Skip to main content

AWS Cloud Security

AWS Services in Scope by Compliance Program

Federal Risk and Authorization Management Program (FedRAMP)

We include generally available services in the scope of our compliance efforts based on the expected use case, feedback and demand. If a service is not currently listed as in scope of the most recent assessment, it does not mean that you cannot use the service. It is part of the shared responsibility for your organization to determine the nature of the data. Based on the nature of what you are building on AWS, you should determine if the service will process or store customer data and how it will or will not impact the compliance of your customer data environment.

We encourage you to discuss your workload objectives and goals with your AWS account team; they will be able to evaluate your proposed use case and architecture, and how our security and compliance processes overlay that architecture. Need to connect with an AWS business representative?

This webpage provides a list of AWS Services in Scope of AWS assurance programs. Unless specifically excluded, generally available features of each of the services are considered in scope of the assurance programs, and are reviewed and tested at the next opportunity for assessment. Refer to the AWS Documentation for the features of an AWS service.

βœ“ = This service is currently in scope and is reflected in current reports. For more specific details on status, please refer to each compliance program tab below.

 

Services going through FedRAMP assessment and authorization will have the following status:

  • Third-Party Assessment Organization (3PAO) Assessment: This service is currently undergoing an assessment by our third-party assessor
  • Under Review: This service is currently undergoing review by the FedRAMP Board

 

FedRAMP
Last updated: September 12, 2025

SERVICES / PROGRAMS SDKs FedRAMP Moderate
(East/West)
FedRAMP High
(GovCloud)
FedRAMP Not Required*
Amazon API Gateway apigateway βœ“ βœ“  
Amazon AppStream 2.0 appstream βœ“ βœ“  
Amazon AppFlow appflow βœ“    
Amazon Athena athena βœ“ βœ“  
Amazon Aurora MySQL rds βœ“ βœ“  
Amazon Aurora PostgreSQL rds βœ“ βœ“  
Amazon Bedrock bedrock βœ“ βœ“  
Amazon Chime chime βœ“    
Amazon Chime SDK chime-sdk-meetings βœ“ βœ“  
Amazon Cloud Directory clouddirectory βœ“ βœ“  
Amazon CloudFront [excludes content delivery through Amazon CloudFront Embedded Point of Presences] cloudfront βœ“    
Amazon CloudWatch cloudwatch βœ“ βœ“  
Amazon CloudWatch Logs logs βœ“ βœ“  
Amazon Cognito cognito-idp
cognito-identity
cognito-sync
βœ“ βœ“  
Amazon Comprehend comprehend βœ“ βœ“  
Amazon Comprehend Medical comprehendmedical βœ“ βœ“  
Amazon Connect connect βœ“ βœ“  
Amazon Data Firehose firehose βœ“ βœ“  
Amazon DataZone datazone βœ“    
Amazon Detective detective βœ“ βœ“  
Amazon DevOps Guru devops-guru βœ“    
Amazon DocumentDB (with MongoDB compatibility) docdb βœ“ βœ“  
Amazon DynamoDB dynamodb βœ“ βœ“  
Amazon Elastic Block Store (EBS) ebs βœ“ βœ“  
Amazon Elastic Compute Cloud (EC2) ec2 βœ“ βœ“  
Amazon EC2 Image Builder imagebuilder βœ“ βœ“  
Amazon Elastic Container Registry (ECR) ecr βœ“ βœ“  
Amazon Elastic Container Service (ECS) ecs βœ“ βœ“  
Amazon Elastic File System (EFS) efs βœ“ βœ“  
Amazon Elastic Kubernetes Service (EKS) eks βœ“ βœ“  
Amazon ElastiCache elasticache βœ“ βœ“  
Amazon Elastic MapReduce (EMR) emr βœ“ βœ“  
Amazon EventBridge events, pipes βœ“ βœ“  
Amazon FinSpace finspace βœ“    
Amazon Forecast forecast βœ“    
Amazon FSx fsx βœ“ βœ“  
Amazon GuardDuty guardduty βœ“ βœ“  
Amazon Inspector inspector2 βœ“ βœ“  
Amazon Inspector Classic inspector βœ“ βœ“  
Amazon Kendra kendra βœ“ βœ“  
Amazon Keyspaces (for Apache Cassandra) keyspaces βœ“ βœ“  
Amazon Kinesis Data Streams kinesis βœ“ βœ“  
Amazon Kinesis Video Streams kinesisvideo   βœ“
 
Amazon Lex lex-models, lex-runtime βœ“ βœ“  
Amazon Location Service location   βœ“  
Amazon Macie macie2 βœ“    
Amazon Managed Service for Apache Flink kinesisanalytics βœ“ βœ“  
Amazon Managed Streaming for Apache Kafka (Amazon MSK) kafka βœ“ βœ“  
Amazon Managed Service for Prometheus amp 3PAO Assessment    
Amazon MemoryDB memorydb βœ“ 3PAO Assessment  
Amazon MQ mq βœ“ βœ“  
Amazon Neptune neptune βœ“ βœ“  
Amazon OpenSearch Service opensearch βœ“ βœ“  
Amazon Pinpoint and End User Messaging pinpoint βœ“ βœ“  
Amazon Polly polly βœ“ βœ“  
Amazon Q Business qbusiness βœ“    
Amazon Q Developer in chat applications [formerly AWS Chatbot] chatbot βœ“    
Amazon Quantum Ledger Database (QLDB) qldb βœ“    
Amazon QuickSight quicksight βœ“ βœ“  
Amazon RDS for Db2 rds 3PAO Assessment    
Amazon RDS for MariaDB rds βœ“ βœ“  
Amazon RDS for MySQL rds βœ“ βœ“  
Amazon RDS for Oracle rds βœ“ βœ“  
Amazon RDS for Postgres rds βœ“ βœ“  
Amazon RDS for SQL Server rds βœ“ βœ“  
Amazon Redshift redshift βœ“ βœ“  
Amazon Rekognition rekognition βœ“ βœ“  
Amazon Route 53 route53 βœ“ βœ“  
Amazon S3 Glacier glacier βœ“ βœ“  
Amazon SageMaker AI sagemaker βœ“ βœ“  
Amazon Security Lake securitylake βœ“ βœ“  
Amazon Simple Email Service (SES) ses βœ“ βœ“  
Amazon Simple Notification Service (SNS) sns βœ“ βœ“  
Amazon Simple Queue Service (SQS) sqs βœ“ βœ“  
Amazon Simple Storage Service (S3) s3 βœ“ βœ“  
Amazon Simple Workflow Service (SWF) swf βœ“ βœ“  
Amazon Textract textract βœ“ βœ“  
Amazon Timestream for LiveAnalytics timestream-query, timestream-write βœ“ βœ“  
Amazon Transcribe transcribe βœ“ βœ“  
Amazon Translate translate βœ“ βœ“  
Amazon Verified Permissions verifiedpermissions βœ“ βœ“
 
Amazon Virtual Private Cloud (VPC) ec2 βœ“ βœ“  
Amazon WorkSpaces workspaces βœ“ βœ“  
Amazon WorkSpaces Secure Browser workspaces-web βœ“    
AWS Application Auto Scaling application-autoscaling   βœ“  
AWS Application Migration Service (MGN) mgn βœ“ βœ“  
AWS App Mesh appmesh βœ“    
AWS Artifact artifact     βœ“
AWS Audit Manager auditmanager βœ“    
AWS Backup backup βœ“ βœ“  
AWS Batch batch βœ“ βœ“  
AWS Billing Conductor billingconductor     βœ“
AWS Budgets budgets     βœ“
AWS Certificate Manager (ACM) acm βœ“ βœ“  
AWS Clean Rooms cleanrooms βœ“    
AWS Cloud9 cloud9 βœ“    
AWS CloudFormation cloudformation βœ“ βœ“  
AWS CloudHSM cloudhsm βœ“ βœ“  
AWS Cloud Map servicediscovery βœ“ βœ“  
AWS CloudShell   βœ“ βœ“  
AWS CloudTrail cloudtrail βœ“ βœ“  
AWS CodeBuild codebuild βœ“ βœ“  
AWS CodeCommit codecommit βœ“ βœ“  
AWS CodeDeploy deploy βœ“ βœ“  
AWS CodePipeline codepipeline βœ“ βœ“  
AWS Compute Optimizer compute-optimizer   βœ“  
AWS Config configservice βœ“ βœ“  
AWS Control Tower controltower βœ“ βœ“  
AWS Cost and Usage Reports       βœ“
AWS Cost Explorer ce     βœ“
AWS Database Migration Service (DMS) dms βœ“ βœ“  
AWS Data Exchange dataexchange     βœ“
AWS DataSync datasync βœ“ βœ“  
AWS Direct Connect directconnect βœ“ βœ“  
AWS Directory Service ds βœ“ βœ“  
AWS Edge Hub       βœ“
AWS Elastic Beanstalk elasticbeanstalk βœ“ βœ“  
AWS Elastic Disaster Recovery (AWS DRS) drs βœ“ βœ“  
AWS Elemental MediaConvert mediaconvert βœ“ βœ“  
AWS Entity Resolution entityresolution βœ“    
AWS Fault Injection Service fis βœ“ βœ“  
AWS Firewall Manager fms βœ“ βœ“  
AWS Global Accelerator globalaccelerator βœ“    
AWS Glue glue βœ“ βœ“  
AWS Glue DataBrew databrew βœ“ βœ“  
AWS Ground Station groundstation βœ“    
AWS Health Dashboard health βœ“ βœ“  
AWS HealthImaging medical-imaging βœ“    
AWS HealthLake healthlake βœ“    
AWS HealthOmics omics βœ“    
AWS Identity and Access Management (IAM) iam, sts βœ“ βœ“  
AWS IAM Identity Center sso   βœ“  
AWS IoT Core iot βœ“ βœ“  
AWS IoT Device Defender   βœ“ βœ“  
AWS IoT Device Management iot βœ“ βœ“  
AWS IoT Events iotevents βœ“ βœ“  
AWS IoT Greengrass greengrass βœ“ βœ“  
AWS IoT SiteWise iotsitewise   βœ“  
AWS IoT TwinMaker iottwinmaker   βœ“  
AWS Key Management Service (KMS) kms βœ“ βœ“  
AWS Lambda lambda βœ“ βœ“  
AWS License Manager license-manager βœ“ βœ“  
AWS Mainframe Modernization m2 βœ“    
AWS Managed Services (AMS)   βœ“ βœ“  
AWS Management Console       βœ“
AWS Marketplace       βœ“
AWS Network Firewall network-firewall βœ“ βœ“  
AWS Network Manager networkmanager βœ“ βœ“  
AWS Organizations organizations βœ“ βœ“  
AWS Outposts (Software) outposts βœ“ βœ“  
AWS Private Certificate Authority acm-pca βœ“ βœ“  
AWS Resilience Hub resiliencehub   βœ“  
AWS Resource Access Manager (AWS RAM) ram βœ“ βœ“  
AWS Resource Groups resource-groups βœ“ βœ“  
AWS Secrets Manager secretsmanager βœ“ βœ“  
AWS Security Hub securityhub βœ“ βœ“  
AWS Security Incident Response security-ir 3PAO Assessment    
AWS Serverless Application Repository serverlessrepo βœ“ βœ“  
AWS Service Catalog servicecatalog βœ“ βœ“  
AWS Service Quotas service-quotas     βœ“
AWS Shield (Standard and Advanced) shield βœ“    
AWS Signer signer βœ“ 3PAO Assessment  
AWS Snowball snowball βœ“ βœ“  
AWS Snowball Edge snowball βœ“ βœ“  
AWS Step Functions stepfunctions βœ“ βœ“  
AWS Systems Manager ssm βœ“ βœ“  
AWS Storage Gateway storagegateway βœ“ βœ“  
AWS Transfer Family transfer βœ“ βœ“  
AWS Trusted Advisor trustedadvisor βœ“ βœ“  
AWS Verified Access (AVA)   βœ“ βœ“  
AWS Web Application Firewall (WAF) wafv2 βœ“ βœ“  
AWS Web Application Firewall Classic (WAF Classic) waf-regional βœ“ βœ“  
AWS Well-Architected Tool wellarchitected βœ“ βœ“  
AWS Wickr   βœ“ βœ“  
AWS X-RAY xray βœ“ βœ“  

*Services not within the scope of FedRAMP review. As such, the FedRAMP team has issued neither an approval nor disapproval decision regarding this product under FedRAMP. Customers are able to leverage this service by working with their AWS Sales Representative directly to seek independent agency approval.   

Need help?

For more information about Services in Scope?

Contact Us