Compare Cloud Costs
Compare Cloud Costs

Compliance & Regulations

Compare security, privacy, and compliance standards across cloud providers, databases, and AI vendors. Filter to verify certifications and reach official trust centers. Curious where these providers actually run? Explore Datacenters for each cloud's global footprint, or track their newest features on the Announcements page. Want to check data freshness? See the platform Status. Last updated: Sep 1, 2026.

Tracked certifications by provider

Counts reflect the 24 standards tracked here — not each provider's full catalog. See the trust centers below for the complete list.

Select one or multiple options above to filter certifications, providers, and compliance standards.

Showing 24 of 24 tracked standards
SecurityGlobal

ISO/IEC 27001

International standard for information security management systems (ISMS).

AWSAzureGoogleOracleIBM CloudAlibabaCloudflareDigitalOceanAivenOpenAIAnthropicPineconeMilvus / ZillizWeaviateCoreWeaveLambda Labs
Learn more
SecurityGlobal

ISO/IEC 27017

Code of practice for information security controls for cloud services.

AWSAzureGoogleOracleIBM CloudAlibabaAivenOpenAI
Learn more
SecurityGlobal

SOC 1

AICPA audit of controls relevant to financial reporting.

AWSAzureGoogleOracleIBM CloudAlibabaCoreWeave
Learn more
SecurityGlobal

SOC 2

AICPA audit of controls for security, availability, processing integrity, confidentiality and privacy.

AWSAzureGoogleOracleIBM CloudAlibabaCloudflareDigitalOceanAivenOpenAIAnthropicMistralCoherePineconeMilvus / ZillizQdrantWeaviateChromaCoreWeaveLambda Labs
Learn more
SecurityGlobal

SOC 3

Publicly shareable, general-use version of the SOC 2 report.

AWSAzureGoogleOracleIBM CloudAlibabaDigitalOceanAiven
Learn more
SecurityGlobal

CSA STAR

Cloud Security Alliance Security Trust Assurance and Risk registry.

AWSAzureGoogleOracleIBM CloudAlibabaDigitalOceanOpenAICoreWeave
Learn more
SecurityNorth America

FIPS 140-3

US/Canadian government standard for cryptographic module validation (successor to FIPS 140-2, which the CMVP retires to historical status on Sept 21, 2026).

AWSAzureGoogleOracleIBM Cloud
Learn more
SecurityGlobal

ISO 22301

International standard for business continuity management systems.

AWSAzureGoogleIBM CloudAlibaba
Learn more
SecurityGlobal

ISO/IEC 20000-1

International standard for IT service management (ITSM).

AWSAzureOracleIBM CloudAlibaba
Learn more
SecurityGlobal

ISO/IEC 42001

First international standard for AI management systems (AIMS).

AWSAzureGoogleOracleIBM CloudOpenAIAnthropic
Learn more
PrivacyGlobal

ISO/IEC 27018

Code of practice for protecting personally identifiable information (PII) in public clouds.

AWSAzureGoogleOracleIBM CloudAlibabaCloudflareAivenOpenAI
Learn more
PrivacyEurope

GDPR

EU General Data Protection Regulation for personal data.

AWSAzureGoogleOracleIBM CloudAlibabaCloudflareDigitalOceanAivenOpenAIAnthropicDeepSeekMistralGrokKimiCoherePineconeMilvus / ZillizQdrantWeaviateChromaCoreWeaveLambda Labs
Learn more
PrivacyGlobal

ISO/IEC 27701

Privacy information management system (PIMS) extension to ISO 27001.

AWSAzureGoogleOracleIBM CloudAlibabaCloudflareOpenAI
Learn more
IndustryGlobal

PCI DSS

Payment Card Industry Data Security Standard for handling cardholder data.

AWSAzureGoogleOracleIBM CloudAlibabaCloudflareDigitalOceanAivenOpenAI
Learn more
IndustryNorth America

HIPAA

US healthcare law governing protected health information (via a Business Associate Agreement).

AWSAzureGoogleOracleIBM CloudAlibabaCloudflareAivenOpenAIAnthropicCoherePineconeMilvus / ZillizQdrantWeaviateChromaCoreWeaveLambda Labs
Learn more
IndustryNorth America

HITRUST CSF

Certifiable security framework widely used in US healthcare.

AWSAzureGoogleIBM Cloud
Learn more
GovernmentNorth America

FedRAMP High

US government authorization for high-impact cloud workloads.

AWSAzureGoogleOracleIBM Cloud
Learn more
GovernmentNorth America

FedRAMP Moderate

US government authorization for moderate-impact cloud workloads.

AWSAzureGoogleOracleIBM Cloud
Learn more
GovernmentAsia Pacific

IRAP

Australian Government Information Security Registered Assessors Program.

AWSAzureGoogleOracleIBM Cloud
Learn more
GovernmentEurope

BSI C5

Germany’s Cloud Computing Compliance Criteria Catalogue (BSI).

AWSAzureGoogleOracleIBM CloudAlibaba
Learn more
GovernmentEurope

ENS

Spain’s Esquema Nacional de Seguridad (National Security Framework).

AWSAzureGoogleIBM Cloud
Learn more
GovernmentAsia Pacific

MTCS

Singapore’s Multi-Tier Cloud Security standard (SS 584).

AWSAzureGoogleIBM CloudAlibaba
Learn more
GovernmentNorth America

NIST SP 800-171

US standard for protecting controlled unclassified information (CUI).

AWSAzureGoogleOracleIBM Cloud
Learn more
GovernmentAsia Pacific

ISMAP

Japan’s government Information system Security Management and Assessment Program.

AWSAzureGoogleOracleIBM Cloud
Learn more

Sources

The links below go to each provider's official trust center, the authoritative certification list (100+ for the largest clouds; AWS alone advertises 140+). We track a curated, comparable subset above. This is not legal or compliance advice; verify directly with the provider.

Last verified: August 2026. Re-verified roughly every six months.

Disclaimer: This compliance matrix is curated for comparison and reflects each provider's publicly documented status as of the last verification date. It is not legal or compliance advice; check each provider's trust center and legal agreements for authoritative audits. Visit our Terms of Use for data coverage details.