RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The archive · 200 retrospective records ↗

The archive / Compliance & obligations

Compliance & obligations / Operating entry · Entry note · prepared 16 September 2026

AWS Artifact hands over paperwork, not AWS's compliance

AWS's own documentation says Artifact gives free, on-demand access to AWS's audit reports, while leaving a customer's own compliance documents to them.

docs.aws.amazon.comprimary record

What Is AWS Artifact?

Document
undated document
Event
no single event
Retrieved
16 September 2026
No visual was published with this record, so its primary document stands in its place.

The workload

A founder assembling a customer's security questionnaire no longer has to email an AWS account rep for evidence; AWS's own Artifact documentation states, verified, that Artifact 'provides on-demand downloads of AWS security and compliance documents,' naming ISO standard reports, PCI Security Standards Council reports, and SOC reports specifically. The Artifact product page adds, verified, that the same self-service portal lets a customer 'accept, terminate, and download compliance agreements' for their account, some of which require agreeing to terms before the download proceeds. The workload this replaces is real but narrow: pulling AWS's own third-party attestations into a compliance packet, not producing new evidence about the founder's own application.

What the documents show

The documentation states plainly, verified and quoted directly: 'AWS customers are responsible for developing or obtaining documents that demonstrate the security and compliance of their companies,' immediately beside a link to AWS's own Shared Responsibility Model. That sentence is the entire answer to whether hosting on AWS means inheriting AWS's SOC 2 status — it does not. Artifact supplies evidence about AWS's infrastructure and services; it says nothing about how the founder configured access controls, wrote code, or handled incident response inside their own application, which is the layer a customer's own auditor still has to examine.

The operating cost

Verified, and stated directly: 'AWS provides AWS Artifact documents and agreements to you free of charge.' The documents themselves cost nothing to download. What is not free, and not priced anywhere in AWS's own Artifact pages, is the labor of turning those downloaded reports into a customer-facing compliance packet, or of commissioning the founder's own separate SOC 2 or CAIQ response — finding that cost requires a quote from a CPA firm or a compliance-automation vendor, two of which appear elsewhere in this batch.

The stop condition

Reusing AWS's attestations only covers the infrastructure layer AWS itself operates. The moment an auditor or enterprise buyer's questionnaire asks about the founder's own access management, code review process, or incident response — anything above the line AWS's shared-responsibility documentation draws — Artifact's downloads stop being sufficient on their own, an editorial extension of the verified shared-responsibility statement rather than a specific claim the documentation states in those words.

  • Which specific report does a customer's questionnaire actually require — an AWS SOC 2, an AWS ISO 27001 certificate, or something about the founder's own application — and does Artifact cover that layer at all?
  • Does the AWS account in question have the IAM permissions Artifact needs, and has anyone checked whether a given report requires accepting an NDA-style agreement before download?
  • Has 'we host on AWS, which is SOC 2 compliant' ever been said to a customer as if it answered a question about the founder's own controls?

Artifact is a distribution mechanism for AWS's own paperwork, not a substitute for a founder's own audit trail. AWS's documentation draws that line itself, in the same paragraph that offers the free downloads.

Sources & reading trail

What Is AWS Artifact? ↗

States what document types Artifact provides (ISO, PCI, SOC reports), that it is free of charge, and that customers remain responsible for their own compliance documents under the Shared Responsibility Model.

Source published: Not established · Retrieved: 16 September 2026

AWS Artifact ↗

States Artifact is a self-service portal for auditor-issued reports and compliance agreements, including for ISV products sold on AWS Marketplace.

Source published: Not established · Retrieved: 16 September 2026

Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.