Guide
How to get and use the AWS SOC 2 report in your own examination
The AWS SOC 2 report covers Amazon's controls over its infrastructure. So it does not cover your workloads, but it lets your own report carve out the data centre and platform layer.
- Preparation, not the examination
- A licensed CPA firm signs the report
- Plain-English guidance
Where to find the AWS SOC 2 report
Amazon publishes its reports in AWS Artifact, inside the AWS console. You accept the terms, then download it. Therefore anyone in your account with access can retrieve it.
What the AWS SOC 2 report covers
It covers Amazon's controls for the services listed in scope. However, it does not cover how you configure those services.
| Layer | Covered by | Your report |
|---|---|---|
| Data centres and hardware | AWS. | Carved out. |
| Managed service platforms | AWS, for listed services. | Carved out. |
| Your configuration and data | You. | In scope. |
AWS SOC 2 report checklist
Tick what you have done.
Your result appears here as you tick, so you can see what is still open.
Using the AWS SOC 2 report in your examination
Your CPA firm will usually carve out AWS and rely on its report. So you should read it, confirm the services you use are listed, and keep a copy as vendor management evidence.
User entity controls you still own
The AWS SOC 2 report lists complementary user entity controls. These are duties AWS expects of customers, such as managing your own IAM users. Therefore your controls must cover them, or your auditor may note a gap.
Our role
We help you map those duties to your controls during readiness. However, the examination is performed by a licensed CPA firm, since we are not one. Reference: AICPA guidance on SOC 2.
Keep the download date on file. Your CPA firm may ask which version you relied on, and Amazon updates its reports periodically. Also check whether newer services you adopted during the year appear in the latest report's scope. If a service you depend on is missing, discuss it with your CPA firm early, because it may change how that part of your system is examined.
AWS SOC 2 report questions
Does the AWS SOC 2 report make us compliant?
No. It covers Amazon's controls, while yours are examined separately.
How often is it updated?
Amazon issues reports periodically, so download the latest before your examination.
Can we share the AWS SOC 2 report with customers?
Check the Artifact terms, because sharing is restricted.
What is a carve-out?
Excluding AWS controls from your report while relying on its own report.
Related guides
Map your cloud duties before fieldwork
Tell us your AWS services. We reply with a written scope and a fixed preparation fee.
Scope your preparation