Amazon Web Services (AWS)

Cloud & Infrastructure United States Website Reviewed Aug. 6, 2026

Global cloud infrastructure provider (IaaS/PaaS) delivering compute, storage, database, networking, AI and security services across 30+ regions.

Certifications & Accreditations

Certification Certifying Body Scope Achieved Expiry Status
ISO/IEC 27001:2022 EY CertifyPoint AWS global infrastructure and in-scope AWS services Current
SOC 1 / SOC 2 / SOC 3 Independent third-party auditor In-scope AWS services; security, availability, confidentiality (SOC 2 Type II) Current
PCI DSS v4.0 (Level 1 Service Provider) Coalfire (QSA) In-scope AWS services supporting cardholder data environments Current
ISO/IEC 27017:2015 EY CertifyPoint Cloud-specific information security controls Current
ISO/IEC 27018:2019 EY CertifyPoint Protection of personally identifiable information in public cloud Current
ISO/IEC 27701:2019 EY CertifyPoint Privacy information management system (PIMS) Current
ISO 22301:2019 EY CertifyPoint Business continuity management system Current
ISO 9001:2015 EY CertifyPoint Quality management system for in-scope AWS services Current
ISO/IEC 42001:2023 EY CertifyPoint AI management system for in-scope AI services Current
CSA STAR Level 2 (CCM) Cloud Security Alliance / third-party auditor Cloud Controls Matrix self-assessment and certification Current
FedRAMP (Moderate / High) 3PAO, JAB / Agency authorised AWS US East/West, GovCloud (US) and in-scope services Current

Compliance Frameworks

ISO/IEC 27001:2022
Full
Certified by EY CertifyPoint; certificate and scope available via AWS Artifact.
SOC 2 Type 2
Full
SOC 2 Type II report issued semi-annually; available under NDA via AWS Artifact.
PCI DSS v4.0
Full
Level 1 Service Provider AoC; responsibility shared with customer for in-scope workloads.
ISO 22301:2019
Full
ISO 22301 certified business continuity management system.
ISO 9001:2015
Full
ISO 9001 quality management certification for in-scope services.
ISO 14001:2015
Full
ISO 14001 environmental management certification.
BSI C5
Full
BSI C5 attestation (Germany) covering in-scope AWS services.
GDPR 2016/679
Full
AWS acts as processor under the AWS DPA; SCCs and EU-US DPF used for transfers.
HIPAA Security
Full
HIPAA-eligible services covered by AWS Business Associate Addendum (BAA).
NIST Cybersecurity Framework
Full
Alignment/framework mapping published by AWS; not a certification in itself.
CIS V8
Partial
CIS Benchmarks and CIS-hardened AMIs available; implementation is customer responsibility.

Penetration Testing

Scope Conducted By Date Frequency Report
AWS infrastructure and in-scope services, assessed by independent auditors under the SOC 2, ISO 27001 and PCI DSS programmes (AWS does not publish individual test dates; date shown is the profile capture date) Independent third-party auditors / AWS internal security assurance Aug. 6, 2026 Annual On NDA
Customer-initiated penetration testing of the customer’s own AWS resources, permitted for listed services without prior approval (date shown is the profile capture date) Customer or customer-appointed testing provider Aug. 6, 2026 Ad-hoc Not Available

Data Handling

Data Residency Regions
US, Canada, Brazil, Chile, Mexico, UK, Ireland, Germany, France, Italy, Spain, Sweden, Switzerland, Israel, UAE, Bahrain, Saudi Arabia, South Africa, India, Singapore, Japan, South Korea, Australia, New Zealand, Hong Kong, Thailand, Malaysia, Indonesia, AWS European Sovereign Cloud (Germany)
Encryption at Rest
Yes — AES-256. Customer-managed and AWS-managed keys via AWS KMS (FIPS 140-3 validated HSMs) and CloudHSM. Encryption on by default for S3, EBS, RDS snapshots and DynamoDB.
Encryption in Transit
Yes — TLS 1.2 minimum with TLS 1.3 supported across service endpoints (AWS s2n-tls). Private connectivity available via VPC endpoints, PrivateLink and Direct Connect with MACsec.
Backup Frequency
Customer-configurable via AWS Backup and service-native snapshots. AWS provides multi-AZ replication; S3 is designed for 99.999999999% object durability.
Retention Policy
Data Deletion
Customer retains ownership and controls deletion of content at any time. Decommissioned storage media are destroyed in line with NIST 800-88 techniques. Post-termination deletion obligations are set out in the AWS Data Processing Addendum.

Sub-processors

Sub-processor Purpose Data Location Trust Portal
Twilio, Inc. A2P messaging for AWS End User Messaging and Amazon SNS USA View ↗
Vonage Holdings Corp. (Nexmo Inc.) A2P messaging and phone number validation USA
Sinch Americas Inc. A2P messaging USA
Infobip Ltd. A2P messaging United Kingdom
TeleSign Corporation A2P messaging and phone number validation USA
Route Mobile (UK) Ltd A2P messaging United Kingdom
Cequens FZE A2P messaging United Arab Emirates
Tanla Digital Labs FZ-LLC A2P messaging United Arab Emirates
Meta Platforms, Inc. / Meta Platforms Ireland Ltd. WhatsApp messaging for AWS End User Messaging USA, Ireland
Environmental Systems Research Institute, Inc. (Esri) Geolocation - maps and points of interest for Amazon Location Service USA, Germany, Australia
HERE North America, LLC Geolocation - maps and places for Amazon Location Service and AWS IoT Core USA
Grabtaxi Holdings Pte Ltd Geolocation - maps and places (device location feature) Singapore
Key-Systems GmbH Domain registration for Amazon Route 53 Germany
250ok Inc. / Email Data Source, Inc. Email deliverability metrics for Amazon Pinpoint USA, United Kingdom, Brazil

Incident & Breach History

Date Summary Impact Resolution Report
Nov. 25, 2020 Amazon Kinesis Data Streams service event in the US-EAST-1 region caused by an operating system thread limit reached during capacity addition. Elevated error rates for Kinesis and dependent services including CloudWatch, Cognito and EventBridge for several hours in a single region. Thread configuration and capacity limits raised, front-end fleet re-architected onto larger hosts, and cellularisation work accelerated. Report ↗
Dec. 7, 2021 Automated scaling activity in the AWS internal network of the US-EAST-1 region triggered congestion between the internal and main networks. Degraded API availability and console access affecting many services in US-EAST-1 for approximately seven hours; global services homed in that region were also affected. Scaling behaviour corrected, additional network configuration deployed, and Service Health Dashboard and support routing improved to be multi-region. Report ↗
June 13, 2023 A latent defect in a subsystem responsible for capacity management for AWS Lambda caused elevated error rates in US-EAST-1. Elevated error rates and latency for Lambda, and knock-on impact to services dependent on Lambda, for roughly three hours in a single region. Defective subsystem behaviour remediated and additional safeguards plus monitoring added around capacity management. Report ↗

Security Policies

Policy Availability Link
AWS Shared Responsibility Model Public View ↗
AWS Privacy Notice Public View ↗
AWS Acceptable Use Policy Public View ↗
AWS Security Bulletins (vulnerability advisories) Public View ↗
AWS Risk and Compliance Whitepaper Public View ↗
Compliance reports (SOC, ISO, PCI DSS) via AWS Artifact On Request View ↗
AWS Data Processing Addendum and GDPR resources Public View ↗

Contact & Responsible Disclosure

Trust Portal & Audit Evidence

**Trust portal:** [AWS Artifact](https://aws.amazon.com/artifact/) - self-service portal for on-demand access to SOC 1/2/3 reports, ISO certificates, PCI DSS AoC, C5 and country-specific attestations. Most reports require acceptance of an NDA within the console.

**Public compliance index:** [AWS Compliance Programs](https://aws.amazon.com/compliance/programs/)

**Sub-processor list:** [aws.amazon.com/compliance/sub-processors](https://aws.amazon.com/compliance/sub-processors/) - AWS commits to updating this page at least 30 days before engaging a new sub-processor, with optional email notification.

**Status / availability:** [AWS Health Dashboard](https://health.aws.amazon.com/health/status)

Risk Assessment Notes

**Inherent risk drivers**

- Tier 1 / critical dependency for most hosting, storage and data processing workloads.
- Broad data categories possible, including personal and special category data, depending on customer configuration.
- Concentration risk: single-region designs (notably US-EAST-1) have historically been the source of the largest customer-visible outages.

**Mitigating factors**

- Extensive independent assurance: ISO 27001/27017/27018/27701/22301/42001, SOC 1-3, PCI DSS Level 1, FedRAMP, C5.
- Mature, versioned DPA with SCCs, documented sub-processor change notification and EU sovereign cloud option.
- Strong native security controls: KMS/CloudHSM, IAM, GuardDuty, CloudTrail, Config, Security Hub.

**Residual responsibilities for the customer (shared responsibility model)**

- Configuration hardening, IAM least privilege, patching of guest OS and applications.
- Region and data-residency selection, backup and DR design, multi-region resilience.
- Encryption key management decisions and logging/monitoring coverage.

**Suggested review cadence:** annual, with evidence refresh from AWS Artifact each time a SOC 2 report is reissued.

Assess Amazon Web Services (AWS) in your own vendor risk programme

SnapGRC lets you send security questionnaires, track DPA status, manage sub-processors, and maintain a supplier risk register — all audit-ready.