731 901 601
Who should have ISO 27018 – and why it’s more important than you think

Who should have ISO 27018 – and why it’s more important than you think

When the name ISO 27018 is mentioned, most companies react in a similar way: “I suppose that’s for the big cloud providers, not for us.” And, as with many other regulations, this intuition is misleading. ISO 27018 applies to a much wider range of organisations than just hyperscalers such as AWS or Microsoft Azure. And for many of them, holding this certification is not so much a matter of good practice as a genuine market necessity.

Who is ISO 27018 aimed at – the list is longer than you might think

The ISO 27018 standard is aimed at all companies and organisations, regardless of their sector, size or legal form, that provide cloud services and therefore process their customers’ personal data in the cloud. In practice, this covers a very wide range of entities.

SaaS providers – companies offering software as a service: CRM systems, ERP systems, HR platforms, project management tools, medical systems, e-learning platforms. If your software processes end-customers’ personal data in the cloud – ISO 27018 applies to you.

IaaS and PaaS providers – companies offering cloud infrastructure or platforms on which their customers process their own data. Even if you have no direct contact with end-users’ personal data – if your infrastructure stores it, ISO 27018 is the relevant standard.

IT companies providing managed services (MSPs) – providers of managed IT services who, as part of their services, gain access to customers’ data stored in the cloud. Managing a customer’s infrastructure constitutes data processing – and gives rise to the obligations of a data processor.

Public institutions and administrative bodies – which provide cloud services; these may include public institutions such as schools, healthcare facilities or non-profit organisations. For such entities, ISO 27018 certification is proof of responsible management of citizens’ data.

Tech start-ups and scale-ups – companies in the growth phase that are securing their first major corporate clients or entering foreign markets. This is the point at which clients begin to require certifications – and the point at which a lack thereof can block a contract.

Why this is more important than you think – five scenarios that change your perspective

Scenario 1: A new corporate client asks about certification. The procurement department of a large company sends a security questionnaire before signing the contract. One of the questions is: “Do you hold an ISO 27018 certificate or equivalent?” A company without a certificate answers “no” and has to explain how else it guarantees data security. A company with a certificate answers “yes” and attaches the certificate number. The difference in the time taken to process the enquiry: a few hours vs. a few weeks.

Scenario 2: Public tender requiring certification. The tender specifications include a requirement for a cloud data security certificate. A supplier without a certificate cannot participate in the tender. Contract value: several hundred thousand zlotys per year. Cost of ISO 27018 certification: a fraction of that amount.

Scenario 3: An inspection by the Personal Data Protection Office following an incident. The Personal Data Protection Office initiates proceedings following a report of a breach. A company with ISO 27018 certification can demonstrate that it had in place and applied personal data protection management systems compliant with a recognised standard. This does not eliminate the risk of a fine – but it significantly influences the amount of the fine and the course of the proceedings.

Scenario 4: Expansion into the Western European market. A company enters the German or Scandinavian market. B2B customers there expect security certificates as the norm, not the exception. ISO 27018 is a recognised, established document that reduces discussions about security to a minimum.

Scenario 5: Due diligence prior to investment or acquisition. An investor or buyer conducts a due diligence audit. The absence of data security certificates is a red flag that may lower the valuation or complicate the transaction. An ISO 27018 certificate is proof that the company manages one of the key risks in cloud operations in a mature manner.

How to get started – and why it’s easier than it seems

For companies that already hold ISO 27001 certification, the path to ISO 27018 is much shorter than you might think. ISO 27018 is regarded as an extension of the certifiable ISO 27001 ISMS – which means that the system infrastructure, documentation and procedures of ISO 27001 form the foundation upon which the ISO 27018 system can be built relatively efficiently.

For companies that do not yet have ISO 27001 – implementing both standards in parallel is more cost-effective than implementing them sequentially. One implementation, one project, two certificates.

Read other posts

The most common mistakes when implementing ISO 22000 and how to avoid them

The most common mistakes when implementing ISO 22000 and how to avoid them

Establishing an ISO 22000 system requires the involvement of the entire organisation – from management to operational staff. akes, which result in non-conformities during the audit or the refusal to issue a certificate. read more
Key requirements of ISO/IEC 17025 – what must a testing laboratory comply with?

Key requirements of ISO/IEC 17025 – what must a testing laboratory comply with?

The ISO/IEC 17025:2018 standard sets requirements for laboratories on two levels simultaneously: the organisational level – concerning how the laboratory is managed – and the technical level read more
Cosmetics and household chemicals manufacturers supplying retail chains – what does the IFS HPC standard offer them?

Cosmetics and household chemicals manufacturers supplying retail chains – what does the IFS HPC standard offer them?

Cosmetics and household chemicals manufacturers supplying their products to European retail chains operate in a sector where product quality and safety requirements are constantly increasing. read more
More posts