CloudCompliance

Kubernetes compliance on EKS, AKS and GKE

Managed Kubernetes moves the control plane to the provider. Access to the cluster, what runs in it, how pods talk to each other and how fast you upgrade are still yours, and auditors increasingly ask.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

A managed Kubernetes cluster passes a SOC 2 or ISO 27001 audit when cluster access goes through your cloud identity with RBAC mapped to groups, control plane audit logs are enabled and retained, images come from a scanned private registry, network policies restrict pod traffic, workloads run without privileged access, and the cluster stays on a supported version. The provider runs the control plane. You run everything above it.

Who is responsible for what

Managed Kubernetes responsibility split
ComponentEKSAKSGKE
Control plane availability and patchingAWSMicrosoftGoogle
Version upgradesYou triggerYou trigger or auto-upgrade channelsRelease channels, auto-upgrade by default
Worker nodesManaged node groups shared, Fargate by AWSNode pools shared, node OS auto-upgrade availableAutopilot by Google, Standard shared
RBAC, workloads, images, network policyYouYouYou

The controls auditors look at

Cluster access
EKS access entries or the aws-auth mapping to IAM roles; AKS with Entra ID integration and Azure RBAC; GKE with Google groups for RBAC. No shared kubeconfigs, no static tokens.
Audit logging
EKS control plane logging for audit and authenticator logs to CloudWatch, off by default; AKS diagnostic settings for kube-audit; GKE audit logs through Cloud Audit Logs.
Image provenance
Images from your own registry, scanned on push, with admission control rejecting unscanned or unsigned images.
Pod security
Pod Security Admission at the restricted or baseline level; no privileged containers or host mounts without a documented exception.
Network policy
Default deny between namespaces, explicit allows. Requires a network policy capable plugin.
Secrets
Envelope encryption of Kubernetes secrets with a KMS key, or secrets pulled from a cloud secret manager.
Upgrades
A supported Kubernetes version. Running a version past end of support is a vulnerability management finding.

Benchmarks

The CIS Kubernetes Benchmark and the provider-specific CIS benchmarks for EKS, AKS and GKE are the usual yardsticks. Defender for Containers, GKE security posture and third-party tools report against them. Treat them as a checklist, not a target score: an auditor wants the important items and a reason for each exception.

Is Kubernetes in scope for SOC 2?

If production workloads run on it, yes. The auditor will test access to the cluster, change management for deployments, logging and vulnerability management of the images, as part of CC6, CC7 and CC8.

Are EKS control plane logs on by default?

No. EKS control plane logging, including the audit log, must be enabled per cluster and sends logs to CloudWatch Logs, where you set retention.

Do we need a service mesh for compliance?

No. A mesh gives mutual TLS between services, which answers questions about encryption in transit inside the cluster. Network policies plus TLS at the edge and to databases satisfy most audits.

Running production on Kubernetes?

Firms in the network review clusters against CIS and prepare the evidence.

Get matched