Personal data protection in the cloud means ISO 27018. Certify it.

Private clients and Public Administration cloud marketplaces increasingly require ISO 27001 certification with the 27018 extension for entities handling personal data in the cloud. With Complaion, the time required to obtain this certification is significantly reduced: a Lead Auditor manages every critical phase, while the platform automates the rest.

Public tenders, contracts and large clients almost always require this standard. With Complaion, the time to achieve it is significantly reduced: a Lead Auditor manages each critical phase, and the platform automates the rest.

ISO 9001

Renewal included

Valid 3 years

Upcoming audits

ISO 27018

ISO 27018

Audit esterno

Da pianificare

ISO 27018

ISO 27018

31/07/26

Audit interno

All audits

“Audit completato. Report caricato, solo 2 Osservazioni!”

Alessandro, Lead Auditor

Alessandro, Lead Auditor
Portrait photo of a Complaion team member

Marco, Lead Auditor | Replies within 24 hours

Portrait photo of a Complaion team member

Marco, Lead Auditor | Replies within 24 hours

Portrait photo of a Complaion team member

Marco, Lead Auditor | Replies within 24 hours

our method

This is how we get you ISO Certified.

80%

automated

Data protection control documentation generated by the platform.

faster

Shorter wait times, less bureaucracy: from gap analysis to audit, with the same rigor required by ISO 27018.

100%

success

We prepare your ISO 27018 audit with accredited bodies: no surprises on the day of the assessment.

protection of personal information in public clouds

Certify what you are already doing to protect personal data.

Complaion Procedure Trasp logo

BUILD OR EXPAND YOUR SYSTEM

We build your ISO 27001 system or extend the one you already have.

If you are starting from scratch, we build the entire information security management system. If you are already ISO 27001 certified, we simply map data segregation, asset return, and roles between the cloud provider and the customer, and integrate them into your existing system.

Work without surprises.

We write your procedures; our platform keeps them up to date.

Data access and deletion rights, customer notification in the event of a breach, and management of subcontractors processing PII: we draft the procedures required by the 25 additional controls of ISO 27018, while the platform monitors each control over time, flagging non-conformities before they become issues during an audit.

Complaion Mon 03 Trasp logo
Complaion Hls Trasp logo

Prepare to grow

Build a foundation that integrates with the rest of your IT system.

ISO 27018 integrates into the same control matrix as ISO 27001 and ISO 27017. From there, you are just one step away from compliance with GDPR, NIS 2, and DORA: a single risk assessment, one platform, and no parallel systems to manage.

complaion's process

We'll be with you every step of the way from 0 to 27018.

Documents

Documents

3 gap

Upload documents

We analyze what you already have, what is missing, and what is needed to be ready.

Procedure n.123

3 ready

We write procedures

We develop procedures, policies, and registers based on the way you actually work.

Compliant

Let's do the Audit

We conduct the internal audit, produce the reports, and verify that everything is ready.

ISO 27018

Valid for 3 years

Get the certificate

A Certification Body carries out the External Audit and issues the Certificate.

Management System Certificate

Management System Certificate

ISO 27017

ISO 27018:2019

ISO 27018:2015

Personal Data Protection in the Cloud

Personal Data Protection in the Cloud

issued by

issued by

Accredited body

Accredited body

Valid 3 years

Valid for 3 years

Renewal included

Renewal included

ISO 27018 CERTIFIED COMPANY

Certification issued by an Accredited Body.

Valid for 3 years

Recognized in over 170 countries

Demand in public tenders

Renewal managed by us

VERIFIED REVIEWS

Who has obtained ISO 27018
with Complaion.

A pleasant discovery

We were dealing with the "usual" lengthy timelines for ISO 9001 and ISO 27001 (with the 27017 extension) certifications, but everything changed when we discovered Complaion. The communication was clear, precise, and—above all—super fast and responsive!

AC

CastInformatica

June 5, 2026

A pleasant discovery

We were dealing with the "usual" lengthy timelines for ISO 9001 and ISO 27001 (with the 27017 extension) certifications, but everything changed when we discovered Complaion. The communication was clear, precise, and—above all—super fast and responsive!

AC

CastInformatica

June 5, 2026

Very serious company

In addition to consulting services, they offer an online platform that greatly simplifies quality system management. Alessia, the consultant who guided us through the certification process, is knowledgeable and extremely helpful.

TB

Croce Blu

May 6, 2026

Very serious company

In addition to consulting services, they offer an online platform that greatly simplifies quality system management. Alessia, the consultant who guided us through the certification process, is knowledgeable and extremely helpful.

TB

Croce Blu

May 6, 2026

Winning model

I received excellent support throughout every stage of the certification process, even during the most challenging times of the year. The combination of the platform and easily accessible human consultants is ideal.

AF

Logistic Solution

February 16, 2026

Winning model

I received excellent support throughout every stage of the certification process, even during the most challenging times of the year. The combination of the platform and easily accessible human consultants is ideal.

AF

Logistic Solution

February 16, 2026

FOR GROWING COMPANIES

Not sure which ISO
ISO partire?

A 30-minute meeting with one of our consultants will be enough to show you the fastest path.

FOR GROWING COMPANIES

Not sure which ISO to start with?

A 30-minute meeting with one of our consultants will be enough to show you the fastest path.

FOR GROWING COMPANIES

Not sure which ISO

to start with?

A 30-minute meeting with one of our consultants will be enough to show you the fastest path.

FREQUENTLY ASKED QUESTIONS

Do you have any questions about ISO 27018 or how Complaion can help you?

What is ISO 27018 and why is it important for my company?

ISO 27018 is the standard that defines specific controls for the protection of personally identifiable information (PII) in the public cloud, featuring 25 additional controls compared to ISO 27001. It cannot be certified in isolation; rather, it is obtained as an extension of ISO 27001. It is significant because AgID requires it—along with ISO 27017—for access to the Public Administration Cloud Marketplace, and because it strengthens GDPR compliance for entities processing personal data in the cloud.

How can you help my company achieve ISO 27018 certification?

If you don’t yet have ISO 27001 certification, we build it together with the privacy controls of ISO 27018 already integrated. If you already have it, a Lead Auditor maps data subject rights, breach notifications, and subcontractor management, adding them to your existing system. The platform generates the required documentation and monitors each control over time.

How long does it usually take to obtain ISO 27018 certification with Complaion?

It depends on your starting point: if you already have ISO 27001 certification, the time required is significantly reduced because you are extending an existing system rather than building one from scratch. Your Lead Auditor will provide a precise estimate after the initial analysis.

What kind of support does Complaion offer during the process?

A dedicated Lead Auditor oversees every critical phase, from mapping privacy controls to audit preparation, while the platform automates documentation and monitors each control over time.

How do I start the process with Complaion?

Request information via the website: a Lead Auditor checks whether you already hold ISO 27001 certification and proposes the most suitable plan, whether you are starting from scratch or building upon an existing system.

Do you provide assistance with certifications other than ISO 27018?

Yes. ISO 27018 integrates into the same control matrix as ISO 27001 and ISO 27017. From there, you are already closer to compliance with GDPR, NIS 2, and DORA. Your Lead Auditor builds everything upon the same system.

REQUEST INFORMATION

We help you get certified quickly.

©2026 Complaion. All Rights Reserved / Complaion S.r.l., P. IVA 12884580965, Via R. Amundsen 5, Milano
PEC: part@pec.it, Capitale Sociale: €17.017,18, REA MI-2690509

REQUEST INFORMATION

We help you get certified quickly.

©2026 Complaion. All Rights Reserved / Complaion S.r.l., P. IVA 12884580965, Via R. Amundsen 5, Milano PEC: part@pec.it, Capitale Sociale: €17.017,18, REA MI-2690509

REQUEST INFORMATION

We help you
get certified quickly.

©2026 Complaion. All Rights Reserved / Complaion S.r.l., P. IVA 12884580965, Via R. Amundsen 5, Milano PEC: part@pec.it, Capitale Sociale: €17.017,18, REA MI-2690509