ISO 27018
What is ISO 27018?
Code of practice for protection of PII in public clouds acting as PII processors. It comprises 45 controls organised across 10 domains, published by ISO/IEC, and applies in International.
Map this against the frameworks you already hold
The compliance knowledge graph holds cross-framework control mappings for hundreds of standards, including the ones you are likely to be certified against already.
Browse the framework graph →The 10 domains ISO 27018 groups its controls into
Where ISO 27018 overlaps with the standards you already hold
Where to get trained on ISO 27018
4 courses in the catalogue cover ISO 27018 directly. Each is self-paced, includes the downloadable toolkit and the implementation playbook, and carries a certificate of completion.
What ISO 27018 means in your sector
What ISO 27018 means for your job
Questions people ask about ISO 27018
What is ISO 27018?
How many controls does ISO 27018 have?
Where does ISO 27018 apply?
What frameworks does ISO 27018 map to?
How do I get started with ISO 27018 compliance?
Query ISO 27018 programmatically
ISO 27018, its 45 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
ISO 27018 API reference and MCP config →How ready are you for ISO 27018?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.