Use ISO/IEC 27018 to design public-cloud processor controls and a SOC 2 report with Privacy to evaluate auditor-tested controls for a defined system, date, or period.
ISO/IEC 27018:2025 is the current edition. Clause-level examples here come from the withdrawn 2019 edition. A generic SOC 2 claim does not show that Privacy was included, and neither framework replaces applicable law or contract terms.
Use ISO/IEC 27018:2025 to choose and operate controls for a public-cloud provider acting as a PII processor. Use the actual SOC 2 report to see which Trust Services Criteria, system, controls, subservice organizations, customer controls, exceptions, date, and period an independent CPA examined. If Privacy is not listed in the report's scope, do not call it .
Side-by-side comparison
ISO/IEC 27018 vs SOC 2 Privacy: scope, duties, evidence, and decision rule
Compare control guidance for a public-cloud PII processor with a CPA attestation report that includes Privacy. Check the exact system, criteria, period, tests, exceptions, subservice treatment, and customer controls before reusing evidence.
Public-cloud PII processor guidance that can shape controls and evidence; it is not a SOC 2 report and does not define a SOC reporting period or auditor opinion.
Second framework
SOC 2 Privacy
A CPA attestation report on controls for a defined service-organization system against selected Trust Services Criteria. Privacy must be explicitly included; Type 1 addresses a date and Type 2 addresses a period.
ISO/IEC 27018 vs SOC 2 Privacy: scope, duties, evidence, and decision rule
Public-cloud providers processing customer PII under instruction; separate provider-controller activity and additional controller duties remain outside the direct scope.
A CPA attestation report on a defined service organization's system and selected Trust Services Criteria. Privacy is a separate category and is not established by a generic SOC 2 claim.
Provider privacy, security, legal, cloud operations, supplier, incident-response, and service owners operate the controls; customers retain authority over instructed processing.
Service-organization management describes the system and asserts that controls meet the criteria; control owners operate them; an independent CPA examines the assertion; user entities operate complementary controls.
Adopt when a public-cloud processor and customer need a recognized privacy-control baseline, or when a contract or assurance request names the standard.
Commissioned when management and intended users need a CPA attestation for a defined system, selected criteria, and either a specified date or operating period.
Management describes the system and controls and makes an assertion. The CPA evaluates the description, control design, and, for Type 2, operating effectiveness over the stated period.
Scope and role records, control applicability, contracts, operating samples, subprocessor and country notices, disclosure and incident records, deletion evidence, findings, and corrections.
Use the report itself, not a marketing page, to review the period, Privacy scope, tests, exceptions, carved-out providers, customer controls, and system boundary.
Type 1 addresses control design at a specified date; Type 2 also addresses operating effectiveness over a specified period. The report does not automatically cover later operations.
Keep the SOC 2 date or period separate from ISO assessment dates. A bridge letter may update management facts but does not extend the CPA's tested period.
Voluntary guidance can support internal audit, customer assurance, or a defined independent audit or certification arrangement; claims must name the service and criteria.
Produces a restricted-use attestation report with a CPA opinion. The conclusion is limited to the described system, selected criteria, date or period, and stated subservice method.
Service inventories, contracts, controls, tickets, logs, supplier records, incidents, deletion results, and audit evidence can be reused where scope and criteria match.
Choose it when the primary problem is protecting customer PII in a public-cloud processor service and making that control operation understandable to customers.
Choose a SOC 2 examination with Privacy when intended users need a CPA opinion and detailed tests of relevant controls for a defined service system, date, or period.
Public-cloud providers processing customer PII under instruction; separate provider-controller activity and additional controller duties remain outside the direct scope.
A CPA attestation report on a defined service organization's system and selected Trust Services Criteria. Privacy is a separate category and is not established by a generic SOC 2 claim.
Provider privacy, security, legal, cloud operations, supplier, incident-response, and service owners operate the controls; customers retain authority over instructed processing.
Service-organization management describes the system and asserts that controls meet the criteria; control owners operate them; an independent CPA examines the assertion; user entities operate complementary controls.
Adopt when a public-cloud processor and customer need a recognized privacy-control baseline, or when a contract or assurance request names the standard.
Commissioned when management and intended users need a CPA attestation for a defined system, selected criteria, and either a specified date or operating period.
Management describes the system and controls and makes an assertion. The CPA evaluates the description, control design, and, for Type 2, operating effectiveness over the stated period.
Scope and role records, control applicability, contracts, operating samples, subprocessor and country notices, disclosure and incident records, deletion evidence, findings, and corrections.
Use the report itself, not a marketing page, to review the period, Privacy scope, tests, exceptions, carved-out providers, customer controls, and system boundary.
Type 1 addresses control design at a specified date; Type 2 also addresses operating effectiveness over a specified period. The report does not automatically cover later operations.
Keep the SOC 2 date or period separate from ISO assessment dates. A bridge letter may update management facts but does not extend the CPA's tested period.
Voluntary guidance can support internal audit, customer assurance, or a defined independent audit or certification arrangement; claims must name the service and criteria.
Produces a restricted-use attestation report with a CPA opinion. The conclusion is limited to the described system, selected criteria, date or period, and stated subservice method.
Service inventories, contracts, controls, tickets, logs, supplier records, incidents, deletion results, and audit evidence can be reused where scope and criteria match.
Choose it when the primary problem is protecting customer PII in a public-cloud processor service and making that control operation understandable to customers.
Choose a SOC 2 examination with Privacy when intended users need a CPA opinion and detailed tests of relevant controls for a defined service system, date, or period.
How should teams use ISO/IEC 27018 alongside SOC 2 Privacy?
Define the public-cloud processor scope and ISO/IEC 27018 edition, then obtain the actual SOC 2 report and confirm that Privacy is included.
Map the Trust Services Criteria and tested controls to the relevant ISO guidance, preserving system boundary, subservice method, customer controls, populations, samples, period, and exceptions.
Collect separate evidence for every ISO control, legal duty, contract term, service, location, or time period that the SOC 2 report does not cover.
ISO/IEC 27018:2025 provides guidance for PII protection when a public-cloud provider acts as a processor. It builds on ISO/IEC 27002 and helps teams design controls, allocate provider and customer responsibilities, and explain how the service handles customer PII.
SOC 2 is an attestation examination, not a control standard for cloud processors and not a certification. Management describes a defined service-organization system and asserts that controls meet selected Trust Services Criteria; an independent CPA reports an opinion and the results of testing.
Security is addressed through the common criteria in a SOC 2 examination. Privacy is a separate Trust Services category and must appear in the report's selected criteria to support a claim.
For ISO/IEC 27018: define the public-cloud service, processor role, customer instructions, shared responsibilities, PII locations, sub-contractors, edition, and applicable controls.
For SOC 2: inspect the report's system boundary, selected criteria, Type 1 or Type 2, date or period, auditor opinion, exceptions, subservice method, and complementary user-entity controls.
For a combined claim: map controls and evidence criterion by criterion; do not infer equivalence from a logo, sales page, or report title.
A addresses the design of controls at a specified date. A also addresses operating effectiveness over a specified period. Neither automatically covers time before or after the stated date or period, services outside the system description, or Privacy when that category was not selected.
Read the auditor's opinion, management's assertion, system description, tests and results, exceptions, subsequent-event information, and any complementary user-entity controls. For subservice organizations, determine whether the report uses the inclusive method or the carve-out method; a carved-out provider's controls are not tested in that report.
An ISO/IEC 27018 assessment or certificate must also be read for the entity, service, edition, locations, exclusions, dates, criteria, and assurance basis. An edition-free claim is not enough.
Report facts: legal entity, system, services, locations, selected criteria, Type 1 date or Type 2 period, opinion, exceptions, and subsequent events.
Shared responsibilities: complementary user-entity controls and controls expected at carved-out subservice organizations.
Privacy scope: the specific Privacy criteria, related controls, populations, samples, tests, results, and exceptions.
ISO scope: edition, cloud-processor role, service boundary, applicable controls, assessment method, findings, and corrective actions.
Service boundaries, PII flows, policies, risk assessments, control ownership, access reviews, logs, sub-contractor records, incident samples, disclosure records, deletion tests, monitoring, and corrective actions can support both efforts when the scopes and criteria align.
Privacy criteria extend beyond security controls. A report that includes Privacy may examine notice, choice and consent, collection, use and retention, access, disclosure, data quality, and monitoring or enforcement processes. Map those criteria to the applicable ISO controls instead of assuming security evidence covers them.
Retain the source evidence once, with separate ISO clause and Trust Services Criteria references.
Preserve the population, sample, test procedure, result, exception, evidence period, and control owner used for each conclusion.
Identify customer-operated and carved-out subservice controls before concluding that the service organization operates the full control.
A SOC 2 report is not an ISO/IEC 27018 certificate. An ISO claim does not provide a CPA opinion, prove Type 2 operating effectiveness, or show that Privacy criteria were selected. A SOC 2 report with Privacy does not prove that every ISO/IEC 27018 control, cloud service, location, customer instruction, or sub-contractor is in scope.
Neither assurance route establishes compliance with every privacy law or contract. State the legal or contractual requirement separately and use the report or assessment only as evidence within its defined scope.
Do not call SOC 2 a certification or describe an ISO assessment as a SOC auditor opinion.
Do not say when the Privacy category is absent from the selected criteria.
Do not hide exceptions, carve-outs, customer controls, excluded services, stale periods, or open corrective actions.
Obtain the actual report or certificate under the required access terms. Verify the legal entity, service, system boundary, locations, selected criteria, Privacy inclusion, Type 1 date or Type 2 period, opinion, exceptions, subservice treatment, customer controls, subsequent events, ISO edition, exclusions, and assurance provider.
Follow up on every qualification or exception that affects the customer's processing. When the report period does not reach the review date, document the uncovered period and obtain appropriate current evidence instead of assuming the prior CPA tests extend beyond their stated period.
Assign an owner to report review, contract follow-up, customer controls, subservice evidence, exceptions, and corrective actions.
Recheck after service, system, criteria, sub-contractor, location, incident, opinion, report period, or ISO edition changes.
Record what the package does not cover so procurement, privacy, security, and service owners can collect the missing evidence.
AICPA's authoritative guide identifies SOC 2 as an assertion-based examination of a service organization's system description and controls and addresses control design and effectiveness.
The withdrawn edition supplies detailed historical examples for cloud-processor evidence, including instructions, disclosures, incidents, sub-contractors, locations, and disposal.
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"