AWS compliance for Canadian companies
AWS carries its own SOC 2 and ISO 27001 reports for the infrastructure. Everything inside your accounts, from who can sign in to whether CloudTrail is on, is yours to configure and yours to prove.
To pass an audit on AWS you need five things in place: production in its own account under AWS Organizations, human access through IAM Identity Center with MFA rather than IAM users, an organization-wide CloudTrail trail stored in a separate logging account, encryption with KMS on every data store, and AWS Config recording configuration history. With those, most of the cloud controls in SOC 2 or ISO 27001 produce evidence on their own. Without them, the project starts with rework.
What AWS covers and what you cover
AWS publishes SOC 1, SOC 2 and SOC 3 reports, ISO 27001, 27017 and 27018 certificates and a PCI DSS attestation for its services. You download them from AWS Artifact in the console. Your auditor will treat AWS as a subservice organization, usually with the carve-out method, and rely on that report for the physical data centres, hardware and the internals of managed services.
AWS calls its side "security of the cloud" and yours "security in the cloud". The shared responsibility page goes through where that line moves between EC2, RDS, Lambda and S3. The short version: the more managed the service, the less you configure, but access, data classification and encryption choices are always yours.
Read the complementary controls
The AWS SOC 2 report lists complementary user entity controls: things AWS assumes you do. Your auditor may ask how you meet them. They are mostly access management and data protection duties you would have anyway, but read the list before fieldwork.
Canadian regions on AWS
| Region | Code | Location | Notes |
|---|---|---|---|
| Canada (Central) | ca-central-1 | Montreal area | The default Canadian region, widest service catalogue |
| Canada West (Calgary) | ca-west-1 | Calgary | Opened December 2023. Fewer services, useful for in-country disaster recovery |
Some AWS services are global and process data outside the region you pick: IAM, CloudFront, Route 53 and parts of the support tooling. That rarely matters for personal information, but it belongs in your data flow diagram. The Canadian regions guide compares all three providers, and data residency covers when the region is a legal question rather than a preference.
The controls auditors test on AWS
| Control | AWS implementation | Evidence the auditor accepts |
|---|---|---|
| Unique identities, MFA | IAM Identity Center federated to your identity provider, MFA enforced there | Identity Center user list, IdP MFA policy export |
| No shared or root use | Root MFA, no root access keys, root use alerted | IAM credential report, CloudTrail root activity query |
| Least privilege | Permission sets per role, SCPs as guardrails | Permission set definitions, quarterly access review sign-off |
| Audit logging | Organization trail to a log archive account, log file validation on | Trail configuration, S3 bucket policy, sample log extract |
| Encryption at rest | KMS on S3, EBS, RDS, DynamoDB; default encryption enforced | Config rule results, KMS key policy |
| Encryption in transit | TLS 1.2 or higher on load balancers and APIs | Listener policies, Config rule results |
| Configuration monitoring | AWS Config recorder, Security Hub standards | Compliance history, findings with resolution dates |
| Backups | AWS Backup plans, vault lock for critical data | Backup plan, job history, a dated restore test |
| Change management | Infrastructure as code, pull request approval, pipeline deploys only | PR history for sampled changes, pipeline role permissions |
| Vulnerability management | Amazon Inspector on EC2, ECR and Lambda | Finding history, remediation within your stated SLA |
| Threat detection | GuardDuty across the organization | Enabled status, alert routing, sample triaged finding |
The detailed SOC 2 walk-through, criterion by criterion, is on SOC 2 on AWS. For ISO 27001, the same controls map to Annex A, and ISO 27001 in the cloud covers the cloud-specific control 5.23 and the ISO 27017 extension.
Native evidence tooling
AWS Config records resource configuration and evaluates it against rules and conformance packs. Security Hub aggregates findings and scores the account against the AWS Foundational Security Best Practices, CIS Benchmarks and other standards. Audit Manager maps collected evidence to prebuilt frameworks, including SOC 2. The guide to all three says what each produces and which you can skip.
If you would rather have evidence mapped to controls in one place, the free traztech Workspace runs daily checks against AWS and files the results against the control they prove. Paid platforms do the same with more integrations; the platform comparison covers when that breadth is worth paying for.
Account structure
An auditor will ask how production is separated from development and who can reach it. On AWS the answer that passes cleanly is separate accounts under AWS Organizations, with SCPs that stop anyone disabling CloudTrail, leaving the approved regions or creating IAM users. Control Tower builds that structure for you; the landing zone guide covers Control Tower against a hand-built setup, and account structure for audits covers what to put where.
Where AWS accounts fail audits
- IAM users with long-lived access keys for people, including departed staff.
- CloudTrail on in one region only, or stored in the same account an admin could wipe.
- Production and staging in one account, so everyone with staging access has production.
- S3 buckets public or unencrypted from before default encryption existed.
- Security Hub switched on, findings never triaged, so the evidence shows a control that did not operate.
The common findings page covers these across all three providers, with the fix for each.
Is AWS SOC 2 compliant?
AWS holds SOC 1, SOC 2 and SOC 3 reports covering its infrastructure and services, downloadable from AWS Artifact. That does not make your product SOC 2 compliant. Your auditor relies on the AWS report for the physical layer and then tests your own configuration and processes.
Do I need Control Tower for SOC 2?
No. You need separate production accounts, centralized logging and guardrails. Control Tower is the quickest way to get them. A small team with two or three accounts can build the same structure with AWS Organizations and a handful of SCPs.
Should we use ca-central-1 or ca-west-1?
Use ca-central-1 as the primary region because it offers the widest set of services. Use ca-west-1 for backups or disaster recovery if you need both copies to stay in Canada.
Is AWS Audit Manager enough to pass SOC 2?
No. Audit Manager collects configuration evidence from AWS and maps it to a SOC 2 framework, but most SOC 2 controls are about people and process: onboarding, access reviews, vendor management, risk assessment, incident response. Those need evidence from outside AWS.
If you want someone to look at the account before an auditor does, TrazTech runs an AWS security review, and other firms that do this work are in the directory.
Get quotes for AWS compliance work
Account hardening, SOC 2 readiness, or a configuration review before the audit.
Get matched