AWS Compliance Programs

The AWS Compliance Program helps customers to understand the robust controls in place at AWS to maintain security and compliance of the cloud. By tying together governance-focused, audit-friendly service features with applicable compliance or audit standards, AWS Compliance Enablers build on traditional programs, helping customers to establish and operate in an AWS security control environment.

IT standards we comply with are broken out by Certifications and Attestations; Laws, Regulations and Privacy; and Alignments and Frameworks. Compliance certifications and attestations are assessed by a third-party, independent auditor and result in a certification, audit report, or attestation of compliance. AWS customers remain responsible for complying with applicable compliance laws, regulations and privacy programs. Compliance alignments and frameworks include published security or compliance requirements for a specific purpose, such as a specific industry or function.

Global

CSA

Cloud Security Alliance Controls

CyberGRX

Third Party Risk Management

CyberVadis

Third Party Risk Management

ISO 9001

Global Quality Standard

ISO 22301

Security and resilience

ISO 27001

Security Management Controls

ISO 27017

Cloud Specific Controls

ISO 27701

Privacy Information Management

ISO 27018

Personal Data Protection

PCI DSS Level 1

Payment Card Standards

SOC 1

Audit Controls Report

SOC 2

Security, Availability, & Confidentiality Report

SOC 3

General Controls Report

Americas

CCCS

Canadian Centre for Cyber Security (CCCS) Assessment

CJIS

Criminal Justice Information Services

U.S. govt icon

CMMC

Cybersecurity Maturity Model Certification

U.S. govt icon

DFARS

Defense Federal Acquisition Regulation Supplement

DoD SRG

Department of Defense
Data Processing

FedRAMP

Government Data Standards

FERPA

Educational Privacy Act

FIPS

Government Security Standards

FISMA

Federal Information Security Management

GxP

Quality Guidelines and Regulations



HIPAA

Protected Health Information



HITRUST CSF

Health Information Trust Alliance Common Security Framework

United States of America Department of State logo

ITAR

International Traffic in Arms Regulations


MPAA

Protected Media Content

NIST

National Institute of Standards and Technology

PIPEDA

Canada’s Federal Private Sector Privacy Legislation 

SEC Rule 17a-4(f)

Recordkeeping Rules

VPAT / Section 508

Accessibility Standards

Asia Pacific

FinTech

Reference Architecture in Japan

FISC

Center for Financial Industry Information Systems in Japan

IRAP

Security Standards in Australia

ISMS logo

K-ISMS

Information Security in Korea

ISMAP

Government program to assess security of public cloud services in Japan

MTCS Tier 3

Multi-Tier Cloud Security Standard in Singapore

NISC

National Center of Incident Readiness and Strategy for Cybersecurity in Japan

OSPAR

Outsourcing Guidelines in Singapore

Europe, Middle East & Africa

HDS

HDS

Personal Health Data Protection in France
 

C5

Operational Security Attestation in Germany

CISPE

Coalition of Cloud Infrastructure Services Providers in Europe

Cyber Essentials Plus

Cyber Threat Protection in the UK

ENS High

Government Standards in Spain

Swiss flag

FINMA ISAE 3000 Type 2 Report

Attestation for Swiss Financial Market Supervisory Authority Circulars

G-Cloud

Government Standards in the UK

Print

GSMA

GSM Association

Finland Flag

PiTuKri ISAE 3000 Type II Report

Criteria for Assessing the Information Security of Cloud Services

TISAX

Automotive Industry Standard

Certifications / Attestations:

Compliance certifications and attestations are assessed by a third-party, independent auditor and result in a certification, audit report, or attestation of compliance.

Laws / Regulations:

AWS customers remain responsible for complying with applicable compliance laws and regulations. In some cases, AWS offers functionality (such as security features), enablers, and legal agreements (such as the AWS Data Processing Agreement and Business Associate Addendum) to support customer compliance.

No formal certification is available to (or distributable by) a cloud service provider within these law and regulatory domains.

Alignments / Frameworks:

Compliance alignments and frameworks include published security or compliance requirements for a specific purpose, such as a specific industry or function. AWS provides functionality (such as security features) and enablers (including compliance playbooks, mapping documents, and whitepapers) for these types of programs.

Requirements under specific alignments and frameworks may not be subject to certification or attestation; however, some alignments and frameworks are covered by other compliance programs.

Privacy

At AWS, customer trust is our top priority. We deliver services to millions of active customers, including enterprises, educational institutions, and government agencies in over 190 countries. Our customers include financial services providers, healthcare providers, and governmental agencies, who trust us with some of their most sensitive information.

Have Questions? Connect with an AWS Business Representative
Exploring compliance roles?
Apply today »
Want AWS Compliance updates?
Follow us on Twitter »