Compliance & Regulations
Compare security, privacy, and compliance standards across cloud providers, databases, and AI vendors. Filter to verify certifications and reach official trust centers. Curious where these providers actually run? Explore Datacenters for each cloud's global footprint.
Sponsor This Page
Sponsor this page. Your brand in front of engineers and architects comparing cloud pricing. See Advertising with us, or email [email protected].
Banner spec: 1200 × 200px (6:1 ratio) · PNG, JPG, or WebP. See the Docs for detailed instructions.
Tracked certifications by provider
Counts reflect the 24 standards tracked here — not each provider's full catalog. See the trust centers below for the complete list.Check any combination of providers, regions, or certification categories. Leaving a column unchecked means it isn't filtered. Hover a row and choose only to narrow to a single value.
ISO/IEC 27001
International standard for information security management systems (ISMS).
ISO/IEC 27017
Code of practice for information security controls for cloud services.
SOC 1
AICPA audit of controls relevant to financial reporting.
SOC 2
AICPA audit of controls for security, availability, processing integrity, confidentiality and privacy.
SOC 3
Publicly shareable, general-use version of the SOC 2 report.
CSA STAR
Cloud Security Alliance Security Trust Assurance and Risk registry.
FIPS 140-3
US/Canadian government standard for cryptographic module validation (successor to FIPS 140-2, which the CMVP retires to historical status on Sept 21, 2026).
ISO 22301
International standard for business continuity management systems.
ISO/IEC 20000-1
International standard for IT service management (ITSM).
ISO/IEC 42001
First international standard for AI management systems (AIMS).
ISO/IEC 27018
Code of practice for protecting personally identifiable information (PII) in public clouds.
GDPR
EU General Data Protection Regulation for personal data.
ISO/IEC 27701
Privacy information management system (PIMS) extension to ISO 27001.
PCI DSS
Payment Card Industry Data Security Standard for handling cardholder data.
HIPAA
US healthcare law governing protected health information (via a Business Associate Agreement).
HITRUST CSF
Certifiable security framework widely used in US healthcare.
FedRAMP High
US government authorization for high-impact cloud workloads.
FedRAMP Moderate
US government authorization for moderate-impact cloud workloads.
IRAP
Australian Government Information Security Registered Assessors Program.
BSI C5
Germany’s Cloud Computing Compliance Criteria Catalogue (BSI).
ENS
Spain’s Esquema Nacional de Seguridad (National Security Framework).
MTCS
Singapore’s Multi-Tier Cloud Security standard (SS 584).
NIST SP 800-171
US standard for protecting controlled unclassified information (CUI).
ISMAP
Japan’s government Information system Security Management and Assessment Program.
Sources
The links below go to each provider's official trust center, the authoritative certification list (100+ for the largest clouds; AWS alone advertises 140+). We track a curated, comparable subset above. This is not legal or compliance advice; verify directly with the provider.
Last verified: July 2026. Re-verified roughly every six months.