Multi-cloud compliance
Multi-cloud compliance is one control set with several evidence sources. The controls do not double. The evidence collection does, which is the cost to plan for.
Compliance across two or three clouds works when you write one control set, federate every cloud to one identity provider, send all audit logs to one place, and accept that configuration evidence comes from each provider's own tooling or from a cloud security posture management tool that reads them all. The auditor tests each control on each in-scope cloud, so a second cloud increases the samples, not the number of controls.
Why companies end up multi-cloud
- An acquisition brought a second provider.
- One team uses a Google Cloud data service while the product runs on AWS.
- A customer requires hosting on its preferred cloud.
- Microsoft 365 and Entra ID come with Azure services attached.
In most of these cases one cloud is primary. Keep the secondary cloud's footprint small and out of the audit scope if it holds no customer data.
What should be common across clouds
| Area | Approach |
|---|---|
| Identity | One identity provider federated to every cloud; one joiner and leaver process |
| Logging | All cloud audit logs routed to one SIEM or log platform with one retention setting |
| Infrastructure as code | Terraform or similar across providers, one review process |
| Policy | One written baseline, implemented per provider with SCPs, Azure Policy and organization policies |
| Findings | One queue and remediation targets for all providers |
When a CSPM earns its cost
With one cloud, native tools are enough. With two or more carrying production data, a cloud security posture management tool that reads every provider and reports in one format saves real time and gives one findings workflow. The CSPM comparison covers the options.
Scoping the audit
In the SOC 2 system description, name each provider as a subservice organization and say what runs where. Clouds that hold no customer data and cannot reach production can be out of scope. For ISO 27001, each provider goes in the control 5.23 record and the supplier list.
Is multi-cloud harder to audit?
It takes more evidence, because each control is tested on each cloud in scope. The control set is the same. Consistent identity, logging and infrastructure as code keep the extra work proportional.
Should we go multi-cloud for resilience?
Rarely, for a small company. Multi-region inside one provider gives most of the resilience at a fraction of the complexity and compliance cost.
Running more than one cloud?
Firms in the network design one control set across providers.
Get matched