ISO/IEC 27017 and 27018 are not standalone certificates
They are cloud security and personal data controls, not standalone Type A management system standards, although they are frequently marketed as separate certificates.
03
On the software and data side, what decides is not the sector but which data you process, whether you provide a defined service to customers, and your role in the AI chain. For most technology companies several standards become candidates at once.
They are cloud security and personal data controls, not standalone Type A management system standards, although they are frequently marketed as separate certificates.
An information security management system does not substitute for KVKK or GDPR compliance or legal advice. ISO/IEC 27701 strengthens this side but is still not a legal compliance certificate.
A team using a chat tool does not create ISO/IEC 42001 candidacy. The developer, provider or high-impact user role is questioned.
For organisations in any sector seeking to standardise processes and manage customer expectations systematically.
For organisations with substantial IT estates and for IT service providers.
For organisations that provide a defined IT service to others.
For organisations where service interruption is critical, or that are multi-site or critical suppliers.
For organisations that process data, access customer systems or provide cloud services.
For organisations processing personally identifiable information within an ISO 27001 scope.
For people-intensive organisations seeking corporate assurance over HR processes.
For organisations seeking to manage institutional knowledge systematically.
For organisations that develop, provide or use artificial intelligence in high-impact contexts.
For R&D and technology organisations establishing systematic innovation management.
For organisations providing application services using service robots.
These are not ISO standards; each has its own scheme owner, issuing body and rules. Whether they are candidates is decided by activity and buyer requirement.
ADISA ICT Asset Recovery Standard 8.0 certifies processors that handle IT asset disposal; ADISA Certification owns and audits the scheme.
EUCC is the EU's first Cybersecurity Act certification scheme for ICT products, based on Common Criteria and applied from 27 February 2025.
ISMS-P is South Korea's integrated certification for information security and personal-data management, statutory for defined ICT operators.
Kantara Initiative runs global identity-assurance certification programs, assessing services against standards including NIST SP 800-63 and the UK's DIATF.
MTCS (Singapore Standard SS 584:2020) is a three-level cloud security certification, published under the Information Technology Standards Committee.
NAID AAA Certification is i-SIGMA's voluntary program for member companies providing secure information destruction. Membership comes first.
O-TTPS is The Open Group's certification standard against maliciously tainted and counterfeit ICT products, with a live public certification register.
SCS 9001 is TIA's certifiable cyber and supply chain security standard for the ICT industry, with optional benchmarking across supply chains.
TL 9000 is TIA QuEST Forum's ICT-industry certification, extending ISO 9001:2015 with telecom-specific requirements for certified organizations.
C5 is the BSI's cloud security criteria catalogue for Germany — auditors examine against it and the output is an attestation (Testat), not a certificate.
A U.S. government-wide software attestation form: the OMB memoranda requiring its collection were rescinded by OMB M-26-05 on 23 January 2026.
ACN's Regolamento sets three qualification tracks — AI, AC and QC — for Italian public bodies and their cloud providers to move data to the cloud.
FedRAMP is the U.S. federal cloud authorization program run by GSA under the FedRAMP Authorization Act — agencies grant authorizations, not certificates.
GovRAMP is a nonprofit cloud security verification program serving U.S. state, local, tribal and educational government — StateRAMP's dba name since 2025.
SecNumCloud is a French state qualification for cloud service providers, granted by ANSSI, covering SaaS, PaaS, CaaS and IaaS activities.
TX-RAMP is Texas's state-government cloud security authorization program: Texas Cyber Command evaluates vendors and DIR issues the certification.
The Cyber Centre's CSP ITS Assessment Program assesses cloud services for GC procurement up to Protected B — the output is a report, not a certificate.
The CSA Cloud Controls Matrix is a cybersecurity control framework for cloud computing, structured in 17 domains, maintained by the Cloud Security Alliance.
ISO/IEC 27017 gives cloud-specific security controls on top of ISO/IEC 27002; the current edition is 27017:2026 — the 2015 text is withdrawn.
ISO/IEC 27018 guides protection of PII in public clouds where the provider acts as PII processor; the current edition is 27018:2025 (third edition).
The RBA Validated Assessment Program is an on-site audit methodology for RBA Code compliance, carried out by independent third-party firms, not RBA itself.
CSA STAR is the Cloud Security Alliance's cloud assurance program, built around a publicly accessible registry of provider security submissions.
The EU Cloud Code of Conduct is a voluntary GDPR Article 40 code; cloud providers declare adherence and SCOPE Europe verifies compliance annually.
The AWS Foundational Technical Review (FTR) is a self-service review of AWS Partner solutions; AWS calls the outcome an approval and a badge, not a certificate.
Last verified:
This page is for information only; it is not legal advice. A record appearing here does not mean it is required for your business. This library does not issue certificates.
Attributing this record helps other researchers verify it independently.
"Technology and Data." Certifidex, FutureTechnologies. Last verified 4 August 2026. https://certifidex.com/sectors/technology-and-data