ISO 27017 Cloud Security Certification in UAE – UAE Laws, Requirements & Get Certified with SCS
https://scscertification.com/contactus.php
Cloud services are now embedded in the way many UAE businesses operate. A fintech company may run customer-facing applications in a public cloud, a healthcare provider may host clinical systems with a technology partner, while a logistics company may depend on cloud platforms for fleet management, warehousing and customer portals.
The security question is therefore broader than where the server is located. Businesses need to understand who controls the data, who manages the infrastructure, which security activities belong to the cloud provider, which remain with the customer, and what contractual or regulatory obligations apply.
ISO/IEC 27017 addresses this cloud-specific environment. The current edition, ISO/IEC 27017:2026, provides guidance for information-security controls in cloud services and adds cloud-specific guidance to ISO/IEC 27002 for both cloud service providers and cloud service customers. ISO published the 2026 edition in July 2026 and lists ISO/IEC 27017:2015 as withdrawn. ISO
For UAE organizations, the standard can provide a useful framework for strengthening cloud-security governance, managing provider relationships and demonstrating a more structured approach to cloud risk.
What Is ISO 27017 Cloud Security Certification?
ISO/IEC 27017 is a cloud-security standard built around the information-security controls of ISO/IEC 27002. Its particular focus is the way those controls should be applied when services, systems and responsibilities are delivered through cloud computing.
That distinction matters.
A conventional information-security program may establish access control, incident management, backup and supplier-security requirements. A cloud environment introduces additional questions:
- Which party administers the infrastructure?
- Who can access customer data?
- How are responsibilities divided between provider and customer?
- How are virtual environments separated?
- What happens when a cloud service changes?
- How are data and systems recovered?
- What happens when the contract ends?
- What security evidence can the customer obtain from the provider?
ISO/IEC 27017:2026 is designed to address these shared responsibilities and cloud-specific risks. ISO
For commercial purposes, organizations should also distinguish between ISO 27017 cloud-security conformity or assessment and certification of an ISO 27001 management system. ISO 27017 itself is guidance for cloud-security controls rather than a replacement for ISO 27001.
ISO 27017:2026 and the Previous 2015 Edition
Businesses that have older ISO 27017 documentation should review it against the current edition.
ISO records ISO/IEC 27017:2015 as withdrawn and identifies ISO/IEC 27017:2026 as the current published edition. ISO
This is particularly relevant to UAE organizations preparing new cloud-security policies, customer security questionnaires or supplier assessments in 2026.
The current standard focuses on cloud services and the relationship between:
- Cloud service providers
- Cloud service customers
- Internal business functions
- Technology suppliers
- Security-control owners
An organization should therefore avoid treating an old 2015 checklist as automatically equivalent to the requirements and guidance of the 2026 edition.
ISO 27017 and ISO 27001: What Is the Difference?
The two standards are related, but they address different needs.
ISO/IEC 27001 specifies requirements for an Information Security Management System (ISMS).
ISO/IEC 27017 provides cloud-specific guidance and controls based on ISO/IEC 27002.
A UAE software company, for example, may use ISO 27001 to manage its overall information-security risks while using ISO 27017 to address risks arising specifically from its cloud infrastructure and cloud-service relationships.
Other standards may be relevant depending on the organization's circumstances. ISO 27018 can be relevant to protection of personally identifiable information in public-cloud environments, while ISO 27701 addresses privacy information management.
The correct combination depends on the organization's activities, customers, cloud architecture and regulatory obligations.
Why ISO 27017 Matters to UAE Businesses
Cloud-security requirements in the UAE cannot be reduced to a single law or a single regulator.
The applicable obligations can vary according to the business sector, location, type of data, customer contracts and regulatory status.
For example, a regulated financial institution faces a different cloud-governance environment from a small software company. A Dubai cloud provider serving government entities may also have requirements that do not apply to an ordinary commercial cloud customer.
ISO 27017 gives businesses a way to examine cloud-security responsibilities systematically rather than relying entirely on the security assurances of a technology supplier.
ISO 27017 Cloud Security Requirements Relevant to UAE Organizations
The exact controls and implementation approach depend on the organization's scope and risk assessment. Several areas deserve particular attention.
Cloud Responsibilities and Shared Responsibility
Cloud security works best when responsibilities are explicit.
A cloud provider may manage physical infrastructure, virtualization and certain platform services. The customer may remain responsible for application configuration, identities, user permissions and the information placed in the service.
Those boundaries can become less obvious with SaaS, PaaS and managed services.
A UAE organization should document who is responsible for:
- Infrastructure security
- Application security
- Identity management
- Data protection
- Security monitoring
- Vulnerability management
- Backup and recovery
- Incident response
- Configuration management
- Supplier management
- Secure deletion
- Cloud exit
ISO/IEC 27017:2026 specifically addresses the shared nature of cloud services and the division of responsibilities between providers and customers. ISO
Cloud Asset and Information Management
A business cannot protect what it does not know it is using.
The cloud inventory may include virtual machines, databases, containers, storage accounts, APIs, applications, backup environments, encryption keys and development platforms.
For UAE organizations, asset identification should be connected to information classification. Customer information, financial records, healthcare information, intellectual property and confidential business information may require different protection measures.
Identity and Access Management
Cloud environments can create large numbers of privileged accounts, service identities and remote-access paths.
Controls should therefore address:
- Least-privilege access
- Role-based permissions
- Multi-factor authentication
- Privileged accounts
- Service accounts
- User lifecycle management
- Periodic access reviews
- Third-party access
- Administrative activities
The objective is not simply to create more passwords or authentication rules. It is to ensure that people and systems receive only the access they actually need.
Cloud Data Protection
Organizations should understand how information moves through their cloud environment.
A useful assessment looks at:
- Where information is stored
- Where it is processed
- Who can access it
- Which suppliers can access it
- Where backups are maintained
- How information is transferred
- How information is deleted
This becomes particularly important where personal data or commercially sensitive information is involved.
Encryption and Key Management
Encryption requirements should be based on risk, data sensitivity and applicable contractual or regulatory requirements.
The organization should understand whether encryption is applied to:
- Data at rest
- Data in transit
- Backups
- Databases
- Storage
- Application communications
Key management deserves separate attention. Knowing that a provider offers encryption is not enough; the organization should understand how keys are protected, administered and accessed.
Logging and Monitoring
Cloud environments can change quickly. Monitoring therefore needs to cover more than traditional server logs.
Depending on the architecture, businesses may need visibility into:
- Authentication events
- Privileged activity
- Configuration changes
- API activity
- Security alerts
- Access to sensitive information
- Administrative operations
For regulated organizations, evidence and auditability are particularly important.
Vulnerability Management
Cloud security assessments should consider vulnerabilities in the applications, configurations, identities and supporting infrastructure that fall within the organization's responsibility.
Depending on the risk profile, this can include vulnerability assessments, penetration testing, configuration reviews and application-security testing.
A cloud provider's security certification does not remove the customer's responsibility for weaknesses within its own applications or configurations.
Backup, Recovery and Resilience
Cloud hosting does not automatically equal business continuity.
A UAE organization should establish:
- Recovery objectives
- Backup requirements
- Recovery responsibilities
- Backup protection
- Recovery testing
- Alternative arrangements
- Provider dependencies
The CBUAE's cloud guidance, for example, requires regulated institutions to maintain appropriate and secure backups and ensure cloud-processed data can be recovered within a predefined timeframe. Rulebook
Supplier and Contract Management
The cloud contract should support the security model.
Important questions include:
- What security controls does the provider operate?
- What remains the customer's responsibility?
- How are incidents reported?
- Can security evidence be obtained?
- Are subcontractors used?
- Where is information processed?
- How is data returned at contract termination?
- How is data securely deleted?
- What happens if the provider becomes unavailable?
These questions are especially important when cloud services support critical business operations.
UAE Laws and Regulations Relevant to Cloud Security
ISO 27017 should be used alongside applicable UAE laws and regulatory requirements. It should not be described as a substitute for them.
The UAE's federal Personal Data Protection Law is one important consideration. Federal Decree-Law No. 45 of 2021 establishes a framework for protecting personal data and includes requirements concerning the processing and security of personal information. u.ae
For an organization using cloud services, this may require consideration of matters such as:
- Personal-data processing
- Security of personal data
- Confidentiality
- Data-sharing arrangements
- Third-party processing
- International transfers
- Data-management responsibilities
The actual legal position depends on the organization's activities and applicable exemptions or sector-specific requirements.
ISO 27017 and CBUAE Cloud Computing Requirements
Financial institutions operating under the supervision of the Central Bank of the UAE require additional attention to cloud governance.
The CBUAE's in-force Cloud Computing guidance addresses areas including materiality, governance, auditability and outsourcing. Rulebook
It also addresses cloud design, management and monitoring, data protection, business continuity, and exit and resolution planning. Rulebook
For a financial institution, cloud governance should therefore consider whether an arrangement is material, how the provider is assessed, how responsibilities are divided and how the organization would respond if the cloud service failed.
CBUAE guidance states that a cloud arrangement may be material where a disruption or security/confidentiality breach could materially affect business operations, risk management, regulatory compliance or the confidentiality and integrity of personal data. Rulebook
This makes ISO 27017 particularly relevant as a supporting cloud-security framework, but an ISO 27017 assessment should not be represented as automatic CBUAE compliance.
ISO 27017 and Dubai DESC Cloud Requirements
Dubai has a specific cloud-security environment for cloud providers serving government and semi-government entities.
The Dubai Electronic Security Center (DESC) states that its Cloud Service Provider Security Standard sets requirements and guidance for CSPs and organizations using cloud services. Compliance is mandatory for CSPs wishing to offer cloud services to Dubai government and semi-government entities. DESC
DESC also states that the CSP Security Standard was based on several international standards, including ISO/IEC 27017:2015. DESC
This distinction matters: ISO 27017 and DESC CSP certification are not the same thing.
A provider seeking to serve Dubai government or semi-government customers should evaluate the current DESC requirements separately.
ISO 27017 and ADGM
Businesses operating within Abu Dhabi Global Market may have additional data-protection obligations depending on their activities.
Where cloud services process regulated or personal information, the organization should consider its responsibilities as a controller or processor, its contracts with service providers and its arrangements for security and data transfers.
ISO 27017 can contribute to the cloud-security component of that framework. It does not replace the applicable ADGM legal requirements.
ISO 27017 and DIFC
DIFC businesses should similarly distinguish between cloud-security controls and privacy-law obligations.
A company operating a cloud-hosted financial, professional-services or technology platform in DIFC may need to address security requirements, data-processing responsibilities, supplier contracts and applicable DIFC data-protection rules.
The practical approach is to map the organization's legal and contractual obligations first, then determine how ISO 27017 controls support those requirements.
ISO 27017 for Key UAE Business Sectors
Cloud security is not limited to IT companies. The risk looks different from one industry to another.
Banking, Financial Services and Fintech
Banks, financial institutions and fintech companies can have substantial dependencies on cloud platforms.
Typical concerns include customer information, authentication, payment applications, APIs, third-party services, resilience and regulatory reporting.
For CBUAE-regulated institutions, cloud governance should be assessed alongside the applicable CBUAE requirements rather than treated as a standalone ISO exercise. CBUAE guidance covers vendor due diligence, cloud governance, monitoring, data protection and exit planning. Rulebook
Healthcare and Medical Technology
Hospitals, clinics, laboratories, telemedicine providers and healthcare technology companies increasingly rely on hosted applications and cloud storage.
Examples include:
- Electronic medical records
- Patient portals
- Laboratory systems
- Telemedicine platforms
- Healthcare analytics
- AI-enabled applications
The security assessment should consider the sensitivity of health information, access privileges, third-party processing and continuity of clinical systems.
SaaS and Software Companies
SaaS companies are a natural fit for cloud-security frameworks because their products and customer environments are closely tied to cloud infrastructure.
A SaaS provider should be able to explain:
- Where customer information is hosted
- How tenant environments are separated
- Who has administrative access
- How incidents are handled
- How backups work
- How customers leave the service
- What security evidence is available
These questions frequently arise during enterprise procurement.
E-Commerce and Retail
Online retailers may depend on cloud-hosted websites, customer databases, payment integrations, inventory systems and marketing platforms.
The security scope should reflect the actual architecture rather than simply the website itself. Third-party applications, APIs and outsourced services can create additional dependencies.
Logistics and Transportation
Dubai and Abu Dhabi logistics operations can involve cloud-based fleet management, GPS systems, warehouse applications, transportation platforms and customer portals.
For these organizations, availability can be as important as confidentiality. A cloud outage affecting dispatch or warehouse operations can quickly become an operational problem.
Manufacturing and Industrial Businesses
Manufacturers increasingly use cloud platforms for ERP, industrial analytics, supplier portals, remote monitoring and connected production systems.
Security reviews should consider the connection between cloud applications and operational technology, particularly where remote access is involved.
Real Estate and Construction
Property developers, facility-management companies and construction businesses may use cloud platforms for CRM, project management, BIM, document management and smart-building systems.
The main security concern is often distributed access across employees, contractors, consultants and technology suppliers.
Government Technology Suppliers
Technology companies supplying government entities may encounter security requirements beyond ordinary commercial procurement.
Cloud providers, SaaS vendors, managed-service providers and digital-platform companies should identify the specific security requirements included in their contracts and applicable government standards.
ISO 27017 Across UAE Emirates and Business Zones
A useful UAE cloud-security strategy should not stop at Dubai.
Dubai
Relevant business ecosystems include:
- DIFC
- Dubai Internet City
- Dubai Silicon Oasis
- DMCC
- JAFZA
- Dubai South
- Dubai Healthcare City
- Dubai Airport Freezone
- Dubai Design District
The applicable requirements will depend on the organization's business activity and whether it operates under a specific regulatory or government procurement framework.
Abu Dhabi
Important business ecosystems include:
- ADGM
- Masdar City
- KEZAD
- Abu Dhabi industrial areas
- Financial and technology businesses
Cloud-security requirements should be assessed against the organization's regulatory and contractual environment.
Sharjah
Relevant business areas include:
- Sharjah Airport International Free Zone
- Hamriyah Free Zone
- Sharjah Research, Technology and Innovation Park
Ajman
Organizations in Ajman Free Zone and other commercial and industrial areas can apply cloud-security controls according to their technology use and business requirements.
Ras Al Khaimah
RAKEZ hosts a broad range of businesses, including industrial, commercial and professional organizations. Companies using cloud ERP, customer platforms, hosted applications or managed services can assess whether ISO 27017 is appropriate for their environment.
Fujairah and Umm Al Quwain
Cloud-dependent businesses in logistics, trading, professional services, hospitality and other sectors can also apply the same risk-based principles while taking account of their specific legal and contractual obligations.
The purpose of location-based analysis should be to identify the actual regulatory and operational context, rather than simply adding an Emirate name to a certification keyword.
ISO 27017 Requirements Checklist for UAE Businesses
Before engaging an assessment or certification provider, management can ask a few practical questions:
- What cloud services are within our scope?
- Which information is stored or processed in the cloud?
- Who owns each cloud-security control?
- Which responsibilities remain with the cloud provider?
- Are privileged accounts controlled?
- Is multi-factor authentication appropriately implemented?
- Are cloud configurations monitored?
- Are sensitive data and backups adequately protected?
- Are cloud activities logged?
- Are vulnerabilities and security weaknesses assessed?
- Are cloud suppliers evaluated before engagement?
- Do contracts define security responsibilities?
- Are incident-reporting requirements documented?
- Can business-critical data be recovered?
- Has cloud exit been considered?
- Which UAE laws and regulatory requirements apply?
- Are sector-specific requirements identified?
- Can the organization demonstrate evidence that controls are operating?
These questions are a starting point rather than a substitute for a formal gap assessment.
How to Prepare for ISO 27017 in UAE
Preparation is easier when the organization begins with its actual cloud environment rather than with a generic document template.
Define the scope
Identify the applications, cloud services, locations, information assets and providers that fall within the intended scope.
Map responsibilities
Create a clear division between customer responsibilities and provider responsibilities.
Assess risks
Consider confidentiality, integrity, availability, regulatory exposure, supplier dependency and business continuity.
Review contracts
Check whether cloud contracts address security, incident notification, access, subcontracting, data handling, audit evidence and termination.
Implement controls
Address the gaps identified during the assessment and align the controls with the organization's risk profile.
Build evidence
Evidence may include policies, risk assessments, asset inventories, access reviews, supplier evaluations, contracts, logs, incident records, backup tests and security assessments.
Conduct an internal review
Before an external assessment, verify that documented controls are actually operating.
That last step is frequently where organizations discover weaknesses. A policy stating that access is reviewed quarterly is of limited value if there is no evidence that the reviews actually occurred.
Business Benefits of ISO 27017 Cloud Security
The business case for ISO 27017 is strongest when it addresses a real cloud-security problem.
For a SaaS company, it can provide a more structured response to enterprise security questionnaires.
For a financial institution, it can help organize cloud responsibilities alongside the applicable regulatory framework.
For a healthcare company, it can strengthen controls around cloud-hosted sensitive information.
For a cloud provider, it can provide a recognizable framework for discussing cloud-security practices with customers.
Across these sectors, the practical benefits can include clearer accountability, better supplier governance, stronger security evidence and greater confidence in cloud-service arrangements.
ISO 27017, ISO 27018 and ISO 27701: Which One Is Relevant?
These standards should not be treated as substitutes.
ISO 27001 focuses on the Information Security Management System.
ISO 27017 focuses on cloud-specific security controls and guidance.
ISO 27018 addresses protection of personally identifiable information in applicable public-cloud environments.
ISO 27701 focuses on privacy information management.
ISO 22301 addresses business continuity management.
A UAE organization may need one standard or a combination depending on its services, customers, information and regulatory obligations.
What Does ISO 27017 Certification Cost in UAE?
There is no single price applicable to every UAE organization.
The cost can be influenced by:
- Organization size
- Cloud architecture
- Number of cloud services
- Scope
- Number of locations
- Existing ISO 27001 controls
- Information-security maturity
- Number of suppliers
- Regulatory requirements
- Assessment arrangements
A company that already operates a mature ISO 27001 system may require a different level of work from a business building its cloud-security framework from the beginning.
A proper quotation should therefore be based on the intended scope rather than employee count alone.
Get ISO 27017 Cloud Security Certification with SCS
For UAE organizations, the value of ISO 27017 is in making cloud-security responsibilities understandable and manageable.
The right approach starts with the business model: identify the cloud services, understand the information being processed, determine the provider/customer responsibilities, map applicable UAE requirements and then assess the controls.
SCS can support organizations seeking to establish and assess an ISO 27017-aligned cloud-security framework in the UAE.
If your organization is a SaaS provider, cloud service provider, fintech company, healthcare organization, e-commerce business, logistics company, technology company, data-centre operator or government technology supplier, discuss your scope and requirements with SCS.
Get certified with SCS and strengthen your UAE cloud-security framework.
https://scscertification.com/contactus.php
|
UAE |
Saudi Arabia |
UK |
Canada |
India |
|
SCS Certification6th Floor Salaam Bldg, Office 9 Al Marakib St, Al Danah, Zone 1,Abu Dhabi, UAE. |
SCS Certification (Partners)7713, King Abdulaziz Street, Al Dawasir, Dammam, 32416Kingdom of Saudi Arabia |
SCS CERTIFICATION EUROPE LIMITED Office 6996,58 Peregrine Road, Hainault, Ilford, Essex, United Kingdom IG6 3SZ. |
SCS Certification (E) Limited Oaklea Blvd, Brampton, ONL6Y 5A2, Canada. |
Chennai: Building bearing No.19/35, V 270,Situated on First Floor, Mount Road, Little Mount, Chennai – 600015, India. Bangalore: Bangalore, Karnataka, India. |
Need ISO Certification for Your Business?
Speak with our certification specialists to understand certification requirements, audit process, implementation timelines and accredited certification services.