- August 1, 2026
- Posted by: Sage Shield Safety Consultants
- Category: Cybersecurity
ISO 27017 vs ISO 27018: Which Cloud Extension Do You Need?
If your Singapore business runs on the cloud — or sells a cloud product — and a customer has asked how you secure it, you will quickly meet two sibling standards: ISO 27017 and ISO 27018. Both extend an ISO 27001 certificate with cloud-specific controls, both are audited by the same certification body that issued your ISO 27001, and both are frequently added at a routine surveillance audit. But they answer different questions: 27017 answers the security question, 27018 answers the privacy question. This guide explains the difference and how to decide which — or whether both — you need.
What Is ISO 27017?
ISO/IEC 27017 is the international code of practice for cloud security controls. It takes the familiar ISO 27002 control set and adds cloud-specific implementation guidance — what access control, cryptography and operations security mean when your infrastructure is AWS, Azure, Google Cloud or a SaaS stack — plus seven controls that exist only in the cloud context: shared roles and responsibilities, removal of customer assets, tenant segregation, virtual machine hardening, administrator operational security, monitoring of cloud services, and alignment of virtual and physical network security.
Distinctively, ISO 27017 addresses both sides of the cloud relationship — cloud service providers and cloud service customers. A company that sells nothing cloud-based but runs entirely on Microsoft 365 and AWS still has a real 27017 scope. Full detail on our ISO 27017 Singapore service page.
What Is ISO 27018?
ISO/IEC 27018 is the international code of practice for protecting personally identifiable information (PII) in public clouds. It is written for cloud providers that process personal data on behalf of their customers — in practice, almost every SaaS product holding names, emails, HR records or customer lists. Its additional controls translate into concrete customer-facing commitments: processing only on the customer’s instructions, no use of PII for advertising without consent, transparency over sub-processors and storage locations, notification of law-enforcement disclosure requests, secure return and deletion of data, and defined breach notification.
For Singapore processors, those commitments map closely onto the PDPA’s protection obligation for data intermediaries — which is why 27018 pairs naturally with PDPA compliance work. Full detail on our ISO 27018 Singapore service page.
ISO 27017 vs ISO 27018: Side-by-Side Comparison
| ISO 27017 | ISO 27018 | |
|---|---|---|
| Question it answers | “How is the cloud secured?” | “What happens to our people’s personal data on your platform?” |
| Subject matter | Cloud security controls — all information, all workloads | Protection of PII specifically, in public clouds |
| Who it applies to | Cloud service providers and cloud service customers | Public cloud providers acting as PII processors |
| Typical buyer trigger | Security section of an enterprise vendor assessment; “do you have cloud-specific controls?” | Privacy section of a vendor assessment; a data-processing agreement (DPA); a DPO’s questionnaire |
| Standalone certificate? | No — extension of ISO 27001 scope | No — extension of ISO 27001 scope |
| How it’s audited | By your ISO 27001 certification body, typically at surveillance or within Stage 2 | Same — and commonly in the same audit as 27017 |
| Singapore regulatory tie-in | Supports outsourcing/vendor-risk expectations for cloud workloads | Audited evidence of the PDPA protection obligation for data intermediaries |
Key Differences That Matter
1. Security of everything vs privacy of personal data
ISO 27017 covers the security of all information in your cloud estate — source code, financials, configurations, customer data alike. ISO 27018 is narrower and deeper on one asset class: personal data, and the promises you make to the customers whose data it is. If a buyer’s concern is uptime, tenant isolation and admin access, that’s 27017 territory. If their concern is consent, sub-processors and deletion, that’s 27018.
2. Who the standard is written for
ISO 27018 is squarely aimed at providers processing PII for customers — a SaaS vendor, a hosting platform, a managed service holding client records. ISO 27017 is broader: even pure cloud consumers use it to govern what they demand and verify from their providers. A business that processes no third-party personal data may need only 27017; a SaaS processor almost always benefits from both.
3. The sales conversation each unlocks
Enterprise vendor assessments almost always have separate security and privacy sections, reviewed by different people — the CISO’s team and the DPO’s team. ISO 27017 pre-answers the first; ISO 27018 pre-answers the second. Holding only one often means the other section still triggers a long questionnaire.
Do You Need Both?
If you are a cloud business that processes customers’ personal data — which describes most SaaS companies — the practical answer is usually yes, and together. The two extensions share scoping work (the cloud service inventory and shared-responsibility mapping), share the Statement of Applicability exercise, and are assessed in the same audit visit. Certifying them together costs meaningfully less than doing them a year apart, and delivers a certificate whose scope line answers both halves of a vendor assessment at once.
If you process no personal data on behalf of others — say, an engineering firm running its own workloads in the cloud — ISO 27017 alone typically suffices. If your buyers’ questions are exclusively about privacy and your security assurance is already settled, 27018 alone can make sense, though this is the rarer case.
How They Certify: The ISO 27001 Extension Mechanic
Neither standard is certifiable on its own — both are codes of practice that certify as extensions of an ISO 27001 ISMS. Your Statement of Applicability is extended with the cloud (and/or PII) controls, your existing certification body audits them alongside the ISMS, and the standards are reflected on your certificate or in a statement of conformity. Two consequences follow:
- Already ISO 27001 certified? Either extension — or both — can typically be assessed at your next scheduled surveillance audit via a scope extension. No new Stage 1/Stage 2 cycle, which makes this one of the most cost-efficient certifications available.
- Not yet certified? The efficient route is a single project that builds the ISO 27001 ISMS with the cloud controls included, so one certification cycle delivers all of it. Our guide to ISO 27001 certification in Singapore covers the base journey.
Ready to extend your certificate — or build all three into one project? Sage Shield is an independent consultancy: we prepare the cloud-control and PII extensions end to end and coordinate the audit; a SAC-accredited certification body certifies. Explore our ISO 27017 and ISO 27018 services, or get in touch to discuss your scope — call or WhatsApp +65 8332 8220.
