Compliance framework

What is ISO 27018?

ISO 27018 establishes controls for protecting personally identifiable information (PII) processed by public cloud service providers. It is often required by data protection officers and privacy counsel evaluating cloud vendors handling personal data.

ISO 27018 maps closely to GDPR requirements for processors and provides a recognized baseline for cloud vendors processing PII on behalf of customers. Certification indicates the vendor has implemented controls for consent, data minimization, transparency, and purpose limitation in their cloud processing activities.

Which vendors hold ISO 27018?

Search the TrustVendor vendor graph to see current certification status, evidence age, and expiry runway across all your vendors.

Common questions about ISO 27018

Which vendors hold ISO 27018 certification?
Search the TrustVendor vendor graph to see which vendors in your portfolio hold current ISO 27018 certification, when it was last verified, and how long until it expires. Certifications are tracked continuously and alerts fire when evidence ages past its half-life.
How often does ISO 27018 certification need to be renewed?
Renewal frequency depends on the framework. SOC 2 Type II reports typically cover a 12-month audit period and should be requested annually. ISO 27001 certificates are valid for three years with annual surveillance audits. FedRAMP authorizations require annual assessment. TrustVendor tracks expiry dates and alerts you 90, 60, and 30 days before lapse.
Can I verify a vendor's ISO 27018 report myself?
For certifications that produce a published artifact (ISO 27001 certificate, FedRAMP Marketplace listing), you can verify directly with the certifying body. For SOC 2, the report is issued by the auditing CPA firm and should be shared directly by the vendor under NDA. TrustVendor stores a sha256-hashed snapshot of every artifact it processes — you can verify the hash client-side using standard tooling.

Related frameworks

ISO 27001ISO 27017GDPR