731 901 601
ISO/IEC 27017:2026 and ISO 27001 certification – how to prepare your company for the changes

ISO/IEC 27017:2026 and ISO 27001 certification – how to prepare your company for the changes

The publication of the second edition of the ISO/IEC 27017:2026 standard raises a question that every company using the cloud or providing cloud services will sooner or later ask itself: do we need to make any changes to our existing information security management system, and how much work will this entail? The answer depends on what stage of implementation the organisation is at – but there are a few rules that apply to everyone.

Key facts at a glance

For those who are just beginning to explore the subject, here are a few points of reference:

  • ISO/IEC 27017:2026 is the second edition of the standard, published on 27 July 2026, replacing the previous version from 2015.
  • The standard does not stand alone – it is an extension of an information security management system compliant with ISO/IEC 27001, which is the standard for which certification is actually sought.
  • The abbreviations CSP (Cloud Service Provider) and CSC (Cloud Service Customer) refer to the provider and customer of cloud services respectively – the standard addresses the obligations of both parties.
  • Organisations that have previously been certified are usually granted a standard three-year transition period to adapt their system to the new edition.
  • Compliance with the standard is verified as part of an ISO/IEC 27001 audit – there is no separate, distinct certification process exclusively for ISO/IEC 27017.

Who is most affected by the change

The new edition is of greatest significance to two groups of organisations:

  • Cloud service providers (CSPs), who use compliance with the standard as a selling point and a means of building trust with institutional clients.
  • Cloud service customers (CSCs), who rely on the standard’s requirements as a benchmark in their contracts with providers and in their vendor risk management processes when assessing whether a provider adequately secures the data entrusted to them.

In both cases, the update to the standard serves as a signal to review existing documentation – statements of application, SLAs, and supplier assessment procedures – to check whether they still refer to the outdated 2015 version.

Transition period – how much time is allowed for compliance

Organisations certified against the previous version of the standard do not usually have to act under immediate time pressure. It is standard practice for this type of revision to set a three-year transition period, during which existing certificates remain valid and organisations gradually adapt their systems to the new edition during subsequent surveillance or recertification audits. This is sufficient time to plan the changes without having to rush to complete them at the last minute – provided that the process is started early enough.

Where to start with the system update

It is advisable to break down the practical adaptation to the second edition of the standard into several stages:

  1. Mapping structural changes – as the security controls have been transferred to a new taxonomy compliant with ISO/IEC 27002:2022, the first step is to cross-reference the old and new numbering so that no requirement is ‘lost’ during the transition.
  2. Verification of the Statement of Application (SoA) – this document must reflect the current set of security controls, including the reduced number of controls prefixed with ‘CLD’ and the new areas concerning cloud intermediaries and shadow IT.
  3. Updating agreements with cloud partners – if the supply chain involves brokers, integrators or external auditors, it is worth checking whether their roles and responsibilities are described in accordance with the new guidelines.
  4. Reviewing the technical architecture in light of the new guidelines – this applies in particular to organisations using containerisation and serverless models, for which the previous edition of the standard provided virtually no specific guidance. It may be helpful to review the methods for effectively securing data in the cloud already outlined as general best practices.
  5. Preparing the team for the upcoming audit – both internal auditors and those responsible for liaising with the certification body should be familiar with the scope of the changes well before the surveillance audit date.

Is it worth waiting to update?

The three-year transition period can be a tempting argument for putting the matter off until later. In practice, however, organisations that view compliance with the standard as a genuine means of building trust – rather than merely a formality for audit purposes – stand to gain from adapting their systems sooner. This applies in particular to cloud providers, for whom an up-to-date statement of compliance is often a key element in responding to requests for proposals from larger institutional clients, who are increasingly verifying that providers comply with the latest versions of standards, rather than simply holding a certificate.

 

Read other posts

The 2022 update to ISO 27001

The 2022 update to ISO 27001

On 23 September 2022, the new ISO 27001:2022 standard was approved. Find out what changes the update to the information security standard has brought! read more
Designing packaging in accordance with the PPWR – what should you bear in mind?

Designing packaging in accordance with the PPWR – what should you bear in mind?

New regulations on packaging and packaging waste introduce a significant change in the approach to packaging design. read more
The second edition of ISO/IEC 27017:2026 – key changes to cloud security

The second edition of ISO/IEC 27017:2026 – key changes to cloud security

For ten years, organisations implementing cloud service security have relied on a document written in a different technological era. read more
More posts