

Operational implication

Use the report itself, not a marketing page, to review the period, Privacy scope, tests, exceptions, carved-out providers, customer controls, and system boundary.

Comparison row 6

Timing and cadence

ISO/IEC 27018

No statutory implementation deadline: cadence follows service changes, risk, contract, evidence expiry, incidents, audits, and the edition used.

SOC 2 Privacy

Type 1 addresses control design at a specified date; Type 2 also addresses operating effectiveness over a specified period. The report does not automatically cover later operations.

Operational implication

Keep the SOC 2 date or period separate from ISO assessment dates. A bridge letter may update management facts but does not extend the CPA's tested period.

Comparison row 7

Enforcement or assurance route

ISO/IEC 27018

Voluntary guidance can support internal audit, customer assurance, or a defined independent audit or certification arrangement; claims must name the service and criteria.

SOC 2 Privacy

Produces a restricted-use attestation report with a CPA opinion. The conclusion is limited to the described system, selected criteria, date or period, and stated subservice method.

Operational implication

A SOC 2 report is not an ISO/IEC 27018 certificate, and an ISO assessment does not provide a CPA opinion or Type 2 operating-effectiveness conclusion.

Comparison row 8

Overlap and reuse

ISO/IEC 27018

Service inventories, contracts, controls, tickets, logs, supplier records, incidents, deletion results, and audit evidence can be reused where scope and criteria match.

SOC 2 Privacy

Access, change, incident, supplier, disclosure, deletion, monitoring, notice, consent, collection, use, retention, access, quality, and enforcement evidence may overlap when Privacy is included.

Operational implication

Reuse source evidence only with separate criteria references, populations, samples, test methods, periods, exceptions, and conclusions.

Comparison row 9

Practical decision rule

ISO/IEC 27018

Choose it when the primary problem is protecting customer PII in a public-cloud processor service and making that control operation understandable to customers.

SOC 2 Privacy

Choose a SOC 2 examination with Privacy when intended users need a CPA opinion and detailed tests of relevant controls for a defined service system, date, or period.

Operational implication

Use ISO/IEC 27018 to design cloud-processor controls and to report on selected tested controls. Document every scope or criteria gap.

Practical decision rule

How should teams use ISO/IEC 27018 alongside SOC 2 Privacy?

  • Define the public-cloud processor scope and ISO/IEC 27018 edition, then obtain the actual SOC 2 report and confirm that Privacy is included.
  • Map the Trust Services Criteria and tested controls to the relevant ISO guidance, preserving system boundary, subservice method, customer controls, populations, samples, period, and exceptions.
  • Collect separate evidence for every ISO control, legal duty, contract term, service, location, or time period that the SOC 2 report does not cover.
Section 1

What decision does each framework answer?

ISO/IEC 27018:2025 provides guidance for PII protection when a public-cloud provider acts as a processor. It builds on ISO/IEC 27002 and helps teams design controls, allocate provider and customer responsibilities, and explain how the service handles customer PII.

SOC 2 is an attestation examination, not a control standard for cloud processors and not a certification. Management describes a defined service-organization system and asserts that controls meet selected Trust Services Criteria; an independent CPA reports an opinion and the results of testing.

Security is addressed through the common criteria in a SOC 2 examination. Privacy is a separate Trust Services category and must appear in the report's selected criteria to support a claim.

  • For ISO/IEC 27018: define the public-cloud service, processor role, customer instructions, shared responsibilities, PII locations, sub-contractors, edition, and applicable controls.
  • For SOC 2: inspect the report's system boundary, selected criteria, Type 1 or Type 2, date or period, auditor opinion, exceptions, subservice method, and complementary user-entity controls.
  • For a combined claim: map controls and evidence criterion by criterion; do not infer equivalence from a logo, sales page, or report title.
Section 2

What does the assurance scope tell a customer?

A addresses the design of controls at a specified date. A also addresses operating effectiveness over a specified period. Neither automatically covers time before or after the stated date or period, services outside the system description, or Privacy when that category was not selected.

Read the auditor's opinion, management's assertion, system description, tests and results, exceptions, subsequent-event information, and any complementary user-entity controls. For subservice organizations, determine whether the report uses the inclusive method or the carve-out method; a carved-out provider's controls are not tested in that report.

An ISO/IEC 27018 assessment or certificate must also be read for the entity, service, edition, locations, exclusions, dates, criteria, and assurance basis. An edition-free claim is not enough.

  • Report facts: legal entity, system, services, locations, selected criteria, Type 1 date or Type 2 period, opinion, exceptions, and subsequent events.
  • Shared responsibilities: complementary user-entity controls and controls expected at carved-out subservice organizations.
  • Privacy scope: the specific Privacy criteria, related controls, populations, samples, tests, results, and exceptions.
  • ISO scope: edition, cloud-processor role, service boundary, applicable controls, assessment method, findings, and corrective actions.
Section 3

Which evidence can support both efforts?

Service boundaries, PII flows, policies, risk assessments, control ownership, access reviews, logs, sub-contractor records, incident samples, disclosure records, deletion tests, monitoring, and corrective actions can support both efforts when the scopes and criteria align.

Privacy criteria extend beyond security controls. A report that includes Privacy may examine notice, choice and consent, collection, use and retention, access, disclosure, data quality, and monitoring or enforcement processes. Map those criteria to the applicable ISO controls instead of assuming security evidence covers them.

  • Retain the source evidence once, with separate ISO clause and Trust Services Criteria references.
  • Preserve the population, sample, test procedure, result, exception, evidence period, and control owner used for each conclusion.
  • Identify customer-operated and carved-out subservice controls before concluding that the service organization operates the full control.
Section 4

Which claims should teams avoid?

A SOC 2 report is not an ISO/IEC 27018 certificate. An ISO claim does not provide a CPA opinion, prove Type 2 operating effectiveness, or show that Privacy criteria were selected. A SOC 2 report with Privacy does not prove that every ISO/IEC 27018 control, cloud service, location, customer instruction, or sub-contractor is in scope.

Neither assurance route establishes compliance with every privacy law or contract. State the legal or contractual requirement separately and use the report or assessment only as evidence within its defined scope.

  • Do not call SOC 2 a certification or describe an ISO assessment as a SOC auditor opinion.
  • Do not say when the Privacy category is absent from the selected criteria.
  • Do not hide exceptions, carve-outs, customer controls, excluded services, stale periods, or open corrective actions.
Section 5

How should customers verify the package?

Obtain the actual report or certificate under the required access terms. Verify the legal entity, service, system boundary, locations, selected criteria, Privacy inclusion, Type 1 date or Type 2 period, opinion, exceptions, subservice treatment, customer controls, subsequent events, ISO edition, exclusions, and assurance provider.

Follow up on every qualification or exception that affects the customer's processing. When the report period does not reach the review date, document the uncovered period and obtain appropriate current evidence instead of assuming the prior CPA tests extend beyond their stated period.

  • Assign an owner to report review, contract follow-up, customer controls, subservice evidence, exceptions, and corrective actions.
  • Recheck after service, system, criteria, sub-contractor, location, incident, opinion, report period, or ISO edition changes.
  • Record what the package does not cover so procurement, privacy, security, and service owners can collect the missing evidence.
Primary sources

References and citations

aicpa-cima.com
Referenced sections
  • AICPA's authoritative guide identifies SOC 2 as an assertion-based examination of a service organization's system description and controls and addresses control design and effectiveness.
aicpa-cima.com
Referenced sections
  • AICPA source for SOC reporting context in ISO comparison pages.
"System and Organization Controls"
iso.org
Referenced sections
  • The withdrawn edition supplies detailed historical examples for cloud-processor evidence, including instructions, disclosures, incidents, sub-contractors, locations, and disposal.
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
iso.org
Referenced sections
  • Primary ISO listing for the 2025 edition of ISO/IEC 27018.
"Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"
Related guides

Explore more topics

ISO/IEC 27018 Audit Evidence FAQ
How to assess ISO/IEC 27018 audit evidence by edition, service scope, criteria, audit period, exceptions, and independent assurance.
ISO/IEC 27018 Breach Support FAQ
ISO/IEC 27018 breach support: when a cloud PII processor should notify a customer, what the contract should define, and what incident records to keep.
ISO/IEC 27018 Cloud Privacy FAQ
ISO/IEC 27018 FAQ on public-cloud PII processor scope, customer instructions, subprocessors, disclosures, breaches, deletion, audit evidence, and GDPR.
ISO/IEC 27018 Customer Instructions FAQ
What counts as a customer instruction under ISO/IEC 27018, how a cloud PII processor should validate it, and what evidence shows it was followed.
ISO/IEC 27018 DPA Clause Review Workflow
Review cloud data-processing terms for instructions, purpose limits, controls, subprocessors, disclosures, incidents, rights support, and deletion.
ISO/IEC 27018 GDPR Overlap FAQ
How ISO/IEC 27018 can support GDPR processor controls without replacing Article 28 terms, controller accountability, transfers, or breach duties.
ISO/IEC 27018 Government Access Evidence Guide
Build a controlled government-access case record showing request authentication, legal review, notice, approval, minimized disclosure, transfer, and closure.
ISO/IEC 27018 Government Access Evidence Workflow
Triage a government request for customer PII, validate authority, decide notice and challenge options, minimize disclosure, and preserve the decision record.
ISO/IEC 27018 Government Access FAQ
How ISO/IEC 27018 addresses legally binding law-enforcement requests: validation, customer consultation or notice, limited disclosure, and records.
ISO/IEC 27018 PII Return and Deletion FAQ
How to plan and prove PII return, transfer, deletion, anonymization, or archival across live systems, backups, temporary files, and subprocessors.
ISO/IEC 27018 Privacy Control Checklist
A practical ISO/IEC 27018:2025 checklist for public-cloud PII processors, with verifiable conditions, owners, evidence, exceptions, and edition controls.
ISO/IEC 27018 Processor Duties FAQ
What ISO/IEC 27018 expects from a public-cloud PII processor: customer instructions, purpose limits, security, transparency, incident support, and disposal.
ISO/IEC 27018 Public Cloud PII Processor Scope Guide
Decide whether a service fits ISO/IEC 27018's public-cloud PII processor scope, separate processor and controller activities, and document the boundary.
ISO/IEC 27018 Subprocessor Evidence Guide
Build subprocessor evidence that proves who processed customer PII, where, under which terms and controls, after which notice and approval, and with what exit result.
ISO/IEC 27018 Subprocessor Evidence Workflow
Assess and approve a cloud subprocessor, disclose its use and countries before processing, handle customer objections, and retain operating and exit evidence.
ISO/IEC 27018 Subprocessor Notice FAQ
What an ISO/IEC 27018 subprocessor notice should disclose, when customers should receive it, and what evidence should support consent and objections.
ISO/IEC 27018 Vendor Contract Requirements Guide
Contract guide for ISO/IEC 27018 public-cloud PII processing: scope, instructions, security, subprocessors, disclosures, incidents, rights support, audits, and exit.
ISO/IEC 27018 vs GDPR Comparison
Compare ISO/IEC 27018 cloud-processor guidance with GDPR legal duties, including scope, Article 28 contracts, breaches, transfers, evidence, and assurance limits.
ISO/IEC 27018 vs ISO/IEC 27701 Comparison
Compare ISO/IEC 27018:2025 cloud-processor guidance with the independent ISO/IEC 27701:2025 privacy management system, including scope, evidence, and assurance.
Using ISO/IEC 27018 for Public-Cloud PII Processing
Decide whether ISO/IEC 27018:2025 applies to a public-cloud PII processor, how it fits an ISMS, what evidence to keep, and which claims the evidence supports.