Don’t do SECURITY. Do business SECURELY.

ISO/IEC 27017:2026 cloud security standard published

ISO and IEC publish the second edition of ISO/IEC 27017, updating cloud security controls to align with ISO/IEC 27002:2022.

ISO and IEC have published ISO/IEC 27017:2026, the second edition of the code of practice for information security controls for cloud services, replacing the 2015 edition.

Key points

  • Provides cloud-specific guidance building on ISO/IEC 27002.
  • Applies to cloud service customers and cloud service providers.
  • Clarifies the division of security responsibilities between customers and providers.
  • Covers public, private and hybrid cloud deployments.
  • Brings the standard into line with the updated ISO/IEC 27002 control set.

Many UK organisations use ISO/IEC 27017 alongside ISO/IEC 27001 certification to show cloud security assurance. Cloud providers should review their controls and plan a transition, and customers should revisit shared responsibility models in their contracts.

Source: ISO/IEC 27017:2026 (ISO)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights