Cloudflare widens its compliance portfolio with ISO 27018, C5 attestation

Cloud computing has shifted data storage and processing away from physical hardware that organizations can see and secure themselves. Instead, customers must rely on their cloud providers to implement appropriate safeguards. Third-party certifications and attestations have become the primary mechanism for verifying that a provider’s security and privacy controls meet recognized standards.

Cloudflare announced three developments in that vein: certification to ISO/IEC 27018:2019, an attestation for the Cloud Computing Compliance Criteria Catalog (C5), and membership in the EU Cloud Code of Conduct General Assembly.

ISO/IEC 27018:2019 certification

ISO 27018 is a privacy extension to the ISO/IEC 27001 and ISO/IEC 27002 standards, which define how to establish and operate an Information Security Management System. The extension provides a code of practice for protecting personal information processed in a public cloud, such as Cloudflare’s network.

Cloudflare’s certification to ISO 27018 follows its earlier achievement of ISO/IEC 27701:2019, which the company obtained in 2021 as one of the first organizations in its industry — and the first Internet performance and security company — to do so. The combination of both certifications assures customers that Cloudflare maintains a privacy program aligned with GDPR industry standards and protects personal data processed on its network as part of that program.

Alongside the company’s Data Processing Addendum (DPA), these certifications offer customers layers of assurance that personal data will be handled in accordance with GDPR requirements when Cloudflare acts as a processor.

The ISO 27018 standard includes enhancements to existing ISO 27002 controls plus a set of 25 additional controls specific to organizations that process personal data. These cover data handling practices, transparency, protection and encryption of personal data, and data subject rights. One example requirement states:

Where the organization is contracted to process personal data, that personal data may not be used for the purpose of marketing and advertising without establishing that prior consent was obtained from the appropriate data subject. Such consent shall not be a condition for receiving the service.

Cloudflare states that when it acts as a data processor, customer data belongs to the customers, and the company does not track end users for marketing or advertising. The commitment extends beyond the ISO control into the customer DPA, which states Cloudflare shall not use personal data for marketing or advertising purposes.

The ISO 27018 certification was assessed by third-party auditor Schellman between December 2021 and February 2022, following a multi-step process of internal and external audits. Cloudflare’s single joint certificate now covers ISO 27001:2013, ISO 27018:2019, and ISO 27701:2019, and is available for download from the Cloudflare Dashboard.

C5 attestation

The C5 catalog was introduced by the German Federal Office for Information Security (BSI) in 2016 and updated in 2020. It evaluates an organization’s security program against a set of cloud security controls. German government agencies and private companies both use C5 to align their cloud computing requirements with these standards.

Cloudflare has completed its independent audit and received the C5 attestation from its third-party auditors. The attestation report is available from the Cloudflare Dashboard.

EU Cloud Code of Conduct membership

The General Data Protection Regulation, adopted four years ago, encourages the drawing up of codes of conduct intended to contribute to the proper application of the regulation, taking into account the features of various processing sectors and the needs of small and medium-sized enterprises. The first code approved as GDPR-compliant by the EU — the EU Cloud Code of Conduct — is designed to help cloud service providers demonstrate the protections they apply to personal data processed on behalf of customers. It covers all cloud service layers, with compliance overseen by accredited monitoring body SCOPE Europe.

Cloudflare has joined the General Assembly of the EU Cloud Code of Conduct. Membership is the first step; the second is undergoing an audit to validate adherence to the code. Cloudflare says it will proceed with that audit and publicly affirm its GDPR compliance as a processor of personal data.

Customers can download Cloudflare’s certifications and reports from the Cloudflare Dashboard; new customers may request them from a sales representative. Updated information about certifications and reports is available on the Trust Hub.