Skip to main content
Category: Cloud Security & Providers

ISO/IEC 27018

Also known as: ISO 27018, Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors
Simply put

ISO/IEC 27018 is an international standard that provides guidance for protecting personal information (referred to as personally identifiable information, or PII) when it is handled in public cloud services. It establishes commonly accepted control objectives, controls, and guidelines that a cloud service provider can implement when it processes such personal data on behalf of its customers. Because it is guidance rather than a binding law or a defense-specific requirement, readers should confirm how it maps to their own regulatory obligations.

Formal definition

ISO/IEC 27018 is a jointly published ISO and IEC standard that establishes commonly accepted control objectives, controls, and guidelines for implementing measures to protect personally identifiable information (PII) in public cloud computing environments, specifically addressing the cloud service provider acting as a PII processor. The standard is structured as a code of practice built upon the broader ISO/IEC 27002 information security controls, extending and supplementing them with cloud- and PII-specific guidance. Multiple revisions exist (the evidence references 2014, 2019, and 2025 editions), so practitioners should verify which revision applies to a given implementation or certification. As an international guidance standard, ISO/IEC 27018 is distinct from and does not by itself satisfy U.S. federal, defense, or CUI-handling requirements such as those under FISMA, FedRAMP, the RMF, or DFARS/CMMC; any such mapping must be confirmed against the applicable authoritative sources.

Why it matters

For organizations that entrust personal data to public cloud services, ISO/IEC 27018 offers a widely recognized reference point for evaluating how a cloud service provider protects personally identifiable information (PII) when acting as a PII processor. Because it establishes commonly accepted control objectives, controls, and guidelines specific to the public cloud context, it gives customers and providers a shared vocabulary for setting expectations around cloud PII handling, and it is frequently cited by major cloud providers as part of their broader compliance posture. This matters for compliance officers and security managers who need to assess third-party cloud services against a consistent, internationally published baseline rather than relying solely on vendor assertions.

Who it's relevant to

Compliance officers and privacy program leads
Those responsible for governing how personal data is handled in the cloud can use ISO/IEC 27018 as a reference for evaluating whether a cloud service provider has implemented recognized controls for protecting PII in its role as a processor. Because the standard is guidance rather than a binding law, they should map its provisions to their own regulatory and contractual obligations and confirm which revision applies.
Information system security managers assessing cloud providers
Security managers evaluating public cloud services can treat ISO/IEC 27018 alignment as one input into a broader assessment. Its foundation on ISO/IEC 27002 means it should be understood in the context of the underlying information security controls rather than in isolation, and its scope centers on the provider acting as a PII processor in public cloud environments.
Government contractors and defense-sector organizations
Contractors handling defense or federal data should note that, as an international guidance standard, ISO/IEC 27018 does not by itself satisfy U.S. federal, defense, or CUI-handling requirements such as those under FISMA, FedRAMP, the RMF, or DFARS/CMMC. Any reliance on a cloud provider's ISO/IEC 27018 alignment must be reconciled against those separate authoritative requirements, and a provider's conformance to this standard should not be assumed to establish authorization or compliance under U.S. frameworks.

Inside ISO/IEC 27018

Code of Practice for PII Protection in Public Cloud
ISO/IEC 27018 is an international standard, maintained by ISO and IEC, that provides a code of practice for protecting personally identifiable information (PII) in public cloud environments where the cloud provider acts as a PII processor. It is a guidance and control-augmentation document rather than a certifiable management system standard on its own.
Relationship to ISO/IEC 27001 and 27002
The standard is generally intended to supplement the controls in ISO/IEC 27002 within the context of an ISO/IEC 27001 information security management system. It adds cloud- and PII-specific implementation guidance and additional controls rather than replacing those base standards. Practitioners should confirm the applicable edition, as control mappings can change across revisions.
Focus on the Processor Role
ISO/IEC 27018 addresses obligations of cloud service providers acting as PII processors handling PII on behalf of customers (the PII controllers). It does not, by itself, resolve all obligations that fall on the controller, and readers should confirm role assignments against their own contracts and applicable law.
Privacy-Oriented Control Areas
The standard generally addresses matters such as consent and choice, purpose limitation for PII processing, transparency about processing and sub-processor use, data return and deletion, and handling of customer PII in accordance with instructions. Exact control text and coverage depend on the applicable edition and should be verified against the current authoritative document.
Scope Boundaries
This is a voluntary, non-binding international standard. It is distinct from U.S. federal compliance regimes such as FISMA, FedRAMP, the RMF under NIST guidance, or DoD CUI requirements, and adherence to ISO/IEC 27018 does not by itself satisfy those authorities.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27018.

Does certifying to ISO/IEC 27018 by itself make a cloud service provider compliant with U.S. federal requirements such as FedRAMP or the DoD RMF?
No. ISO/IEC 27018 is an international standard maintained by ISO and IEC that provides a code of practice for protecting personally identifiable information (PII) in public clouds acting as PII processors. It is not a U.S. federal authorization program. FedRAMP authorization (overseen by the FedRAMP PMO) and DoD authorizations under the Risk Management Framework rely on NIST SP 800-53 control baselines and their own assessment and authorization processes. A provider generally must satisfy those distinct requirements separately, and an ISO/IEC 27018 certification does not automatically map to or satisfy them. Confirm applicable requirements against the current authoritative sources for each program.
Is ISO/IEC 27018 a standalone information security standard that a provider can certify against on its own?
Generally no. ISO/IEC 27018 is designed as a sector- and role-specific extension that builds on the broader information security management system context associated with ISO/IEC 27001 and the guidance in ISO/IEC 27002. In most implementations it is applied as an add-on set of controls and implementation guidance for public-cloud PII processing rather than as an independent management system standard on its own. Readers should verify the intended relationship among these standards against the current published texts.
Who within an organization typically owns the effort to implement ISO/IEC 27018 controls?
In most implementations, ownership is shared between the information security function responsible for the underlying management system and privacy or data protection roles concerned with PII handling. Because ISO/IEC 27018 addresses a provider acting as a PII processor in a public cloud, coordination with legal, contracting, and cloud operations teams is generally needed. This entry does not prescribe an organizational structure; roles and responsibilities should be defined according to your governance model and confirmed against the standard's current text.
How does ISO/IEC 27018 relate to the controls we already implement under NIST SP 800-53 for a federal system?
ISO/IEC 27018 and NIST SP 800-53 are maintained by different bodies and serve different purposes: the former is an ISO/IEC code of practice for cloud PII processing, while SP 800-53 is a NIST control catalog used within federal authorization processes. They may address overlapping topics such as PII protection, but they are not interchangeable and do not map one-to-one. Any crosswalk between them should be treated as an organizational analysis to be validated, not as an established equivalence. Verify control applicability against the current authoritative publications.
Can we rely on a provider's ISO/IEC 27018 certification when assessing that provider as part of our own compliance program?
A provider's certification can be useful supporting evidence of its practices for protecting PII in a public cloud, but reliance on it should be qualified. In most implementations, you would review the certification scope, applicability, and currency, and confirm that the certified boundary covers the services you use. Because assessment is distinct from authorization, and because a certificate reflects a point-in-time evaluation, ongoing monitoring and contractual assurances are generally still needed. Confirm specifics against current documentation.
Does ISO/IEC 27018 satisfy our contractual or legal obligations for handling personal data or Controlled Unclassified Information (CUI)?
Not necessarily. Alignment with ISO/IEC 27018 does not by itself establish that contractual clauses, statutory obligations, or CUI protection requirements are met. Obligations for CUI in defense contexts, for example, are generally driven by separate authorities and requirements distinct from an ISO/IEC code of practice, and legal or contractual specifics are out of scope for this entry. Readers should confirm applicable obligations with counsel, contracting officers, and the current governing regulations and standards.

Common misconceptions

ISO/IEC 27018 is a standalone certification a provider can be certified against on its own.
It is generally applied as a supplement to an ISO/IEC 27001 management system and ISO/IEC 27002 controls, providing cloud PII-processor guidance. Certification is typically assessed in the context of the underlying management system standard; readers should confirm current certification scope and conformity assessment practices.
Alignment with ISO/IEC 27018 satisfies U.S. federal or defense privacy and security requirements.
ISO/IEC 27018 is a voluntary international standard and is separate from federal civilian requirements under FISMA, cloud authorization under FedRAMP, the RMF, or DoD CUI protection obligations. Meeting it does not automatically demonstrate compliance with those distinct authorities, which must be verified independently.
Conformance with ISO/IEC 27018 makes the cloud provider solely responsible for PII protection.
The standard focuses on the provider's role as a PII processor, but obligations remain with the PII controller (typically the customer). It does not eliminate controller responsibilities, and specific allocation of duties should be confirmed in contracts and against applicable law.

Best practices

Confirm the specific edition of ISO/IEC 27018 in use and verify its control content and mappings against the current authoritative ISO/IEC text, since guidance can change across revisions.
Implement ISO/IEC 27018 as a supplement to an ISO/IEC 27001 management system and ISO/IEC 27002 controls rather than treating it as a self-contained framework.
Clearly document controller and processor roles in contracts, including instructions for PII processing, sub-processor use, and data return or deletion, and confirm these against applicable law.
Do not assume ISO/IEC 27018 alignment satisfies FISMA, FedRAMP, RMF, or DoD CUI requirements; map and validate those obligations separately against their governing authorities.
Treat ISO/IEC 27018 conformance as one input to, not a substitute for, a broader privacy and security program, and verify residual controller responsibilities.
Engage qualified assessors and legal or compliance counsel to confirm how the standard applies to your specific cloud arrangement and jurisdiction before relying on it for assurance.