home / frameworks / iso-27017

// International standards

ISO/IEC 27017:2026

ISO/IEC 27017 adds cloud-specific guidance and extra controls to the ISO/IEC 27002 control set for cloud providers and customers. The second edition was published in July 2026 and replaces the 2015 edition.

InternationalISO/IEC 27017:2026 (Edition 2, July 2026)

Overview

ISO/IEC 27017 is a code of practice for information security in cloud services. It builds on ISO/IEC 27002 by adding cloud-specific implementation guidance to existing controls and by introducing extra controls for risks that come from shared infrastructure. The second edition, ISO/IEC 27017:2026, was published in July 2026 and has replaced the 2015 edition, which ISO lists as withdrawn. It follows the 2022 control set.

It speaks to 2 audiences. For each relevant control, it says what the cloud service customer should do and what the cloud service provider should do, which helps both parties see who is responsible for what. ISO now states plainly that it applies to all deployment models. That includes public, private, and hybrid clouds, and in a private cloud the customer and provider roles may be internal departments.

It has no management system. Organizations aren't certified to ISO/IEC 27017 alone. Cloud providers usually include its controls in the Statement of Applicability of an ISO/IEC 27001 certification and have the certification body review them during the same audit, often with a certificate or statement that refers to ISO/IEC 27017. Organizations holding certificates that reference the 2015 edition should ask their certification body how and when audits will move to the 2026 edition. In Canada, buyers often request this evidence alongside SOC 2 reports and CSA STAR entries.

Who it applies to in Canada

Cloud service providers and cloud service customers in public, private, and hybrid cloud models. It helps both sides divide and apply security controls when they share responsibility for a service.

Canadian cloud providers and SaaS vendors cite ISO/IEC 27017 to show cloud-specific security practices to buyers, and Canadian organizations moving workloads to the cloud use it to set out shared responsibilities in contracts. Federal guidance from the Canadian Centre for Cyber Security asks departments to rely on independent third-party assurance when assessing cloud providers.

Controls at a glance

The guidance follows the ISO/IEC 27002 themes, adding customer and provider guidance to relevant controls plus extra cloud-specific controls.

Shared roles and responsibilities

  • Agree and document who handles each security duty
  • Describe provider and customer roles in service agreements
  • Account for subcontractors and peer cloud providers
  • Tell customers which controls the provider operates

Organizational controls with cloud guidance

  • Cloud-aware security policies and supplier agreements
  • Inventory of customer assets held in the service
  • Legal jurisdiction and location of stored data
  • Incident reporting duties between provider and customer
  • Return or removal of customer assets at contract end

People and physical controls with cloud guidance

  • Awareness training on cloud-specific risks
  • Secure disposal and reuse of provider equipment
  • Protection of data centres that host customer data

Technological controls with cloud guidance

  • Separation of tenants in virtual environments
  • Hardening of virtual machines and images
  • Secure administration of cloud management consoles
  • Logging and monitoring that customers can use
  • Key management and encryption for customer data
  • Network security for virtual and physical networks

Customer responsibilities

  • Assess provider capabilities before adopting a service
  • Configure tenant-side settings and access securely
  • Manage own identities, keys, and backups where required
  • Review provider assurance reports and certificates

Certification and assessment

ISO/IEC 27017 isn't certified on its own. A cloud provider adds its controls to the ISO/IEC 27001 Statement of Applicability, and the certification body checks them during the ISMS audit. The result is usually shown on the ISO/IEC 27001 certificate or in a separate statement of conformity.

Dates to know

2026-07-27
ISO/IEC 27017:2026 (Edition 2) published, replacing the 2015 edition

Resources

Official texts and free tools for ISO 27017. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. ISO/IEC 27017:2026 Information security controls for cloud services, ISO
  2. Cloud security risk management (ITSM.50.062), Canadian Centre for Cyber Security