HomeFrameworksInformation Security & PrivacyISO 27017

Framework  Information Security & Privacy

ISO 27017

ISO/IEC 27017:2015 is a code of practice that adds cloud-specific implementation guidance to the ISO/IEC 27002 controls and introduces seven additional controls for cloud service providers and cloud customers, covering shared roles and responsibilities, removal and return of customer assets, segregation in virtual environments, virtual machine hardening, administrator operational security, monitoring of cloud services, and alignment of virtual and physical network security.

A second edition was in development as of early 2026; verify the current edition on the ISO site.

It is not a management system standard and cannot be certified on its own. Certification bodies issue ISO 27017 as an extension of an ISO/IEC 27001 certificate, so the organization must have a certified ISMS and then document how the 27017 controls are implemented: a shared responsibility matrix, cloud-specific policies and procedures, customer-facing documentation of security functions, and evidence of the added controls in the Statement of Applicability.

AI-compiled
Share
Sponsored
ISO
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with ISO 27017
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Voluntary. Cloud service providers use it to demonstrate cloud-specific controls to enterprise and public sector customers; cloud customers can use it to structure their own obligations. No statutory trigger.

What the assessor asks to see

Valid ISO 27001 certificate and Statement of Applicability extended with the 27017 controls; shared responsibility matrix; cloud service agreements and customer documentation; virtual environment segregation and hardening evidence; administrator access and privileged activity monitoring; asset return and deletion procedures; monitoring of cloud service capability; network security alignment records.

Assessors

Who assesses ISO 27017

An accredited ISO/IEC 27001 certification body that includes ISO/IEC 27017 in the audit scope and issues a certificate or statement referencing 27017 alongside the 27001 certificate. Accredited by National accreditation bodies (ANAB, UKAS and peers) accredit the certification body for ISO/IEC 27001; 27017 coverage is added under that accreditation, and practice varies by body.

Public register of assessors: https://www.iafcertsearch.org/

No firm has claimed a ISO 27017 assessor listing yet. Claim yours →

Consultants

Who helps with ISO 27017

ISO 27001 consultancies add 27017 scope to an ISMS engagement: writing the shared responsibility model, extending the risk assessment to cloud controls, updating the Statement of Applicability and preparing evidence. Typically a few weeks of additional work on top of an ISO 27001 program.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

ArchlightMinneapolis, MN, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Archlight is a vCISO / ISO 27001 consultancy based in Minneapolis, MN, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
BEMOUSANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
BEMO is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Control and FunctionDenver, CO, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Coral EsecureNew Jersey, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Coral Esecure is a vCISO / ISO 27001 consultancy based in New Jersey, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
CycoreMiami, FL, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Cycore is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Genius GRCWoodstock, GA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Genius GRC is a vCISO / ISO 27001 consultancy based in Woodstock, GA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
IllumenPacific Northwest, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Illumen is a vCISO / ISO 27001 consultancy based in Pacific Northwest, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Neutral PartnersMiami, FL, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Neutral Partners is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Securis360Pittsburgh, PA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Soter AdvisoryUSANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Soter Advisory is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TestprosReston, VA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Testpros is a vCISO / ISO 27001 consultancy based in Reston, VA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TrustedCISORemote, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
TrustedCISO is a vCISO / ISO 27001 consultancy based in Remote, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Related reading

  1. ISO/IEC 27017:2015 code of practice for information security controlsExplains that 27017 is assessed inside the annual ISO 27001 audit and which cloud-specific controls that audit covers.Microsoft

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for ISO 27017

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with ISO 27017

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.