The AWS cloud is uniquely positioned to provide scalable cost-efficient solutions for the US Federal Government to find ways cloud services can be employed to meet mandates, reduce costs, drive efficiencies, and increase innovation across its Civilian agencies and the Department of Defense. AWS provides cloud services a pay-as-you-go model, delivering access to technology resources that are managed by experts. Simply access AWS services over the internet, with no upfront costs (no capital investment), and pay only for the computing resources that you use, as your needs scale.

Register today for our recorded webinar: How to Buy Cloud Computing Services for Your Agency.

Webinar: How to Buy Cloud Computing Services for Your Agency »

Leveraging the HHS authorization, U.S. government agencies can evaluate AWS GovCloud (US) for their applications and workloads, complete their own authorizations to use AWS, and deploy systems into the AWS environment. Customers can immediately request access to "Amazon Web Services - AWS GovCloud (US) Region" FedRAMP package by submitting a request on the Compliance Contact Us Request Form or by submitting a request through the FedRAMP Program Management Office.

Workloads that are appropriate for the AWS GovCloud (US) Region include all categories of Controlled Unclassified Information (CUI), including ITAR, as well as Government oriented publicly available data. Because the AWS GovCloud (US) Region is physically and logically accessible by US persons only and also supports FIPS 140-2 compliant end points, customers can manage more heavily regulated data in AWS while remaining compliant with federal requirements.

The AWS GovCloud (US) Region is an AWS Region designed to address the specific regulatory needs of United States government agencies, education entities, and other customers and partners. Learn more about the AWS GovCloud (US) Region »


The Department of Defense (DoD) Cloud Security Model (CSM) provides a formalized assessment and authorization process for cloud service providers (CSPs) to gain a DoD Provisional Authorization, which can subsequently be leveraged by DoD customers. A Provisional Authorization under the CSM provides a reusable certification that attests to our compliance with DoD standards, reducing the time necessary for a DoD mission owner to assess and authorize one of their systems for operation on AWS.

For additional information on the CSM, including the full definition of the security control baselines defined for Levels 1 through 6 can be found here.

AWS GovCloud Earns DoD CSM Level 3-5 Provisional Authorization »


AWS recognizes that when law enforcement places data in the cloud it puts an absolute priority on timely and secure access to information, wherever and whenever it is needed. To meet these needs, the AWS cloud infrastructure has been architected to be one of the most flexible and secure cloud computing environments available for storing criminal justice information. Our architecture provides an extremely scalable, highly reliable platform enabling customers to deploy applications and data quickly and securely in support of a wide variety of security and regulatory requirements, to include Criminal Justice Information Services (CJIS) workloads according to the CJIS Security Policy.

In the spirit of a shared responsibility philosophy AWS has created a Criminal Justice Information Services (CJIS) Workbook in a security plan template format aligned to the CJIS Policy Areas. This Workbook is intended to support our partners documenting their alignment to CJIS security requirements. Furthermore, the template provides our partners and customer agencies a systematic approach to documenting their implementation of CJIS security requirements for review and authorization. The workbook provides an overview of CJIS, AWS and AWS services, and the AWS/Customer applicability of CJIS requirements.

This document is releasable under an AWS Non-Disclosure Agreement (NDA); please reach out to your AWS point of contact for more details or submit a request for more information by contacting AWS Sales and Business Development.


The Federal Risk and Authorization Management Program (FedRAMP) is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. AWS has two separate FedRAMP Agency ATOs in the FedRAMP Repository; one ATO applicable to the AWS US East/West regions, and the other applicable to the AWS GovCloud (US) Region. AWS US East/West is a multi-tenant public cloud for federal, state, and local government customers, as well as enterprise customers, and is designed to meet a wide range of regulatory requirements, including government compliance and security requirements. AWS GovCloud (US) is an AWS Region designed to allow US government agencies, contractors and customers to move more sensitive workloads into the cloud by addressing their specific regulatory and compliance requirements, such as ITAR, which governs how organizations manage and store defense-related data. Additional information is available at AWS GovCloud (US) Region.

Agencies and federal contractors can immediately request access to the AWS HHS ATO packages by submitting a FedRAMP Package Access Request Form for the "Amazon Web Services - AWS GovCloud (US) Region" with package ID "AGENCYAMAZONGC" and the "Amazon Web Services - US East/West Region" with package ID "AGENCYAMAZONEW". Additional information on FedRAMP, including the FedRAMP Concept of Operations (CONOPS) and Guide to Understanding FedRAMP, can be found at

Why is FedRAMP important?

The Cloud First policy mandates that agencies take full advantage of cloud computing benefits to maximize ...  » Click for FAQs: AWS FedRamp

Services in Scope

The following services are in the accreditation boundary for the regions stated:

Amazon Redshift: Amazon Redshift is a fast, fully managed, petabyte-scale data warehouse service that makes it simple and cost-effective to efficiently analyze all your data using your existing business intelligence tools.

Amazon Elastic Compute Cloud (Amazon EC2): Amazon EC2 provides resizable compute capacity in the cloud. It is designed to make web-scale computing easier for developers.

Amazon Simple Storage Service (S3): Amazon S3 provides a simple web services interface that can be used to store and retrieve any amount of data, at any time, from anywhere on the web.

Amazon Virtual Private Cloud (VPC): Amazon VPC provides the ability for you to provision a logically isolated section of AWS where you can launch AWS resources in a virtual network that you define.

Amazon Elastic Block Store (EBS): Amazon EBS provides highly available, highly reliable, predictable storage volumes that can be attached to a running Amazon EC2 instance and exposed as a device within the instance.

AWS Identity and Access Management (IAM): IAM enables you to securely control access to AWS services and resources for your users. Using IAM, you can create and manage AWS users and groups and use permissions to allow and deny their access to AWS resources.

Click here for all our AWS Public Sector Case studies.


The Financial Industry Regulatory Authority (FINRA), one of the largest independent securities regulators in the U.S., was established to help watch and regulate financial trading practices. To respond to rapidly changing market dynamics, FINRA is moving its platform to Amazon Web Services (AWS) to analyze and store approximately 30 billion market events every day.

Read More »


From the control room in Pasadena, California, NASA/JPL is using Amazon Web Services (AWS) to capture and store images and metadata collected from the Mars Exploration Rover and the Mars Science Laboratory missions.

Read More »


For the 2012 campaign, OFA chose AWS as the foundation of their system design. The campaign needed what AWS offered: on-demand utility pricing, elasticity, security, scalability and reliability. Amazon Web Services (AWS) provided OFA with a foundation on which to build close to 200 applications with a set of APIs that leveraged diverse data sets as one shared data source.

Read More »

In order to provide end-to-end security and end-to-end privacy, AWS builds services in accordance with customer mandates, security best practices, provides appropriate security features in those services, and documents how to use those features.

The AWS cloud infrastructure has been designed and managed in alignment with regulations, standards, and best-practices including:

  • SOC 1/SSAE 16/ISAE 3402 (formerly SAS70)
  • SOC 2 / SOC 3 (FAQs)
  • PCI DSS Level 1 (FAQs)
  • ISO 27001 (FAQs)
  • FedRAMP(SM) (FAQs)
  • ITAR
  • FIPS 140-2
  • CSA
  • MPAA


TCO Detailed Calculator for Web Applications
Get a detailed TCO comparison for AWS and on-premises IT infrastructure

Launch the Calculator »


The AWS Partner Network
The AWS Partner Network is made up of a strong and growing community of companies that offer a wide range of products and services on the AWS platform. To find the type of AWS Partner that meets your needs, use the search criteria in this directory to refine your search. Click here »

AWS Marketplace
Find great cloud software, launch quickly and pay by the hour. Shop now »