ISMS Copilot
Product Updates

ISO 27017 moves to the 2026 edition: the assistant reads both citation languages

A 2024 Statement of Applicability cites the 2015 CLD set. A 2026 audit may cite the new controls. The assistant recognizes both editions' citations.

by ISMS Copilot··5 min read
ISO 27017 moves to the 2026 edition: the assistant reads both citation languages

On 27 July 2026, ISO published ISO/IEC 27017:2026, the second edition of its cloud security controls standard, and retired the first: the 2015 edition moved to withdrawn status the same day.

If you run an ISMS with cloud services in scope, ISO/IEC 27017 is the standard behind the cloud rows of your Statement of Applicability: shared responsibility between customer and provider, segregation in virtual environments, monitoring of cloud services. It is a code of practice, not a certification you hold on its own. Conformance is typically asserted through the SoA of an ISO 27001 certification. And the documents that carry it live for years. The SoA you signed in 2024 cites 2015 Annex A numbering. The audit starting next quarter may work from the 2026 text. Both are legitimate, and both can be in the room.

So the practical question after an edition change is not "what is new in the standard". It is whether your tools can read both editions' citations. That is what we improved.

What changed in the standard

The 2026 edition realigns the body with ISO/IEC 27002:2022 (published February 2022), whose 93 controls sit in four themes. Where a control needs no cloud addition, the 2026 text simply points back at 27002:2022. The cloud-specific controls moved from a normative Annex A in the 2015 edition, seven controls carrying CLD.* numbers, to four CLD-marked controls in the body:

  • 5.38, shared roles and responsibilities
  • 5.39, cloud service partner roles (new)
  • 8.35, segregation in virtual computing environments
  • 8.36, detection and prevention of unauthorized cloud use (new)

Two of the four are new. The other two carry 2015's cloud intent under the extended numbering. Two informative annexes close the edition: one maps the 2026 controls back to their 2015 counterparts, and one covers monitoring of cloud services. The standard itself treats the transition as a correspondence problem.

What we shipped

On 2026-07-29 we updated the assistant's ISO 27017 knowledge module from the 2015 edition to the 2026 one. It shipped in our July product changelog. Before that update, the module was still tracking 2015, with a re-verify note waiting for the revision to publish.

After the update:

  • Cloud-control answers follow the 2026 structure, including the four CLD-marked controls above.
  • The assistant recognizes both 2026 citation forms, the dotted form (CLD.5.38) and the contents-page form (5.38 CLD).
  • The 2015 legacy patterns are kept. A citation to the old Annex A numbering still resolves, and the assistant can tell which edition a citation refers to.
  • Two sibling modules, ISO 27002 and ISO 27018, no longer claim that 27017 is unrevised.

That third line is the deliberate part. Swapping the text was the easy half. For the detailed old-to-new correspondence, the standard's own Annex A remains the source; the assistant points you there rather than guessing at a mapping it does not carry.

Why we kept the old citations

A knowledge base can chase the current edition and nothing else. It is cleaner to maintain, and wrong in the field. Standards documents have long lives. Certificates run on multi-year cycles. Statements of Applicability get amended rather than rewritten. Every contract or questionnaire that quoted a 2015 CLD number stays exactly as it was written. Anyone who moved an ISMS from ISO 27001:2013 to the 2022 edition has already lived this: for a couple of years, your own archive speaks one numbering system while new work speaks another.

Edition transitions are citation problems as much as content problems. A compliance assistant that only speaks the current edition makes your own documents illegible to it. One that force-migrates every answer to the new numbering can contradict the document you are holding. So the module carries both: new questions get 2026 answers, and a citation written against the retired edition is still recognized and identified as such, not treated as a typo.

What this is not

  • Not a certification change. ISO/IEC 27017 remains guidance for information security controls in cloud services, not a certification you hold on its own. It typically feeds the Statement of Applicability of an ISO 27001 certification. The 2026 edition does not change that shape.
  • No transition deadlines here. Certification bodies will set their own expectations for moving SoAs and scopes to the new numbering. We quote none, and you should not take one from this post.
  • Identifiers, not the standard's text. The reference module carries control identifiers and concise titles, not ISO's copyrighted guidance.

Who it is for

  • Consultants and in-house ISMS teams with cloud services in scope, whose SoAs and audit evidence now straddle two editions.
  • Cloud service providers holding an ISO 27001 certification with a cloud scope, where 27017 citations appear in contracts, customer questionnaires, and audits.
  • Auditors and reviewers, who will see both numbering systems in the wild for the next few years and need answers that do not contradict whichever document is open.

If you have no cloud services in scope and no 27017 citations anywhere, nothing changes for you. That is fine too.

Try it

Ask the assistant about a cloud control. Cite it the 2026 way (CLD.8.36) or the 2015 way (an Annex A CLD.* number), and ask which edition the citation refers to. The assistant should recognize the edition your document is written against, and the standard's Annex A carries the full correspondence when you need the mapping.

Standards move slower than software, but they move. When they do, the tools around them have to bridge the gap, not overwrite it.

Related Posts