HomeFrameworksInformation Security & PrivacyISO 27018

Framework  Information Security & Privacy

ISO 27018

ISO/IEC 27018:2019 is a code of practice for protecting personally identifiable information (PII) in public clouds when the provider acts as a PII processor.

It adapts the ISO/IEC 27002 controls for that role and adds a set of PII-specific controls drawn from the ISO/IEC 29100 privacy principles: processing only on customer instructions, no use of customer data for advertising without consent, notifying customers of legally binding disclosure requests, breach notification to the customer, secure return and deletion, disclosure of sub-processors and locations, and independent verification of controls.

Like ISO 27017, it cannot be certified alone. It is audited as an extension of an ISO/IEC 27001 certification, so the provider needs a certified ISMS plus documented PII processing policies, customer-facing terms that reflect the 27018 commitments, records of sub-processors and data locations, breach notification procedures and evidence that the extended controls appear in the Statement of Applicability.

The 2019 edition replaced the 2014 edition.

AI-compiled
Share
Sponsored
ISO
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with ISO 27018
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Voluntary. Public cloud providers processing customer PII, especially those selling into regulated sectors or the EU market where GDPR Article 28 processor duties apply. No statutory trigger, though it is often cited in vendor due diligence.

What the assessor asks to see

Valid ISO 27001 certificate and Statement of Applicability extended with the 27018 controls; PII processing policy and customer instructions process; customer contracts and privacy terms; sub-processor and data location register; breach notification procedure and records; data return and deletion procedures with evidence; access and encryption controls for PII; records of law enforcement disclosure requests; staff confidentiality agreements and training.

Assessors

Who assesses ISO 27018

An accredited ISO/IEC 27001 certification body that includes ISO/IEC 27018 in the audit scope and issues a certificate or statement referencing it. Accredited by National accreditation bodies (ANAB, UKAS and peers) under the certification body's ISO/IEC 27001 accreditation; practice for listing 27018 on certificates varies by body.

Public register of assessors: https://www.iafcertsearch.org/

No firm has claimed a ISO 27018 assessor listing yet. Claim yours →

Consultants

Who helps with ISO 27018

ISO 27001 and privacy consultancies add 27018 scope to an ISMS program: mapping processor obligations, drafting PII policies and customer terms, extending the risk assessment and Statement of Applicability, and preparing evidence. Usually a modest add-on to an ISO 27001 or ISO 27701 project.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

ArchlightMinneapolis, MN, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Archlight is a vCISO / ISO 27001 consultancy based in Minneapolis, MN, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
BEMOUSANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
BEMO is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Control and FunctionDenver, CO, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Coral EsecureNew Jersey, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Coral Esecure is a vCISO / ISO 27001 consultancy based in New Jersey, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
CycoreMiami, FL, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Cycore is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Genius GRCWoodstock, GA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Genius GRC is a vCISO / ISO 27001 consultancy based in Woodstock, GA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
IllumenPacific Northwest, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Illumen is a vCISO / ISO 27001 consultancy based in Pacific Northwest, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Neutral PartnersMiami, FL, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Neutral Partners is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Securis360Pittsburgh, PA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Soter AdvisoryUSANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Soter Advisory is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TestprosReston, VA, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
Testpros is a vCISO / ISO 27001 consultancy based in Reston, VA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TrustedCISORemote, USANot yet verified
What they do
VCISO / ISO 27001 consultancy
Who they help
TrustedCISO is a vCISO / ISO 27001 consultancy based in Remote, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Related reading

  1. ISO/IEC 27018 code of practice for protecting personal data in the cloudSets out what a public cloud processor has to prove under 27018 and how the code is audited alongside ISO 27001.Microsoft

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for ISO 27018

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with ISO 27018

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.