ISO 27001 · AWS
ISO 27001 on AWS: mapping the controls to your estate
How ISO 27001 Annex A controls map to AWS services, what you inherit from AWS and what remains yours, and how to keep evidence current between audits.
Read the guide →The certificate is dated the day the auditor leaves, and the estate starts drifting the same afternoon. Accounts appear, permissions widen, logging gets disabled during an incident and never re-enabled. A year later the scramble begins again, against an estate that no longer resembles the one that passed.
Tooling has not solved this, because tooling produces findings and findings are not fixes. Every security team we meet has a dashboard of flagged issues; far fewer have someone whose job is to make the list shorter. Compliance runs on dates, and the date does not care how good the dashboard looked.
Talk to us when
A certification or renewal date is approaching and the estate has drifted since the last one
An audit came back failed or qualified, and the findings list is longer than anyone can own
A customer security questionnaire is holding up a contract you need signed
A public sector bid requires evidence against frameworks you have never had to prove before
A post-incident review exposed the gap between your documented controls and your running estate
New regulatory scope has arrived and nobody is sure what it means for the cloud
The service, in practice
Continuous monitoring of your estate against the frameworks you certify to
Findings triaged by real risk to your organisation, not by raw scanner severity
Remediation carried out by our engineers, not filed as a recommendation
Evidence collected as you go, so the audit reviews records you already hold
A monthly review of posture and findings, and a quarterly report written for auditors and boards
We monitor your estate against the frameworks you certify to, all year. Findings are triaged by what they actually put at risk, remediated by our engineers, and closed with the evidence attached. By the time the audit date arrives, the assessment is a review of records you already hold.
You see the position every month and receive a quarterly report written to be handed straight to an auditor, a board or a customer's security team. If you hold a date for a renewal, an assessment or a procurement, everything we do is worked back from that date.
It is the same operating model as our Managed FinOps service, applied to controls instead of cost.
Compliance tooling is excellent at producing findings and structurally incapable of resolving them. Our engineers make the change, test it and close the finding. The gap between "flagged" and "fixed" is the service.
We take no commission from any vendor and we are not an audit practice, so we have no licence to sell you and no audit to protect. Our only incentive is an estate that passes because it deserves to.
Cloudreason manages live cloud estates for clients every day, so we know what breaks when a control is applied carelessly. Compliance advice from people who also carry a pager reads differently from advice out of a spreadsheet.
ISO 27001, Cyber Essentials Plus, the NCSC Cloud Security Principles, PCI DSS, SOC 2 and, where relevant, the NHS Data Security and Protection Toolkit. We publish practical guides on applying each framework to a cloud estate.
ISO 27001 · AWS
How ISO 27001 Annex A controls map to AWS services, what you inherit from AWS and what remains yours, and how to keep evidence current between audits.
Read the guide →NCSC Cloud Security Principles · AWS + Azure + Google Cloud
What the 14 NCSC Cloud Security Principles ask of a cloud estate, why principle 14 is where estates fail, and how to evidence them for public sector work.
Read the guide →Cyber Essentials Plus · AWS + Azure + Google Cloud
Cloud services are in scope for Cyber Essentials Plus. What the five controls mean for AWS, Azure and SaaS estates, and how to pass the audited assessment.
Read the guide →PCI DSS · AWS
Running PCI DSS v4 on AWS: what you inherit from a Level 1 provider, how to shrink the cardholder data environment, and how to hold compliance all year.
Read the guide →SOC 2 · AWS
What SOC 2 asks of an AWS estate: the Trust Services Criteria, what a Type II observation window means, and how to keep evidence audit-ready all year.
Read the guide →NHS DSPT · AWS + Azure
What the NHS Data Security and Protection Toolkit asks of a cloud estate, how the CAF-aligned version changes it, and how suppliers evidence it each June.
Read the guide →Certifying against a framework not listed here? The same continuous approach applies. Ask us.
Cloudreason runs production cloud infrastructure in payments, the public sector and social housing: sectors where a control failure is a regulatory event, not an inconvenience. The same engineers, and the same continuous discipline, deliver this service.
Read the case studies →Fixed scope, fixed price, mirroring our Cloud Cost Health Check. We assess your estate against the framework you care about, tell you exactly where you would fail today, and hand you a prioritised remediation plan worked back from your audit date. Run it yourselves, or ask us to. The findings are yours either way.
Book a Compliance Health Check →ISO 27001, Cyber Essentials Plus, the NCSC Cloud Security Principles, PCI DSS, SOC 2 and, where relevant, the NHS Data Security and Protection Toolkit, across AWS, Microsoft Azure and Google Cloud estates.
No, and that is deliberate. We are independent of audit and certification bodies as well as vendors, so we have no audit to protect and no licence to sell. Our job is to make your estate and its evidence so well prepared that the assessment itself becomes a formality.
Tooling flags findings; it cannot fix them, and in most organisations nobody owns making the list shorter. Our engineers remediate findings, test the fixes and close them with evidence attached, and we triage by what actually puts your organisation at risk rather than by raw scanner severity.
No, but start now. We work backwards from the date: assess where you would fail today, fix the findings that matter in the time available, and arrive with the evidence organised. The earlier we start, the calmer that process is.
No, we extend it. Your team keeps ownership and context; we carry the continuous monitoring, remediation and evidence load that annual-cycle compliance programmes never have capacity for.
Tell us the date and the framework, and we'll tell you honestly what stands between your estate and passing.