ISO/IEC 27017 second edition updates cloud security controls

On July 27, 2026, ISO and IEC published ISO/IEC 27017:2026, the second edition of the cloud information security controls guidance. The catalogue lists the 2015 edition as withdrawn, with the new text as the current International Standard. If your Information Security Management System (ISMS) scope includes ISO/IEC 27017 (often alongside ISO/IEC 27001 and ISO/IEC 27018), the control set and structure you map to have changed.

What changed

ISO/IEC 27017 gives cloud-specific guidance on top of ISO/IEC 27002 for cloud service customers (CSCs) and cloud service providers (CSPs). The second edition is aligned to ISO/IEC 27002:2022. According to the foreword of the published standard, the main revisions are:

  • Title and scope updates
  • A restructured presentation of controls using a simple taxonomy and attributes (matching the 27002:2022 style)
  • Some controls merged or removed, and several new controls added

The document remains guidance for selecting and implementing controls based on risk assessment and legal, regulatory, or contractual needs. It applies across cloud deployment models, including private cloud (with adjustments where internal departments share roles). It is not itself a stand-alone certification scheme, but many organizations and certification bodies reference 27017 in ISO/IEC 27001 cloud scopes.

What is not changing

ISO/IEC 27001:2022 requirements are unchanged by this publication. ISO/IEC 27018 (public-cloud personally identifiable information guidance) is a separate document. Publication of 27017:2026 does not by itself create a new law or regulator mandate; contract language, customer expectations, and your certification body’s transition expectations drive the practical deadline.

What to do now

  1. Confirm whether your Statement of Applicability, cloud supplier agreements, or customer contracts still cite ISO/IEC 27017:2015.
  2. Obtain ISO/IEC 27017:2026 and run a control-by-control gap review against your current cloud CSC/CSP control set, using the correspondence annex in the new edition where helpful.
  3. Ask your certification body (or customers) how they will treat 27017:2015 references and when they expect alignment to the 2026 edition.
  4. Update shared-responsibility matrices, supplier security schedules, and evidence for any new or restructured cloud controls before your next surveillance or recertification.
  5. Follow ISO/IEC 27001 on this site for further cloud ISMS updates.

#version-updates#program-changes

← Back to news