Four certifications matter most for UK cloud buyers: ISO 27001, ISO 27017, CSA STAR Level 2 and Cyber Essentials Plus. ISO 27001 proves a working information security management system. ISO 27017 adds cloud-specific controls on top of it. CSA STAR Level 2 provides independently audited cloud assurance. Cyber Essentials Plus is technically tested rather than self-declared.
Quick reference
ISO 27001 – the baseline. Certifies a management system, not a product. Read the scope statement.
ISO 27017 – cloud-specific extension to ISO 27001. Shared responsibility, virtual machine hardening, administrator access, data return on exit.
ISO 27018 – controls for personal data processed in a public cloud. Also an extension to ISO 27001.
CSA STAR Level 1 – self-assessment. Level 2 – third-party audited. The gap between them is significant.
Cyber Essentials Plus – UK government-backed, hands-on technical verification. Frequently a condition of public sector contract award.
SOC 2 – a US attestation report, not a certificate. Useful evidence, not a UK requirement.
ISO 22301, ISO 20000-1, ISO 9001, ISO 14001 – operational standards. They tell you whether the provider can run the service, not just secure it.
Always verify the certificate number, the certification body and the scope. A logo on a website proves nothing.
Why do cloud security certifications matter?
When you move a workload to a cloud provider, you inherit that provider’s security posture. Your regulator, your auditor and your own customers will hold you responsible for data you no longer physically control. Certifications exist to convert a supplier’s claim into third-party evidence you can put in front of those people.
In practice they do three jobs. They shorten procurement, because a due diligence questionnaire that would otherwise take weeks can be answered with a certificate and a scope statement. They support your own compliance work, providing documented assurance for a data protection impact assessment or a supplier risk assessment. And they act as a filter, because maintaining a certified management system requires ongoing investment that thin operations cannot sustain.
What certifications do not do is guarantee that a specific service is secure. A certificate covers a defined scope, at a defined point in a defined audit cycle. The value is in reading it properly, which is where most buyers stop short.
What does ISO 27001 actually prove?
ISO/IEC 27001 certifies an information security management system. It is a systems standard, not a technical one. It confirms that an organisation has identified its information security risks, selected controls to treat them, documented how those controls operate, and can demonstrate that the whole thing is reviewed and improved on a cycle.
Certification runs on a three-year cycle with annual surveillance audits, so a current certificate means the system has been re-examined within the last twelve months. The 2022 revision reorganised the Annex A control set, which is why you will see both ISO 27001:2013 and ISO 27001:2022 certificates in circulation. A 2013-vintage certificate is not automatically a problem, but it does tell you the provider is due a transition.
The critical detail is scope. An ISO 27001 certificate names the activities, services and locations it covers. A provider can hold a genuine certificate that covers its head office administration and not the data centre your workload sits in. Ask which services and which sites the scope statement names, and read the answer.
What does ISO 27017 add that ISO 27001 does not?
ISO/IEC 27017 is a code of practice for information security controls in cloud services. It is not a standalone certifiable standard in its own right. Certification bodies assess it as an extension to an existing ISO 27001 management system, which is why you will see providers announcing ISO 27017 only after they already hold ISO 27001.
It does two things. It provides cloud-specific implementation guidance on 37 of the existing ISO/IEC 27002 controls, and it adds seven controls that exist nowhere else in the ISO 27000 family. Those seven cover the areas where cloud genuinely differs from on-premise infrastructure.
The additions are practical rather than theoretical. They address the division of security responsibility between provider and customer, which is the single most common cause of cloud security gaps. They cover the removal and return of customer assets when a contract ends, which matters enormously for exit planning. They deal with segregation in virtual environments, virtual machine hardening, administrator operational security, monitoring of cloud service use, and keeping virtual and physical network security aligned.
For a buyer, ISO 27017 answers a question ISO 27001 alone cannot: has this provider thought about the risks that only exist because the service is delivered from shared, virtualised infrastructure?
What is ISO 27018 and does it apply to you?
ISO/IEC 27018 is a code of practice for protecting personally identifiable information in public clouds where the provider acts as a processor. Like ISO 27017, it is assessed as an extension to ISO 27001 rather than on its own.
It becomes relevant when the provider will be processing personal data on your behalf. It covers consent and choice, restrictions on using customer data for the provider’s own purposes such as advertising, disclosure to law enforcement, and the return, transfer and disposal of personal data.
One caution worth stating plainly: ISO 27018 is supporting evidence for UK GDPR compliance, not compliance in itself. No certificate makes an organisation GDPR compliant. The obligations sit with the controller, and a certified processor is one input into meeting them.

What is CSA STAR and how do the levels differ?
The Cloud Security Alliance’s Security, Trust, Assurance and Risk programme is cloud-native in a way the ISO standards are not. It assesses providers against the Cloud Controls Matrix, a framework built specifically for cloud services, and publishes the results on an openly accessible registry.
The levels are not variations on a theme. Level 1 is a self-assessment: the provider completes a questionnaire and submits it. It is free, it is public, and it is unaudited. Level 2 requires a third-party audit conducted by an accredited certification body, carried out alongside an ISO 27001 assessment. Level 3 introduces continuous monitoring and automated evidence.
The practical takeaway is that a STAR listing alone tells you very little. Check which level, and check the date. Because the registry is public, this takes about thirty seconds and requires no cooperation from the provider.
What is Cyber Essentials Plus?
Cyber Essentials is a UK government-backed scheme delivered through IASME on behalf of the National Cyber Security Centre. It covers five technical control areas: firewalls, secure configuration, user access control, malware protection and security update management.
Base-level Cyber Essentials is a self-assessment questionnaire, verified by an assessor but not independently tested. Cyber Essentials Plus adds a hands-on technical audit in which an assessor tests the controls directly, including vulnerability scanning of internet-facing and internal systems and sample testing of end user devices.
For anyone selling into UK central government or the wider public sector, Cyber Essentials is frequently a mandatory condition of contract award, and Cyber Essentials Plus is increasingly specified where the contract involves sensitive or personal data. It is also a useful proxy for basic operational hygiene: it is difficult to pass the Plus audit with an untidy estate.
What about SOC 2, and is it needed in the UK?
SOC 2 originates from the American Institute of Certified Public Accountants and works differently from the ISO standards. It is not a certification and there is no certificate. It is an attestation report written by an auditor, assessing controls against five trust services criteria: security, availability, processing integrity, confidentiality and privacy.
Type I assesses whether controls are suitably designed at a single point in time. Type II assesses whether they operated effectively across a period, usually between three and twelve months. Type II is the meaningful one, and it is the one to ask for.
SOC 2 reports are normally shared under a non-disclosure agreement rather than published, which means evaluating one requires actually reading a substantial document. In the UK, ISO 27001 plus its cloud extensions is the more common evidence set, and SOC 2 tends to appear where a supply chain includes US customers or US-headquartered enterprises. Neither framework is superior. They answer similar questions in different formats, and a provider holding one is not deficient for not holding the other.
What do the operational standards tell you?
Security certifications describe how a provider protects data. They say nothing about whether the provider can actually deliver a reliable service, which is a separate risk and often the one that materialises first.
ISO 22301 certifies a business continuity management system, which matters if you need evidence of tested recovery capability. ISO 20000-1 certifies IT service management, covering incident, change and problem processes. ISO 9001 certifies quality management. ISO 14001 certifies environmental management, and ISO 14068-1 provides independently verified assurance around carbon neutrality claims, which increasingly appears in public sector and enterprise tenders as a scored criterion.
Taken together, this second group answers the question a security certificate cannot: when something goes wrong at three in the morning, is there a documented, audited process for handling it?
Which certifications matter for which sector?
Requirements vary considerably by sector, and asking for everything is as unhelpful as asking for nothing. The table below reflects what UK buyers are typically asked to evidence in procurement.
| Sector | What buyers are typically asked to evidence |
|---|---|
| Public sector and central government | ISO 27001, Cyber Essentials Plus, and a live G-Cloud framework listing. Cyber Essentials is frequently a condition of contract award. |
| Healthcare and NHS supply chain | ISO 27001 and Cyber Essentials Plus, plus provider evidence the customer can use to support its own Data Security and Protection Toolkit submission. |
| Legal | ISO 27001 and documented UK data residency. ISO 27017 is increasingly requested as firms tighten cloud due diligence against SRA expectations. |
| Financial services | ISO 27001 and ISO 22301, with operational resilience, exit planning and concentration risk evidence. |
| SaaS and software vendors | ISO 27001 and ISO 27017, since enterprise customers pass their own obligations down the chain. SOC 2 Type II where the customer base is US-heavy. |

How do you verify a provider’s certification claims?
This is where most due diligence falls down. Certification logos are trivially easy to place on a website and are not policed in any systematic way. The verification process is short and worth doing every time.
Ask for the certificate itself, not the logo. A genuine certificate shows a unique reference number, the issuing certification body, the standard and revision year, the issue and expiry dates, and the scope statement. Read the scope statement against what you are actually buying.
Check the certification body is accredited. In the UK that generally means accredited by UKAS. An unaccredited certificate is not worthless, but it is a different thing and should be understood as such.
Verify against a registry where one exists. CSA STAR listings are published on the Cloud Security Alliance registry. Cyber Essentials certificates appear in the IASME directory. ISO certificates can be checked through IAF CertSearch or the certification body’s own verification service.
Finally, watch the language. There is a meaningful difference between certified, audited against, aligned with, compliant with and built to the principles of. Only the first means a certificate exists. The others are, at best, self-declared.
Cloud security certifications compared
The table below summarises what each certification proves and how independently it has been assessed.
| Certification | What it proves | Independently audited | Cloud-specific | Publicly verifiable |
|---|---|---|---|---|
| ISO 27001 | A working information security management system across the certified scope | Yes | No | Via certification body or IAF CertSearch |
| ISO 27017 | Cloud-specific controls layered onto an ISO 27001 system | Yes, as an ISO 27001 extension | Yes | Via certification body |
| ISO 27018 | Controls for personal data processed in a public cloud | Yes, as an ISO 27001 extension | Yes | Via certification body |
| CSA STAR Level 1 | A self-completed questionnaire against the Cloud Controls Matrix | No | Yes | Yes, on the STAR Registry |
| CSA STAR Level 2 | Third-party audit against the Cloud Controls Matrix | Yes | Yes | Yes, on the STAR Registry |
| Cyber Essentials | Five basic technical controls, self-assessed | No | No | Yes, IASME directory |
| Cyber Essentials Plus | The same five controls, hands-on technically tested | Yes | No | Yes, IASME directory |
| SOC 2 Type II | Controls operating effectively over a defined period | Yes | Partly | No, shared under NDA |
Key takeaway
The certification a provider holds matters less than the scope it covers and whether you can verify it. Ask for the certificate, read the scope statement, check the registry, and treat aligned with as a different claim from certified.
How does BlackBox Hosting evidence its certifications?
BlackBox Hosting publishes its certificates rather than its logos. Every reference below can be checked against the issuing body, and the certificates themselves are downloadable from the certifications page.
| Certification or framework | Reference |
|---|---|
| ISO 27001:2022 – Information security management | IS 766577 |
| ISO 22301 – Business continuity management | BCMS 773897 |
| ISO 20000-1 – IT service management | ITMS 689313 |
| ISO 9001 – Quality management | FD 689980 |
| ISO 14001 – Environmental management | EMS 751332 |
| ISO 14068-1:2023 – Carbon neutrality | Verification Opinion Statement issued by BSI |
| CSA STAR Level 2 – Cloud assurance | STAR 743786 |
| Cyber Essentials Plus | Certificate published on the BlackBox certifications page |
| G-Cloud 14 – Government procurement framework | Supplier ID 705653 |
| ISO 27017 – Cloud security controls | Stage 2 audit completed with BSI |
All certificates, including scope statements and expiry dates, are available to download from the BlackBox Hosting certifications page. Where a registry exists, the listing is public and can be checked without contacting us.
A note from BlackBox
“Certifications are only worth what a buyer can verify. We publish our certificates, our numbers and our registry listings because the alternative is asking people to take our word for it, and no procurement team should have to. If a provider will not show you a scope statement, that is your answer.”
Matt Burden, Founder and Managing Director, BlackBox Hosting
Frequently asked questions
ISO 27001 certifies an information security management system that applies to any organisation. ISO 27017 is a code of practice that adds cloud-specific guidance on 37 existing controls and introduces seven controls unique to cloud services, covering shared responsibility, virtual machine hardening, administrator access and the return of data when a contract ends. ISO 27017 is assessed as an extension to ISO 27001, not instead of it.
No. ISO 27017 is a code of practice rather than a standalone management system standard. Certification bodies assess it alongside or on top of an existing ISO 27001 certification, so any provider claiming ISO 27017 should also hold current ISO 27001 certification covering the same scope.
No. SOC 2 is a US attestation framework and carries no regulatory weight in the UK. It appears most often where a supply chain involves US customers or US-headquartered enterprises. For UK procurement, ISO 27001 with cloud extensions, plus Cyber Essentials Plus for public sector work, is the more usual evidence set.
Level 1 is a self-assessment questionnaire submitted by the provider and published to the STAR Registry without independent verification. Level 2 requires a third-party audit by an accredited certification body against the Cloud Controls Matrix, conducted alongside an ISO 27001 assessment. Both appear on the same public registry, so it is worth checking which level a listing represents.
It is not mandatory for all organisations, but Cyber Essentials is a condition of award for many UK central government contracts, and Cyber Essentials Plus is increasingly specified where a contract involves personal or sensitive data. Outside the public sector it is voluntary, though some insurers and enterprise buyers now request it.
No. Certifications held by a cloud provider are supporting evidence for your own compliance work, not a substitute for it. Under UK GDPR the obligations sit with the data controller. A certified provider helps you demonstrate that you selected a processor offering sufficient guarantees, which is one requirement among many.
Ask for the certificate rather than accepting a logo. Check the reference number, the issuing certification body, whether that body is UKAS accredited, the expiry date and the scope statement. Verify against a public registry where one exists: the CSA STAR Registry for STAR listings, the IASME directory for Cyber Essentials, and IAF CertSearch or the certification body’s own service for ISO certificates.

