ISO/IEC 27017 · Certification bodies

A quality review on the cloud controls in every ISO/IEC 27001 report.

The second edition landed in July 2026 and realigned the standard onto ISO/IEC 27002:2022. Upload the report and get an automated AI QA review: which edition was audited, whether the cloud controls are in the Statement of Applicability, and whether the split of responsibility between provider and customer is written down. Reviewed and signed by you.

Provider and customer
both sides of every shared control
Two editions
2015 and 2026, told apart
Consistent
the same QA pass every time
forauditsNorthgate Certification
audit-report.pdf
Standard detectedISO/IEC 27017:2026
A.5.23cloud security
A.5.21ICT supply chain
A.8.31separation of environments
Partner firm of the Portuguese Quality Institute

Cloud controls arrive inside an audit that was not designed for them.

ISO/IEC 27017 is not certified on its own. It is a code of practice that adds guidance to the ISO/IEC 27002 controls plus a few controls specific to cloud services, and it reaches the certificate from inside the ISO/IEC 27001 scope. That leaves the reviewer with a problem the standard does not solve: working out whether the report addresses the cloud service customer, the provider, or both, and whether each finding falls on the right side of that line. A finding written against the provider in a customer's report is not a nonconformity, it is a change of subject. Since July 2026 there is a question that comes before all of them: which edition it was written against.

How the review works

From report upload to a signed review.

01

Upload the report

Drop an ISO/IEC 27001 audit report whose scope includes the ISO/IEC 27017 cloud controls (PDF, DOCX or XLSX). foraudits validates it and starts the review.

forauditsNorthgate Certification
Upload report
Drop your draft reportPDF · DOCX · XLSX · up to 50 MB
report-draft.docxValidated
forauditsaudit-report.pdf
Standard detectedISO/IEC 27017:2026
A.5.23cloud security
A.5.21ICT supply chain
A.8.31separation of environments
02

Our AI engine reviews it

foraudits detects which edition is in play, walks the cloud controls against the Statement of Applicability, and flags where the role, provider or cloud service customer, is undeclared or shifts partway through the report.

03

Reviewed report, with comments

You get the report annotated with findings and gaps tied to the control at issue. The decision and the sign-off stay yours.

forauditsreport-draft.docx
Reviewed by AI specialist
ISO/IEC 27017:2026
Shared responsibility
boundary undefined
Audited edition identified in the report
What we check, by clause and control

Every finding tied to the most specific control.

With the Statement of Applicability checked against the risk, and the distinction between correction and corrective action required by ISO/IEC 17021-1.

EditionWhich edition of ISO/IEC 27017 the report audits, and whether it says so
ScopeCloud services covered, and the role audited in each
SoACloud controls declared in the Statement of Applicability
SplitDivision of responsibility between provider and cloud service customer
A.5Organizational controls carrying cloud guidance
A.8Technological controls carrying cloud guidance
Anchored to the right references
ISO/IEC 27017:2026ISO/IEC 27001:2022ISO/IEC 27002:2022ISO/IEC 17021-1Independent certification decision
From review to creating the report

One engine, many audit types.

Once you are reviewing, we build the full flow for your standard: forms, checklists and the report. The same engine that reviews cloud controls also runs energy audits and NIS2 supply-chain compliance, where the same question about suppliers comes back.

Trust

Built for certification bodies in the EU.

The engine is yours. So is the client relationship.

EU data residency
Storage and processing in the European Union, including AI review.
GDPR-aligned
Handled to GDPR standards by default.
Isolated per auditor
Your reports never mix with another body's.
No model training
Your documents never train our models.
Unlimited users
Your whole team, no per-seat fees.

Questions about ISO/IEC 27017 report review.

Is there such a thing as ISO/IEC 27017 certification?
Not on its own. ISO/IEC 27017 is a code of practice rather than a requirements standard, so there is no accredited certificate for it alone. The cloud controls are audited within the ISO/IEC 27001 scope and referenced in the scope of the certificate the certification body issues.
What changed in the 2026 edition of ISO/IEC 27017?
The second edition was published in July 2026, titled Information security, cybersecurity and privacy protection, Information security controls based on ISO/IEC 27002 for cloud services. The structural change is the realignment onto ISO/IEC 27002:2022: the 2015 edition sat on the earlier ISO/IEC 27002 structure, so control-for-control mapping is no longer direct. The full text is ISO's and that is where the list of changes should be confirmed.
What is the review run against?
ISO/IEC 27017:2026, together with the ISO/IEC 27001:2022 and ISO/IEC 27002:2022 that give it its structure. The review detects when a report was written against the 2015 edition and flags it, because both are in circulation through the transition.
Does the review tell the cloud service provider and customer apart?
Yes, and it is the central check for this standard. ISO/IEC 27017 addresses both, and the same measure means different things depending on the side. The review flags the controls where the report does not declare which role is being audited.
Does foraudits change the report?
No. The review returns findings and comments tied to the control. The wording, the decisions and the signature stay with whoever runs the audit.
Is foraudits a certification body?
No. foraudits is not a certification body and is not accredited to certify, attest or verify. It reviews the report against the standard and returns the analysis; the decision and the signature stay with the competent body.

Let's review one of your reports covering cloud controls.

Book a demo and we'll review a report with ISO/IEC 27017 in scope, end to end.

foraudits is not an accredited certification body; the decision and signature belong to the reviewer.