AWS Security Blog
New whitepaper available: AICPA SOC 2 Compliance Guide on AWS
We’re excited to announce the release of our latest whitepaper, AICPA SOC 2 Compliance Guide on AWS, which provides in-depth guidance on implementing and maintaining SOC 2-aligned controls using AWS services.
Building and operating cloud-native services in alignment with the AICPA’s Trust Services Criteria requires thoughtful planning and robust implementation. This new whitepaper helps cloud architects, security and compliance teams, and DevOps professionals design environments that meet SOC 2 requirements while leveraging AWS’s shared responsibility model.
What’s inside the whitepaper:
- Overview of the SOC 2 framework—including Common Criteria (CC 1–CC 9) and category-specific criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy)
- Mapping of each Trust Services Criterion to AWS services and constructs
- Guidance on implementing complementary user entity controls (CUECs)
- Strategies for evidence collection, documentation, and audit procedures
- Risk and governance for executives
- Best practices for automating compliance and preparing for SOC 2 readiness assessments
Download AICPA SOC 2 Compliance Guide on AWS.
For further assistance, contact AWS Security Assurance Services.
If you have feedback about this post, submit comments in the Comments section below.