Amazon Web Services
The company that industrialized compliance. AWS's shared responsibility model is the most influential GRC concept of the cloud era, and its biggest risk is the half of the model that belongs to the customer.
Overview
AWS runs the largest compliance-certified infrastructure on earth: its SOC 2, ISO 27001, FedRAMP, and PCI DSS scopes span hundreds of services across dozens of regions, and its compliance documentation is consumed by more auditors than any other company's. But the genuinely original contribution is conceptual: the shared responsibility model, which splits security and compliance obligations between AWS (security of the cloud) and the customer (security in the cloud).
That model is simultaneously AWS's greatest governance asset and its most persistent exposure, because most cloud breaches occur on the customer side of the line, and AWS's name carries the reputational damage regardless.
Compliance posture at a glance
| Framework | Status | Notes |
|---|---|---|
| ISO 27001 / 27017 / 27018 | Certified | Core services across all commercial regions; PII extension for customer data. |
| SOC 1 / 2 / 3 | Audited | Type II reports; SOC 3 public; attestations per region and service. |
| FedRAMP | High / Moderate | Hundreds of services authorized; GovCloud for public sector. |
| PCI DSS | Level 1 | Validated service provider; customer carve-outs documented. |
| HIPAA / HITRUST | BAA / certified | Healthcare workloads with BAAs and HITRUST CSF certification. |
| C5 / IRAP / regional | Attested | Germany C5, Australia IRAP, Japan, Singapore, and more. |
| NIST / CMMC | Mapped | 800-53-based controls; CMMC alignment for defense supply chain. |
NIST CSF 2.0 maturity assessment
Overall: 4.4 / 5. AWS-side maturity is elite across the board, with response and recovery slightly lower only because the customer half of the model (where most incidents live) is outside AWS's direct control.
Key findings
1. The shared responsibility model is governance architecture
By making the line explicit, and auditable via the AWS Artifact portal, AWS gave customers and their auditors a contractual fact instead of a marketing claim. Every major cloud vendor now copies the model; AWS invented it.
2. Compliance automation at industrial scale
AWS Config, Control Tower, Security Hub, and Artifact turn compliance evidence into API-consumable artifacts. A customer can demonstrate control status to an auditor with infrastructure-as-code, the direction enterprise GRC is moving everywhere.
3. Attestation breadth as the moat
More certifications, in more regions, than any competitor, and each one scoped to specific services and geographies. For regulated buyers (finance, health, government), the question "is my workload in scope" has a documented answer.
Watch items
The customer side of the line
The overwhelming majority of AWS-environment breaches are misconfigurations on the customer side, public S3 buckets, exposed keys, overly permissive IAM. AWS documents the boundary perfectly and then carries reputational risk for what happens inside it.
AI services and the responsibility line
Bedrock and SageMaker move responsibility in new directions, model governance, data provenance, and AI Act obligations sit awkwardly in the classic shared model. Watch how AWS redraws the line for AI workloads.
Concentration and sovereignty
AWS's dominance invites regulatory scrutiny (EU cloud-sovereignty debates, DORA third-party rules) and makes its own operational incidents, like major-region outages, systemic events with GRC consequences for thousands of customers.
Bottom line
AWS is the industrial model of compliance at scale: attestation breadth, automation, and a responsibility boundary that reshaped how the entire industry thinks about cloud governance. Its next test is whether the shared responsibility concept survives contact with AI.
Sources & verification
Every factual claim above was verified against the following public sources (accessed August 2026). Figures updated to the latest fiscal year reported.
Verification note: Certification claims verified against AWS's own compliance pages (which publish the certificate/attestation documents). Revenue is the AWS segment figure from Amazon's FY2024 10-K. The claim that "most cloud breaches are customer-side misconfigurations" is an industry-wide observation reflected in cloud-security reporting (e.g., Verizon DBIR and cloud vendor incident analyses), not a figure AWS itself publishes, it is presented as an analyst judgment on the page. No internal AWS documents were used.