ISO 27017 cloud security certification exists to close a specific gap. ISO 27001:2022 tells you to manage supplier risk and control access; it does not tell you who is responsible for hypervisor hardening, what happens to your data when you terminate a cloud contract, or how a customer and a provider divide the work of monitoring.
ISO 27017 is a code of practice that extends ISO 27002 with cloud-specific guidance: additional implementation advice on existing controls plus seven controls that exist only in the cloud context. Crucially, it is written for both sides: cloud service customers and cloud service providers each get their own guidance, and the point of the standard is making the boundary between them explicit.
It is not a standalone certification. It is audited as an extension of an ISO 27001:2022 management system, so the sensible route is to build or extend the ISMS with cloud scope from the start. Where personal data is involved, ISO 27018 is the companion standard; the technical half is cloud security testing.