AWS Certified Cloud Practitioner
AWS Compliance and AWS Artifact
Learn how AWS proves it meets security standards, which compliance programs it holds, and how AWS Artifact gives you on-demand access to audit reports and agreements.
- Explain what cloud compliance means and how it ties to the shared responsibility model
- Identify the main compliance programs and certifications AWS holds
- Describe what AWS Artifact is and the documents it provides
- Explain who can access AWS Artifact and the rules for handling its reports
Why compliance matters in the cloud
Many organizations have to follow rules about how they handle data. A hospital must protect patient records, an online store that takes card payments must meet payment-card rules, and a government supplier must meet government security standards. These rules come from laws, industry bodies, and regulators, and breaking them can mean fines or losing the right to operate.
When you run everything in your own data center, you have to prove you meet every rule yourself, top to bottom. Moving to AWS changes that. AWS already meets a long list of standards for the infrastructure it runs, and it gives you the paperwork to prove it. You still have to handle compliance for what you build, but you inherit a strong, audited foundation underneath.
How AWS proves its compliance
AWS does not just claim to be secure. Independent auditors and accreditation bodies test its controls and issue formal reports and certifications. AWS environments are audited on an ongoing basis, and the results are published so customers can rely on them.
These audits cover the parts of the system AWS owns: the physical data centers, the hardware, and the software that runs AWS services. This is the "security of the cloud" side of the shared responsibility model. Because AWS proves these controls once, every customer benefits from them instead of each company auditing the same data centers separately.
AWS compliance programs
AWS takes part in many compliance programs that span different regions and industries. You do not need to memorize the full list for the exam, but you should recognize the common ones and what they relate to.
| Program | What it covers |
|---|---|
| SOC 1, 2, 3 | System and Organization Controls reports on AWS's security and operational controls |
| PCI DSS Level 1 | Payment Card Industry Data Security Standard for handling card data |
| ISO 27001, 27017, 27018 | International standards for information security and cloud privacy |
| HIPAA | US healthcare data protection (AWS offers HIPAA-eligible services) |
| FedRAMP | US government cloud security authorization |
| GDPR | European Union data protection regulation |
One detail to keep straight: AWS being certified or "eligible" for a standard does not make your workload compliant by itself. If you run a healthcare app, AWS offering HIPAA-eligible services is a starting point, but you still have to configure and use those services correctly. Compliance of what you build stays your job.
What is AWS Artifact?
AWS Artifact is a self-service portal that gives you on-demand access to AWS's security and compliance documents. Instead of opening a support ticket and waiting, you sign in, find the report you need, and download it in minutes. The service is free.
Artifact has two main kinds of content:
Reports. These are AWS's audit artifacts, such as SOC 1, 2, and 3, PCI DSS, and ISO certifications. You hand these to your auditors or regulators to show that the AWS infrastructure under your application meets a given standard. New reports are added as they become available.
Agreements. Artifact also lets you review, accept, and track the status of legal agreements with AWS, such as a Business Associate Addendum for HIPAA. You can manage these for one account or across many accounts in your organization.
Who can access Artifact, and the rules for using it
Every AWS account has access to AWS Artifact. The root user and IAM users with the right permissions can download the available documents after agreeing to the terms attached to each one.
These reports are confidential. Each download carries a unique, traceable watermark tied to your account. You are allowed to share them inside your company and with your regulators and auditors, but you must not post them publicly or hand them to your own customers. Treat them as sensitive legal documents, because that is what they are.
How Artifact fits the bigger picture
Think of AWS Artifact as the evidence locker for the "of the cloud" side of security. When someone needs proof that AWS itself is compliant, Artifact is where that proof lives. When the question is about your data, your access settings, or your application, that is the "in the cloud" side, and the evidence for it comes from you, not Artifact.
Exam tips
- AWS Artifact is the go-to service for downloading AWS compliance reports (SOC, PCI DSS, ISO) and managing agreements. It is free and self-service.
- If a question asks where to get AWS's audit reports for an auditor, the answer is AWS Artifact.
- AWS holds many compliance certifications, but its certifications do not make your own workload compliant. Compliance in the cloud is your responsibility.
- Artifact reports are confidential and watermarked. Share them with auditors and regulators, not the public.
- Recognize common programs by name: SOC, PCI DSS, ISO 27001, HIPAA, FedRAMP, and GDPR.
