Compliance framework

What is ISO 27017?

ISO 27017 is a code of practice that provides guidelines for information security controls applicable to cloud services. It extends ISO 27001 with cloud-specific controls for both cloud service providers and cloud service customers.

ISO 27017 addresses seven cloud-specific control areas that ISO 27001 does not explicitly cover, including shared responsibilities, virtual machine hardening, and administrator access to cloud environments. Vendors offering multi-tenant cloud services are increasingly expected to hold both ISO 27001 and ISO 27017.

Which vendors hold ISO 27017?

Search the TrustVendor vendor graph to see current certification status, evidence age, and expiry runway across all your vendors.

Common questions about ISO 27017

Which vendors hold ISO 27017 certification?
Search the TrustVendor vendor graph to see which vendors in your portfolio hold current ISO 27017 certification, when it was last verified, and how long until it expires. Certifications are tracked continuously and alerts fire when evidence ages past its half-life.
How often does ISO 27017 certification need to be renewed?
Renewal frequency depends on the framework. SOC 2 Type II reports typically cover a 12-month audit period and should be requested annually. ISO 27001 certificates are valid for three years with annual surveillance audits. FedRAMP authorizations require annual assessment. TrustVendor tracks expiry dates and alerts you 90, 60, and 30 days before lapse.
Can I verify a vendor's ISO 27017 report myself?
For certifications that produce a published artifact (ISO 27001 certificate, FedRAMP Marketplace listing), you can verify directly with the certifying body. For SOC 2, the report is issued by the auditing CPA firm and should be shared directly by the vendor under NDA. TrustVendor stores a sha256-hashed snapshot of every artifact it processes — you can verify the hash client-side using standard tooling.

Related frameworks

ISO 27001ISO 27018