731 901 601
Is ISO 27017 mandatory? When is it worth getting certified, even if you don’t have to

Is ISO 27017 mandatory? When is it worth getting certified, even if you don’t have to

One of the first questions our clients ask us is: “Do we have to have ISO 27017?” The answer is simple – no, certification is not legally mandatory. But that is just the start of the conversation. Because the real question is: can your company afford not to have it?

In an era when most business processes are moving to the cloud, and customers and partners are looking ever more closely at who they entrust their data to, ISO 27017 certification is no longer just a document. It has become a signal – that the organisation takes security seriously.

ISO 27017 – a voluntary standard, but one that is increasingly expected

ISO/IEC 27017 is an international standard providing guidelines on information security in cloud services. You won’t find it on the list of mandatory regulations – no EU law or regulation requires companies to implement it. We discussed the scope of the standard and its requirements in more detail in our article on ISO 27017.

However, the market operates according to its own rules. It is becoming increasingly common for:

  • large corporations and public institutions to require their IT suppliers to have a documented approach to cloud security,
  • tenders and requests for proposals to include the criterion of holding certificates from the ISO 27000 family,
  • business partners ask directly about data protection standards in cloud environments during due diligence.

Who should consider certification first?

Not every company needs to seek certification straight away. However, there are situations in which implementing ISO 27017 is particularly justified:

  1. Cloud and SaaS service providers
    If your company offers software or infrastructure in a cloud-based model, certification is almost a natural next step after ISO 27001. It shows customers that the security of their data is a priority for you – not just in theory.
  2. Companies serving corporate or public sector clients
    Large organisations are increasingly auditing their suppliers. Holding the certificate streamlines this process and builds trust even before a contract is signed.
  3. Organisations processing sensitive data in the cloud
    Medical data, financial data, customers’ personal data – the more sensitive the information, the stronger the protection should be, and the more important it is to document it.
  4. Companies planning to expand into foreign markets
    ISO 27017 is a globally recognised standard. The certificate can open doors to markets where security standards are verified as early as the negotiation stage.

What are the benefits of getting certified ‘ahead of the curve’?

Companies that decide to get certified before it becomes a market requirement gain several tangible advantages:

  • A competitive edge – you stand out from companies that haven’t done so yet.
  • Better negotiating position – a client who sees the certificate is less likely to question your security credentials.
  • Internal order – the process of implementing the standard often reveals gaps and inefficiencies that are worth addressing regardless of certification.
  • Peace of mind during inspections and audits – when questions arise about data security in the cloud, you have a ready, documented answer.

How to get started?

Implementing ISO 27017 does not have to be a project starting from scratch. If your organisation already holds ISO 27001 certification, you have a solid foundation – the 27017 standard is an extension of it, focused on the specific nature of cloud environments.

A good starting point is a gap analysis – an assessment of what is already in place within your organisation and what needs to be addressed. This allows you to realistically estimate the time, costs and scope of the project before making a final decision.

ISO 27017 is not mandatory – but ‘not mandatory’ does not mean ‘unimportant’. In an environment where data in the cloud is one of the most valuable business assets, certification serves as proof of an organisation’s maturity. The question is not “do we have to?”, but “can we afford to let the competition have what we lack? If you need support in preparing your organisation for ISO 27017 certification, we can help you through the entire process.

Read other posts

The FSC logo on packaging – why are customers starting to demand it, and what does this mean for your printing company?

The FSC logo on packaging – why are customers starting to demand it, and what does this mean for your printing company?

Packaging manufacturers and printing houses serving the FMCG, food and cosmetics sectors are increasingly hearing a new question from their customers at the quotation stage: “Do you hold FSC certification?” read more
ISO 14001:2026 in practice – how to prepare your company step by step?

ISO 14001:2026 in practice – how to prepare your company step by step?

The publication of ISO 14001:2026 means that many organisations will need to update their environmental management systems. read more
Key differences: ISO 9001:2015 vs ISO 9001:2026

Key differences: ISO 9001:2015 vs ISO 9001:2026

A comparison of the ISO 9001:2015 version with the planned update for 2026 reveals a clear direction for the development of quality management systems. read more
More posts