The certification builds on Nakisa's existing ISO 27001 and ISO 27017 credentials, adding independently audited assurance for how customer data is protected in Nakisa cloud services.
Independent assurance for customer data in the cloud
Nakisa has achieved ISO 27018 certification, the international standard for protecting personally identifiable information (PII) in public cloud services. The certification adds a standard dedicated to privacy for customer data in the cloud to Nakisa's existing ISO 27001 and ISO 27017 certifications. Customers now have independently audited assurance that their PII is handled according to a globally recognized benchmark.
Steve Simmons
COO of A-LIGN
ISO 27018 is built specifically for cloud service providers that process PII on behalf of their customers. It sets requirements for consent, transparency, and data minimization that go beyond the general controls covered by ISO 27001. For Nakisa customers in the Global 2000, public sector, and highly regulated industries, ISO 27018 strengthens the evidence available to procurement, security, and compliance teams when assessing how customer PII is protected in Nakisa cloud services.
Amir Taghavi
Director of IT & Cloud Services at Nakisa
About Nakisa
Nakisa is an enterprise software company that helps the world's largest organizations manage high-value decisions about their most important assets: their people, real estate, equipment and financial commitments.
For over 20 years, Nakisa has served Global 2000 enterprises, including large public sector organizations, spanning workforce planning and organizational design, real estate portfolio management, lease accounting and compliance, and decision intelligence. Customers such as Walmart, Nestlé, Allied Irish Banks, and Ontario Power Generation rely on Nakisa to manage complex, multi-entity operations at scale.
Request a personalized demo of Nakisa here.
For more information, contact us here.
FAQ
Nakisa's handling of personally identifiable information in the cloud has been independently audited against a globally recognized standard for consent, transparency, and data minimization.
ISO 27001 covers information security management broadly, and ISO 27017 covers cloud security controls. ISO 27018 adds requirements specific to protecting PII in public cloud environments.
Complete the compliance reports request form to request a copy. An NDA is required to review the reports.