ISO 27017:2026 Explained: Key Changes, New Cloud Controls, and What It Means for Certification

Cloud adoption continues to accelerate, especially with the growth of Artificial Intelligence (AI) applications, and organisations are increasingly relying on cloud providers to host their critical systems, process sensitive information, and deliver services. In response, ISO 27017:2026 has been released as a major update to the cloud security standard, bringing it into alignment with ISO 27002:2022 and addressing modern cloud security challenges.

For cloud service providers (CSPs) and cloud service customers (CSCs), the new edition introduces a revised structure, updated guidance, and several new cloud-specific controls that reflect today’s cloud-first IT environment.

What is ISO 27017?

ISO 27017 provides cloud security guidance based on the controls contained within ISO 27002, as used in Annex A of ISO 27001 the ISMS standard. The standard is specifically designed for organisations that provide cloud services and those that use them. It supplements general information security controls with cloud-specific guidance and additional cloud-focused controls.

A key feature of ISO 27017 is its recognition that cloud security is a shared responsibility. The standard differentiates between:

  • CSC (Cloud Service Customer): The organisation purchasing or consuming cloud services.
  • CSP (Cloud Service Provider): The organisation delivering cloud services.
  • CSN (Cloud Service Partner): Supporting organisations such as cloud auditors, cloud service brokers, or cloud service developers.

This distinction helps organisations understand which security responsibilities sit with the provider and which remain with the customer.

What Has Changed in ISO 27017:2026?

The 2026 edition represents the first major revision since ISO 27017:2015. ISO states that the update includes several significant changes:

  • Modification of the title and scope.
  • Alignment with the structure and taxonomy of ISO/IEC 27002:2022.
  • Merging and removal of certain controls.
  • Introduction of new controls and updated guidance.

Unlike the previous version, the new standard adopts the same organisational, people, physical and technological control structure used throughout ISO 27002:2022. This makes implementation far easier for organisations already operating an ISO 27001 Information Security Management System (ISMS).

The standard also introduces a more mature approach to cloud governance, virtualisation, monitoring, configuration management and shared responsibilities. These areas have become increasingly important as organisations move towards SaaS, PaaS, IaaS, hybrid cloud and multi-cloud environments.

Greater Focus on CSC and CSP Responsibilities

One of the most noticeable changes is the enhanced focus on the relationship between cloud customers and cloud providers.

The standard acknowledges that cloud services create a complex supplier relationship where security responsibilities are often shared and it highlights the need for clear allocation of responsibilities between CSCs and CSPs, particularly where information security controls cannot be fully managed by the customer.

The revised guidance provides dedicated instructions for both CSCs and CSPs throughout the standard, helping each party understand their obligations and reducing the risk of security gaps.

New CLD Controls Introduced in ISO 27017:2026

One of the most important updates is the introduction of four dedicated cloud-specific controls prefixed with CLD (Cloud Extended Controls). These controls address areas that are unique to cloud environments and cannot be fully covered through traditional information security controls alone.

CLD 5.38: Shared Roles and Responsibilities Within a Cloud Computing Environment

This control formalises one of the most fundamental principles of cloud security: shared responsibility.

The control requires information security responsibilities to be allocated, documented, communicated and implemented by both the CSC and CSP. The objective is to ensure there is no ambiguity regarding which organisation is responsible for specific security activities.

For organisations using Microsoft Azure, AWS or Google Cloud, this control reinforces the need to clearly define where provider responsibilities end and customer responsibilities begin.

CLD 5.39: Agreement on the Roles and Responsibilities of the Cloud Service Partner

This is a completely new control with no equivalent in the 2015 edition.

It requires information security roles and responsibilities to be defined when a Cloud Service Partner (CSN) is involved. Examples include:

  • Cloud service brokers
  • Cloud auditors
  • Cloud service developers 

As cloud ecosystems become increasingly interconnected, this control ensures third-party cloud partners are properly governed and contractually managed.

CLD 8.35: Segregation in Virtual Computing Environments

Multi-tenancy environments remain one of the defining characteristics of cloud computing.

This control requires cloud environments to be protected from unauthorised access through effective segregation between tenants. CSPs must ensure logical separation of customer data, applications, operating systems, storage and networks to prevent one customer’s environment affecting another’s. 

The control also requires segregation between customer environments and provider administrative systems, strengthening protection within shared cloud architectures.

CLD 8.36: Detection and Prevention of Unauthorised Use of Cloud Services

Another entirely new control, CLD 8.36 addresses cloud usage monitoring and detection capabilities.

The control requires monitoring of cloud service usage to prevent unauthorised access, data transfers and other potentially risky activities. It encourages organisations to implement:

  • User activity monitoring
  • Detection of unusual resource consumption
  • Monitoring of unauthorised data transfers
  • Compliance monitoring against cloud security policies
  • Identification of abnormal behaviour and anomalies

This reflects growing concerns around shadow IT, excessive permissions, cloud misconfigurations and insider threats.

Relationship Between ISO 27017 and ISO 27001

ISO 27017 does not operate as a standalone management system standard. Instead, it provides cloud-specific control guidance that complements the Annex A controls of ISO 27001. 

The standard explicitly references ISO 27001 for information security risk management requirements and recommends that CSCs and CSPs use ISO 27001 processes when assessing and treating cloud security risks.

In practical terms:

  • ISO 27001 defines the requirements for establishing and operating an Information Security Management System (ISMS).
  • ISO 27017 provides cloud-specific implementation guidance and additional cloud controls.
  • ISO 27018 can be added where personal data protection in public cloud environments is required.

Together, these standards form a robust framework for managing cloud security risks.

Is ISO 27001 Required to Achieve ISO 27017 Certification?

In reality, yes.

Although ISO 27017 itself is a guidance standard rather than a management system standard, certification is normally achieved as an extension to an existing ISO 27001 certification. Because ISO 27017 builds directly upon ISO 27001 and ISO 27002 controls, certification bodies generally assess ISO 27017 as an additional cloud security framework alongside an ISO 27001-certified ISMS.

Organisations seeking ISO 27017 certification should expect to:

  1. Implement and maintain an ISO 27001-compliant ISMS.
  2. Apply relevant cloud-specific controls and guidance from ISO 27017.
  3. Demonstrate cloud security governance, risk management and responsibility allocation for CSC and CSP activities.
  4. Undergo certification assessment against both standards.

For most organisations, ISO 27001 is effectively a prerequisite for ISO 27017 certification.

Why ISO 27017:2026 Matters

The updated standard addresses many of the security challenges facing modern cloud environments, including multi-cloud deployments, cloud supply chains, virtualisation security, customer-provider responsibility models and cloud monitoring. 

For cloud providers, certification demonstrates strong security governance and accountability. For cloud customers, it provides confidence that cloud security responsibilities have been clearly defined and managed.

As businesses continue to migrate critical workloads into the cloud, ISO 27017:2026 offers an increasingly important framework for protecting information, managing shared responsibility risks and supporting trusted cloud services.

How Assent Risk Management Can Help

At Assent Risk Management, we help organisations achieve and maintain ISO 27001, ISO 27017 and ISO 27018 certification. Whether you are a cloud service provider looking to demonstrate security assurance or a business seeking to strengthen cloud governance, our consultants can support your implementation, internal audits, gap assessments and certification readiness programmes.

Contact Assent Risk Management today to discuss your ISO 27017 compliance journey and discover how the new ISO 27017:2026 requirements could affect your organisation.

Robert Clements
Robert Clements
Articles: 360