- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Archlight is a vCISO / ISO 27001 consultancy based in Minneapolis, MN, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework Information Security & Privacy
ISO 27017
ISO/IEC 27017:2015 is a code of practice that adds cloud-specific implementation guidance to the ISO/IEC 27002 controls and introduces seven additional controls for cloud service providers and cloud customers, covering shared roles and responsibilities, removal and return of customer assets, segregation in virtual environments, virtual machine hardening, administrator operational security, monitoring of cloud services, and alignment of virtual and physical network security.
A second edition was in development as of early 2026; verify the current edition on the ISO site.
It is not a management system standard and cannot be certified on its own. Certification bodies issue ISO 27017 as an extension of an ISO/IEC 27001 certificate, so the organization must have a certified ISMS and then document how the 27017 controls are implemented: a shared responsibility matrix, cloud-specific policies and procedures, customer-facing documentation of security functions, and evidence of the added controls in the Statement of Applicability.
help
Who has to comply
Voluntary. Cloud service providers use it to demonstrate cloud-specific controls to enterprise and public sector customers; cloud customers can use it to structure their own obligations. No statutory trigger.
What the assessor asks to see
Valid ISO 27001 certificate and Statement of Applicability extended with the 27017 controls; shared responsibility matrix; cloud service agreements and customer documentation; virtual environment segregation and hardening evidence; administrator access and privileged activity monitoring; asset return and deletion procedures; monitoring of cloud service capability; network security alignment records.
Assessors
Who assesses ISO 27017
An accredited ISO/IEC 27001 certification body that includes ISO/IEC 27017 in the audit scope and issues a certificate or statement referencing 27017 alongside the 27001 certificate. Accredited by National accreditation bodies (ANAB, UKAS and peers) accredit the certification body for ISO/IEC 27001; 27017 coverage is added under that accreditation, and practice varies by body.
Public register of assessors: https://www.iafcertsearch.org/
No firm has claimed a ISO 27017 assessor listing yet. Claim yours →
Consultants
Who helps with ISO 27017
ISO 27001 consultancies add 27017 scope to an ISMS engagement: writing the shared responsibility model, extending the risk assessment to cloud controls, updating the Statement of Applicability and preparing evidence. Typically a few weeks of additional work on top of an ISO 27001 program.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- BEMO is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Coral Esecure is a vCISO / ISO 27001 consultancy based in New Jersey, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Cycore is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Genius GRC is a vCISO / ISO 27001 consultancy based in Woodstock, GA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Illumen is a vCISO / ISO 27001 consultancy based in Pacific Northwest, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Neutral Partners is a vCISO / ISO 27001 consultancy based in Miami, FL, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Soter Advisory is a vCISO / ISO 27001 consultancy based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Testpros is a vCISO / ISO 27001 consultancy based in Reston, VA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- TrustedCISO is a vCISO / ISO 27001 consultancy based in Remote, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for ISO 27017
Tools that name this framework in their own material.
Related reading
- ISO/IEC 27017:2015 code of practice for information security controlsExplains that 27017 is assessed inside the annual ISO 27001 audit and which cloud-specific controls that audit covers.Microsoft
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for ISO 27017
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with ISO 27017
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.