Amazon Web Services (AWS) is pleased to announce that the Fall 2025 System and Organization Controls (SOC) 1, 2, and 3 reports are now available. The reports cover 185 services over the 12-month period from October 1, 2024–September 30, 2025, giving customers a full year of assurance. These reports demonstrate our continuous commitment to adhering to the heightened expectations of cloud service providers.
Customers can download the Fall 2025 SOC 1 and 2 reports through AWS Artifact, a self-service portal for on-demand access to AWS compliance reports. Sign in to AWS Artifact in the AWS Management Console, or learn more at Getting Started with AWS Artifact. The SOC 3 report can be found on the AWS SOC Compliance Page.
AWS strives to continuously bring services into the scope of its compliance programs to help customers meet their architectural and regulatory needs. You can view the current list of services in scope on our Services in Scope page. As an AWS customer, you can reach out to your AWS account team if you have any questions or feedback about SOC compliance.
To learn more about AWS compliance and security programs, see AWS Compliance Programs. As always, we value feedback and questions; reach out to the AWS Compliance team through the Contact Us page.
If you have feedback about this post, submit comments in the Comments section below.
In late March of 2026, Google announced a 2029 timeline for their post-quantum cryptography (PQC) migration. That announcement also mentions a change in priorities. PQC…
Wiz has certified its commercial platform in the Spanish National Cryptologic Center (CCN) ICT Security Products and Services Catalog (CPSTIC). Inclusion in this catalogue enables…
Table of Contents From Theoretical CVE to Validated Attack Path: Exposing Exploitable Risk End the Guesswork: Full Traceability with the Code-to-Cloud Pipeline One-Click Remediation: From…
Table of Contents What are system prompt leaks? The problem: System prompt leakage can’t be fully remediated Designing system prompts for the inevitable Implementing mitigation…