We include services in the scope of our compliance efforts based on the expected use case, feedback and demand. If a service is not currently listed as in scope of the most recent assessment, it does not mean that you cannot use the service. It is part of the shared responsibility for your organization to determine the nature of the data. Based on the nature of what you are building on AWS, you should determine if the service will process or store customer data and how it will or will not impact the compliance of your customer data environment.
We encourage you to discuss your workload objectives and goals with your AWS account team; they will be able to evaluate your proposed use case and architecture, and how our security and compliance processes overlay that architecture. Need to connect with an AWS business representative?
AWS Services in Scope have been fully assessed by a third party auditor and result in a certification, attestation of compliance or ATO.
โ = This service is currently in scope and is reflected in current reports
In Progress = This service is undergoing a full assessment by our third party assesor
Ready = This service has been fully assessed by our third party assessor and the FedRAMP Security Package is available for review by authorizing officials (AO)
-
SOC
-
PCI
-
ISO
-
FedRAMP
-
DoD CC SRG
SERVICES / PROGRAMS DoD CC SRG IL2 (East/West) DoD CC SRG IL2 (GovCloud) DoD CC SRG IL4 (GovCloud) DoD CC SRG IL5 (GovCloud)
Amazon Aurora (MySQL) โ Amazon CloudWatch Logs โ โ โ Amazon DynamoDB โ โ โ Amazon Elastic Block Store (EBS) โ โ โ โ Amazon Elastic Compute Cloud (EC2) โ โ โ โ Amazon Elastic MapReduce โ โ โ Amazon Glacier โ โ โ Amazon Kinesis Streams โ โ โ Amazon Redshift โ โ โ Amazon RDS (MySQL, Oracle) โ โ โ Amazon RDS (Postgres) โ โ โ Amazon Simple Notification Service (SNS) โ โ โ Amazon Simple Queue Service (SQS) โ โ โ Amazon Simple Storage Service (S3) โ โ โ โ Amazon Simple Workflow Service (SWF) โ โ โ Amazon Virtual Private Cloud (VPC) โ โ โ โ Auto Scaling โ โ โ โ AWS CloudFormation โ โ โ AWS CloudTrail โ โ โ AWS Identity & Access Management (IAM) โ โ โ โ AWS Key Management Service โ โ โ โ Elastic Load Balancing โ โ โ โ -
HIPAA BAA
-
IRAP
SERVICES / PROGRAMS IRAP Amazon Elastic Block Store (EBS) โ Amazon Elastic Compute Cloud (EC2) โ Amazon Simple Storage Service (S3) โ Amazon Virtual Private Cloud (VPC) โ AWS Identity and Access Management (IAM) โ -
MTCS
SERVICES / PROGRAMS MTCS Amazon API Gateway โ Amazon CloudFront โ Amazon DynamoDB โ Amazon ElastiCache โ Amazon Elastic Block Store (EBS) โ Amazon Elastic Compute Cloud (EC2) โ Amazon EC2 Container Service (ECS) โ Amazon Elastic MapReduce โ Amazon Glacier โ Amazon Redshift โ Amazon RDS (MySQL, Oracle) โ Amazon RDS (Postgres) โ Amazon RDS (SQL Server) โ Amazon Route 53 โ Amazon SimpleDB โ Amazon Simple Storage Service (S3) โ Amazon Simple Queue Service (SQS) โ Amazon Simple Workflow Service (SWF) โ Amazon Virtual Private Cloud (VPC) โ Amazon WorkDocs โ Amazon WorkSpaces โ AWS CloudFormation โ AWS CloudHSM โ AWS CloudTrail โ AWS Config โ AWS Database Migration Service โ AWS Direct Connect โ AWS Directory Service โ AWS Elastic Beanstalk โ AWS Identity & Access Management (IAM) โ AWS Key Management Service โ AWS Lambda โ AWS Storage Gateway โ AWS WAF โ Elastic Load Balancing โ VM Import/Export โ -
C5

