CloudCompliance

Cloud compliance checklist

Forty items, grouped the way an auditor asks for them. Tick what is already true. What is left is your gap list, and the order within each group is the order to fix it.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Work through this list before the observation window opens. Each item names the control and the evidence that proves it. It applies to AWS, Azure and Google Cloud; the provider guides give the exact settings: AWS, Azure, Google Cloud. Your ticks are saved in this browser only.

0 of 40 done ·

Structure and scope

Getting this section right

Evidence that passes. An export of the account or subscription hierarchy, the dated architecture and data flow diagrams, and the policy that keeps workloads in approved regions. The diagram has to match what the console shows on the day the auditor looks.

Typical timing. One to two weeks to separate production from development if it is not already split; a day to export and date what exists.

Common mistakes. Customer data copied into staging to debug a ticket; a diagram drawn once for a sales deck and never updated; guardrails that exist in one account but not the others.

In Canada. If a contract or a public body customer requires Canadian residency, restrict regions to ca-central-1 and ca-west-1 on AWS, Canada Central and Canada East on Azure, or Montreal and Toronto on Google Cloud, and keep the policy as evidence.

Identity and access

Getting this section right

Evidence that passes. A dated access review with the reviewer's name, the MFA enforcement setting, and the list of people with administrative rights compared against the current staff list.

Typical timing. A first access review takes a day. Moving everyone to single sign-on with enforced MFA usually takes one to three weeks.

Common mistakes. Root or global administrator accounts used day to day; long-lived access keys on personal accounts; leavers removed from the identity provider but not from the cloud console.

In Canada. PIPEDA expects access to personal information to be limited to people who need it. An access review is the simplest way to show that, and it is the first thing a privacy investigation asks for.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Logging and monitoring

Getting this section right

Evidence that passes. Organization-wide logging switched on and protected from deletion, retention set to cover the audit period, and a record that alerts were reviewed and acted on.

Typical timing. Turning logging on takes an afternoon. It has to be running for the whole observation window, so it must start before the window does.

Common mistakes. Logging switched on in one region only; logs stored in an account the engineers can delete from; alerts that go to a channel nobody reads.

In Canada. Breach records under PIPEDA have to be kept for 24 months. Set log retention with that in mind, not just the audit period.

Data protection

Getting this section right

Evidence that passes. Encryption settings for every data store, the key policy showing who can use and administer keys, and a data inventory naming where personal information lives.

Typical timing. Most managed services encrypt by default, so this is often days of confirming and documenting rather than building.

Common mistakes. Assuming default encryption answers every question; one person holding sole administrative control of keys; no inventory of where personal information is stored.

In Canada. Quebec's Law 25 requires a privacy impact assessment before personal information leaves Quebec, which includes a move to a cloud region outside the province.

Resilience

Getting this section right

Evidence that passes. Backup configuration, the date of the last restore test with what was restored and how long it took, and a recovery plan that names an owner.

Typical timing. Setting up backups is quick; the first real restore test is a half day and usually finds something.

Common mistakes. Backups that have never been restored; backups kept in the same account as production; a recovery plan that names someone who has left.

In Canada. If you promised Canadian residency, check the backup and replica regions too. They are the usual place data quietly leaves the country.

Change and vulnerability management

Getting this section right

Evidence that passes. Pull requests with review and approval before merge, infrastructure changes made through code, and a vulnerability scan record with fix dates.

Typical timing. Branch protection takes an hour. A clean scanning history needs a few months of dated results before an audit.

Common mistakes. Engineers changing production in the console outside the pipeline; scan results with no record of what was fixed or when.

In Canada. Canadian enterprise buyers increasingly ask for an annual penetration test of the cloud environment. Book it before the audit window so the report is ready when they ask.

What to do next

Count the unticked items. Under ten, a few weeks of focused work. Ten to twenty-five, plan a readiness project; the roadmap gives the order. More than twenty-five, get help before the customer's deadline. The readiness score gives the same picture as a percentage per area.

Is this checklist enough to pass SOC 2?

It covers the cloud controls, which are roughly a third of a SOC 2 control set. Governance, risk assessment, HR, vendor management and incident response come from outside the cloud. SOC2Prep's checklist covers the full set.

Does it apply to ISO 27001 too?

Yes. The same items map to Annex A controls such as 5.15, 5.23, 8.5, 8.13, 8.15, 8.24 and 8.32. ISO 27001 adds the management system clauses on top.

Too many unticked boxes?

Firms in the network close cloud gaps before the audit.

Get matched