About ISO 27018 and 27018 certification
Just a few steps to cloud certification
ISO 27017 and ISO 27018, both based on ISO 27001, have been specially adapted to the specific requirements of cloud service providers. ISO 27017 is primarily concerned with the relationship between providers and their customers. As part of the ISO 27017 audit, our experts help you identify key security elements that improve the quality and reliability of your cloud services.
ISO 27018 specifically addresses the requirements of data protection law. The focus here is mainly on the processing of personal data within the cloud.
Certification is based on ISO 27001 supplemented by the applicable standard. Depending on your individual needs, we offer certification for both standards combined or each one independently.
Certification procedure according to ISO 27017 / ISO 27018
- Informational meeting
Clarification of open questions, joint planning of next steps, project discussion or optional pre-audit - Document review & on-site audit
Readiness assessment and review of the management system description, ability to deliver quality customer service, implementation of documented statements in day-to-day operations - Audit report and assessment
On-site visit report and management system assessment - Certification and DEKRA seal
Upon successful completion of the certification criteria, conferral of certificate and our recognized DEKRA seal (with a 3-year maximum validity) - Annual surveillance audit
A monitoring audit is carried out every 12 months - Recertification
Three years after initial certification, steps 2 to 6 are repeated for recertification