CloudCompliance

AWS compliance for Canadian companies

AWS carries its own SOC 2 and ISO 27001 reports for the infrastructure. Everything inside your accounts, from who can sign in to whether CloudTrail is on, is yours to configure and yours to prove.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

To pass an audit on AWS you need five things in place: production in its own account under AWS Organizations, human access through IAM Identity Center with MFA rather than IAM users, an organization-wide CloudTrail trail stored in a separate logging account, encryption with KMS on every data store, and AWS Config recording configuration history. With those, most of the cloud controls in SOC 2 or ISO 27001 produce evidence on their own. Without them, the project starts with rework.

What AWS covers and what you cover

AWS publishes SOC 1, SOC 2 and SOC 3 reports, ISO 27001, 27017 and 27018 certificates and a PCI DSS attestation for its services. You download them from AWS Artifact in the console. Your auditor will treat AWS as a subservice organization, usually with the carve-out method, and rely on that report for the physical data centres, hardware and the internals of managed services.

AWS calls its side "security of the cloud" and yours "security in the cloud". The shared responsibility page goes through where that line moves between EC2, RDS, Lambda and S3. The short version: the more managed the service, the less you configure, but access, data classification and encryption choices are always yours.

Read the complementary controls

The AWS SOC 2 report lists complementary user entity controls: things AWS assumes you do. Your auditor may ask how you meet them. They are mostly access management and data protection duties you would have anyway, but read the list before fieldwork.

Canadian regions on AWS

AWS regions in Canada
RegionCodeLocationNotes
Canada (Central)ca-central-1Montreal areaThe default Canadian region, widest service catalogue
Canada West (Calgary)ca-west-1CalgaryOpened December 2023. Fewer services, useful for in-country disaster recovery

Some AWS services are global and process data outside the region you pick: IAM, CloudFront, Route 53 and parts of the support tooling. That rarely matters for personal information, but it belongs in your data flow diagram. The Canadian regions guide compares all three providers, and data residency covers when the region is a legal question rather than a preference.

The controls auditors test on AWS

Common SOC 2 and ISO 27001 controls on AWS, and their evidence
ControlAWS implementationEvidence the auditor accepts
Unique identities, MFAIAM Identity Center federated to your identity provider, MFA enforced thereIdentity Center user list, IdP MFA policy export
No shared or root useRoot MFA, no root access keys, root use alertedIAM credential report, CloudTrail root activity query
Least privilegePermission sets per role, SCPs as guardrailsPermission set definitions, quarterly access review sign-off
Audit loggingOrganization trail to a log archive account, log file validation onTrail configuration, S3 bucket policy, sample log extract
Encryption at restKMS on S3, EBS, RDS, DynamoDB; default encryption enforcedConfig rule results, KMS key policy
Encryption in transitTLS 1.2 or higher on load balancers and APIsListener policies, Config rule results
Configuration monitoringAWS Config recorder, Security Hub standardsCompliance history, findings with resolution dates
BackupsAWS Backup plans, vault lock for critical dataBackup plan, job history, a dated restore test
Change managementInfrastructure as code, pull request approval, pipeline deploys onlyPR history for sampled changes, pipeline role permissions
Vulnerability managementAmazon Inspector on EC2, ECR and LambdaFinding history, remediation within your stated SLA
Threat detectionGuardDuty across the organizationEnabled status, alert routing, sample triaged finding

The detailed SOC 2 walk-through, criterion by criterion, is on SOC 2 on AWS. For ISO 27001, the same controls map to Annex A, and ISO 27001 in the cloud covers the cloud-specific control 5.23 and the ISO 27017 extension.

Native evidence tooling

AWS Config records resource configuration and evaluates it against rules and conformance packs. Security Hub aggregates findings and scores the account against the AWS Foundational Security Best Practices, CIS Benchmarks and other standards. Audit Manager maps collected evidence to prebuilt frameworks, including SOC 2. The guide to all three says what each produces and which you can skip.

If you would rather have evidence mapped to controls in one place, the free traztech Workspace runs daily checks against AWS and files the results against the control they prove. Paid platforms do the same with more integrations; the platform comparison covers when that breadth is worth paying for.

Account structure

An auditor will ask how production is separated from development and who can reach it. On AWS the answer that passes cleanly is separate accounts under AWS Organizations, with SCPs that stop anyone disabling CloudTrail, leaving the approved regions or creating IAM users. Control Tower builds that structure for you; the landing zone guide covers Control Tower against a hand-built setup, and account structure for audits covers what to put where.

Where AWS accounts fail audits

  • IAM users with long-lived access keys for people, including departed staff.
  • CloudTrail on in one region only, or stored in the same account an admin could wipe.
  • Production and staging in one account, so everyone with staging access has production.
  • S3 buckets public or unencrypted from before default encryption existed.
  • Security Hub switched on, findings never triaged, so the evidence shows a control that did not operate.

The common findings page covers these across all three providers, with the fix for each.

Is AWS SOC 2 compliant?

AWS holds SOC 1, SOC 2 and SOC 3 reports covering its infrastructure and services, downloadable from AWS Artifact. That does not make your product SOC 2 compliant. Your auditor relies on the AWS report for the physical layer and then tests your own configuration and processes.

Do I need Control Tower for SOC 2?

No. You need separate production accounts, centralized logging and guardrails. Control Tower is the quickest way to get them. A small team with two or three accounts can build the same structure with AWS Organizations and a handful of SCPs.

Should we use ca-central-1 or ca-west-1?

Use ca-central-1 as the primary region because it offers the widest set of services. Use ca-west-1 for backups or disaster recovery if you need both copies to stay in Canada.

Is AWS Audit Manager enough to pass SOC 2?

No. Audit Manager collects configuration evidence from AWS and maps it to a SOC 2 framework, but most SOC 2 controls are about people and process: onboarding, access reviews, vendor management, risk assessment, incident response. Those need evidence from outside AWS.

If you want someone to look at the account before an auditor does, TrazTech runs an AWS security review, and other firms that do this work are in the directory.

Get quotes for AWS compliance work

Account hardening, SOC 2 readiness, or a configuration review before the audit.

Get matched