CloudCompliance

Cloud pentesting rules by provider

None of the three major providers requires pre-approval to test your own resources on most services. All three prohibit denial of service testing and attacks on their shared infrastructure. The rest is scoping.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

You can penetration test your own AWS, Azure and Google Cloud resources without asking the provider first, within each provider's published rules. All three prohibit denial of service and stress testing without separate approval, attacks on other customers, and attempts against the provider's own infrastructure. Read the current policy before each test, because the permitted service lists change.

Cloud provider penetration testing policies, summary
ProviderPre-approval for standard testingProhibited without approvalWhere the rules are
AWSNot required for a listed set of servicesDoS and flooding, DNS zone walking against Route 53 hosted zones, protocol floodingAWS penetration testing policy page; separate simulated events form for DDoS and red team simulations
AzureNot requiredDoS testing, testing other tenants, phishing Microsoft staff, heavy automated fuzzing of shared servicesMicrosoft Cloud Penetration Testing Rules of Engagement
Google CloudNot requiredTesting that breaches the Acceptable Use Policy or terms, affects other customers, or targets Google's infrastructureGoogle Cloud acceptable use policy and terms of service

This is a summary of published policies as of September 2026, not legal advice, and the providers update them. Your testing firm should cite the current version in its rules of engagement.

What a cloud penetration test should cover

External application and API
Your internet-facing product. The core of most SOC 2 pentests.
Cloud configuration review
IAM paths to privilege escalation, exposed storage, overly permissive roles and network rules, reviewed with read-only access.
Assumed breach
Starting from a compromised workload or developer credential, how far can an attacker get? This is where cloud-specific findings live.
Container and Kubernetes
Cluster configuration, pod escape paths, service account permissions. See Kubernetes compliance.

A web application and API test for a typical SaaS product costs $8,000 to $18,000 CAD. A cloud configuration review adds $3,000 to $8,000 CAD. An assumed breach exercise is priced separately. GetPentest covers cloud penetration testing in more depth, including what a good report contains.

What auditors want from the pentest

  • A report dated within the audit period, or within twelve months.
  • A scope that covers the system in the audit.
  • Evidence that findings were fixed or accepted with a reason, ideally a retest letter.
  • A tester independent of the people who built the system.

SOC 2 does not require a penetration test by name, but almost every auditor and enterprise buyer expects one. PCI DSS v4.0.1 requirement 11.4 does require annual internal and external testing and segmentation testing.

Rules of engagement checklist

  1. List accounts, subscriptions or projects, and the specific resources in scope.
  2. Confirm each in-scope service is permitted under the provider's current policy.
  3. Exclude third-party SaaS you do not own unless that vendor has approved testing.
  4. Set testing windows, source IP addresses and emergency contacts.
  5. Decide whether to notify your own detection tooling or test whether it notices.
  6. Agree how credentials for authenticated and assumed breach testing are issued and revoked.
Do I need AWS permission to run a penetration test?

Not for the services on AWS's list of permitted services, which covers the common ones such as EC2, RDS, Lambda, API Gateway and CloudFront. You need approval for simulated events such as DDoS testing or large red team simulations, through AWS's simulated events form.

Can a pentester test Azure AD or Entra ID?

Testing the configuration of your own tenant, such as Conditional Access gaps or weak app registrations, is common and allowed within the rules of engagement. Brute-forcing or attacking the Entra ID service itself is not.

How often should a cloud-hosted SaaS company pentest?

At least annually, and after major changes such as a new product or an architecture move. Buyers and auditors expect a report no more than twelve months old.

Need a cloud penetration test?

Get quotes from firms that test cloud-hosted products.

Get matched