What is cloud compliance?
Cloud compliance means your cloud environment meets a standard someone holds you to, and you can prove it with records. The standard usually comes from a customer, sometimes from a law.
Cloud compliance is the part of a compliance program that lives in your AWS, Azure or Google Cloud accounts: the access, logging, encryption, network, backup and change controls a standard requires, configured in the cloud and producing evidence. For a Canadian software company the standard is usually SOC 2 or ISO 27001, asked for by a customer, sitting alongside privacy duties under PIPEDA or Quebec's Law 25.
Which standards apply to a cloud environment?
| Standard or law | Who asks | Cloud focus |
|---|---|---|
| SOC 2 | North American enterprise customers | Access, monitoring, change management; see AWS, Azure, Google Cloud |
| ISO 27001:2022 | European, UK and global customers | Annex A technical controls and control 5.23; see ISO 27001 in the cloud |
| PCI DSS v4.0.1 | Card brands through your acquirer | Cardholder data environment; see PCI DSS in the cloud |
| PIPEDA | The law, for commercial personal information | Safeguards, accountability for processors |
| Quebec Law 25 | The law, for Quebec residents' information | Transfers outside Quebec; see Law 25 transfers |
| PHIPA and provincial health laws | Health custodians | Audit logs, residency; see health data |
| CIS Benchmarks | Some customers and insurers | Configuration baselines per provider |
Is cloud compliance the same as cloud security?
No. Security is whether the environment is protected. Compliance is whether it meets a defined standard and can prove it. A well-secured account with no logs retained fails an audit. An account that passes can still have risks the standard never asked about. Cloud security against cloud compliance covers the difference in more detail.
What does an auditor check in the cloud?
- Who can access production, how they sign in, and whether that list is reviewed.
- Whether administrative activity is logged, kept and watched.
- Whether data is encrypted and where it is stored.
- Whether changes are reviewed before they reach production.
- Whether backups exist and have been restored.
- Whether vulnerabilities are found and fixed on a schedule.
The provider's own certifications cover the data centre. Everything on this list is yours. The shared responsibility model explains the split.
Where to start
- Ask the customer which standard, which report type and by when.
- Check your account structure. Production separated from everything else is the foundation.
- Turn on logging with long retention, today. It cannot be backdated.
- Run the readiness score to see how far you are.
- Follow the cloud compliance roadmap.
Is AWS, Azure or Google Cloud compliant with PIPEDA?
The providers offer services and contract terms that let customers meet PIPEDA's safeguarding and accountability principles, and they host in Canada. PIPEDA compliance itself is your obligation as the organization collecting the information.
Who is responsible for cloud compliance in a small company?
Usually a CTO or senior platform engineer for the technical controls, with a founder or operations lead owning policies, people processes and the audit relationship. A fractional CISO or consultant often runs the program at first. HireACISO covers when a vCISO makes sense.
Starting a cloud compliance project?
Get quotes from firms that do the work on AWS, Azure and Google Cloud.
Get matched