SOC 2 · AWS
Published
SOC 2 rarely starts as your idea. It arrives from outside: an enterprise prospect’s security review, a US customer’s procurement gate, a due diligence checklist ahead of a funding round. For UK software businesses on AWS it has become the second framework alongside ISO 27001, and the one where the difference between looking compliant and operating compliantly is written into the report itself.
A report, not a certificate
SOC 2 is an attestation defined by the AICPA, the US accountancy body, and delivered by a licensed CPA firm. There is no certificate and no badge; the deliverable is a report, and your customers will read it. The report assesses your controls against the Trust Services Criteria: security is mandatory, and availability, confidentiality, processing integrity and privacy are added as your customer commitments require. Most SaaS platforms scope security, availability and confidentiality.
The distinction that matters commercially is Type I versus Type II. Type I says your controls were suitably designed on a given day. Type II says they operated effectively across an observation window, typically six to twelve months. Sophisticated buyers ask for Type II, and increasingly specify a minimum window.
What AWS’s own SOC reports settle
AWS publishes SOC 1, 2 and 3 reports for its infrastructure, available through AWS Artifact, and your auditor will rely on them for the layers AWS operates: physical security, the hypervisor, the underlying network. AWS is treated as a subservice organisation, normally under the carve-out method, meaning its controls sit outside your report but your reliance on them is documented.
What that does not do is shrink your side of the shared responsibility model. The AWS SOC 2 report contains a list of complementary user entity controls: things AWS explicitly expects its customers to do, from configuring access control to encrypting data and monitoring their own workloads. Your auditor has read that list and will check you against it.
Mapping the criteria to an AWS estate
The common criteria translate onto AWS services directly, and most of the evidence can be generated as a by-product of running the estate well:
- Logical access (CC6). IAM and IAM Identity Center for least privilege, multi-factor authentication, and joiner-mover-leaver records. Access reviews need to exist as records, not as a policy that claims they happen.
- System operations (CC7). CloudTrail, GuardDuty and Security Hub for monitoring and anomaly detection, with triage records showing alerts were investigated. Incident response needs at least one exercised, documented run.
- Change management (CC8). Infrastructure as code with review and approval in the pipeline, and AWS Config to catch changes made around it. The unreviewed console change is the classic Type II exception.
- Availability. Multi-AZ design, AWS Backup with tested restores, and capacity monitoring. A backup that has never been restored is a hope, not a control.
- Confidentiality. KMS for encryption and key lifecycle, data classification, and retention and disposal that provably happen.
The observation window is the audit
The property that makes SOC 2 different from every point-in-time assessment is that a Type II report grades the whole window. The auditor samples across the period: access reviews from March, change records from June, alert triage from September. A month where logging was off, or a quarter of skipped reviews, does not get fixed before the audit; it becomes an exception, printed in the report your customers read.
That makes SOC 2 structurally hostile to the scramble-before-the-audit model that annual frameworks tolerate. The estate either operates its controls continuously, or the report says so. This is the model Cloudreason’s cloud compliance service is built for: continuous monitoring against your control set, remediation carried out by our engineers, and evidence accumulating throughout the window rather than reconstructed at the end of it. If a customer has just asked for your SOC 2 report and you do not have one, talk to us about the fastest honest route to a clean Type II.