AWS Compliance Programs

BarCompliance

Global

csa-logo

CSA

Cloud Security Alliance Controls

ISO9001

ISO 9001

Global Quality Standard

ISO27001

ISO 27001

Security Management Controls

ISO27017

ISO 27017

Cloud Specific Controls

ISO27018

ISO 27018

Personal Data Protection

pci

PCI DSS Level 1

Payment Card Standards

SOC-SizedLogo

SOC 1

Audit Controls Report

SOC-SizedLogo

SOC 2

Security, Availability, & Confidentiality Report

SOC-SizedLogo

SOC 3

General Controls Report

BarCompliance

United States

CJIS_Logo

CJIS

Criminal Justice Information Services

DoD SRG

DoD SRG

DoD Data Processing

FedRAMPLogoNew

FedRAMP

Government Data Standards

dept_education_sized

FERPA

Educational Privacy Act

ffiec_logo_sized

FFIEC

Financial Institutions Regulation

FIPS_New

FIPS

Government Security Standards

FISMASized

FISMA

Federal Information Security Management

GxPLogoAws

GxP

Quality Guidelines and Regulations

HIPAA-sized

HIPAA

Protected Health Information

itar-sized

ITAR

International Arms Regulations

MPAAIcon

MPAA

Protected Media Content

nist-logo

NIST

National Institute of Standards and Technology

sec_logo

SEC Rule 17a-4(f)

Financial Data Standards

VPAT

VPAT / Section 508

Accessibility Standards

BarCompliance

Asia Pacific

FISC

FISC [Japan]

Financial Industry Information Systems

IRAP

IRAP [Australia]

Australian Security Standards

K-ISMSProgram

K-ISMS [Korea]

Korean Information Security

MTCSSingaporeLogo

MTCS Tier 3 [Singapore]

Multi-Tier Cloud Security Standard

MyNumberActLogo

My Number Act [Japan]

Personal Information Protection

BarCompliance

Europe

C5_Sized

C5 [Germany]

Operational Security Attestation

cyber-essentials-logo

Cyber Essentials Plus [UK]

Cyber Threat Protection

GovUkCloud

G-Cloud [UK]

UK Government Standards

tuv_logo_sized

IT-Grundschutz [Germany]

Baseline Protection Methodology

Certifications / Attestations:

Compliance certifications and attestations are assessed by a third-party, independent auditor and result in a certification, audit report, or attestation of compliance.

Laws / Regulations / Privacy:

AWS customers remain responsible for complying with applicable compliance laws and regulations. In some cases, AWS offers functionality (such as security features), enablers, and legal agreements (such as the AWS Data Processing Agreement and Business Associate Addendum) to support customer compliance.

No formal certification is available to (or distributable by) a cloud service provider within these law and regulatory domains.

Alignments / Frameworks:

Compliance alignments and frameworks include published security or compliance requirements for a specific purpose, such as a specific industry or function. AWS provides functionality (such as security features) and enablers (including compliance playbooks, mapping documents, and whitepapers) for these types of programs.

Requirements under specific alignments and frameworks may not be subject to certification or attestation; however, some alignments and frameworks are covered by other compliance programs.

compliance-contactus-icon
Have Questions? Connect with an AWS Compliance Representative
Exploring compliance roles?
Apply today »
Want AWS Compliance updates?
Follow us on Twitter »