AWS Artifact — A service that provides on-demand access to AWS security and compliance documents and agreements.


Overview

AWS Artifact is your central repository for AWS compliance documentation — including audit reports, certifications, and agreements with AWS.

Key Insight: When your auditor asks “prove that AWS is compliant,” you use AWS Artifact to download the necessary documentation.


Core Artifact Concepts

ConceptDescriptionKey Point
Audit ReportsThird-party audit reports (SOC, ISO, PCI, etc.)Prove AWS compliance
AgreementsYour agreements with AWS (BAA, MSA)Legal documents
Artifact ReportsCustom compliance reportsYour-specific compliance
Artifact DocsSelf-service access to compliance docsNo need to contact support

Available Documents

Audit Reports

Report TypeDescription
SOC 1/2/3AICPA SOC reports
ISO 27001Information security certification
ISO 27017/27018Cloud security and privacy
PCI DSSPayment card industry compliance
FedRAMPUS federal government compliance
HIPAA BAABusiness Associate Agreement
CSA STARCloud security alliance

AWS Agreements

AgreementDescription
Business Associate Agreement (BAA)HIPAA compliance
Customer AgreementMaster service agreement
Service TermsTerms of service

How Artifact Works

flowchart LR
    Auditor["Auditor"]
    Regulator["Regulator"]
    Customer["Customer"]

    Need["Compliance evidence needed"]
    Portal["AWS Artifact"]

    Browse["Browse available reports and agreements"]
    Select["Select required document"]
    Download["Download PDF"]
    Share["Share with stakeholders"]

    Auditor --> Need
    Regulator --> Need
    Customer --> Need
    Need --> Portal --> Browse --> Select --> Download --> Share

Key Features

FeatureDescription
Self-ServiceAccess documents without contacting AWS support
Multi-AccountAggregates reports for all accounts in organization
SharingDirect sharing with auditors and regulators
Historical AccessAccess previous report versions (December 2025 enhancement)
Encrypted DownloadSecure document transfer

Use Cases

Use CaseDescription
Compliance AuditsProvide auditors with SOC, ISO, PCI reports
Regulatory RequirementsProve compliance to regulators
Customer Due DiligenceShare compliance with customers
Contractual RequirementsFulfill AWS agreement obligations
Risk AssessmentReview AWS security controls

Notable Updates

DateUpdateWhy It Matters
December 2025Previous Version AccessRetrieve older report versions directly in Artifact without opening a support case
2025Enhanced SharingSimpler workflows for sharing compliance documents with auditors and regulators

Pricing

AWS Artifact is a no-cost service. All compliance documents are available at no charge.


Artifact vs Audit Manager

AspectAWS ArtifactAWS Audit Manager
FocusAWS compliance documentsYour compliance evidence
ContentAWS reports, certificationsYour resource configurations
Use CaseProve AWS is compliantProve YOU are compliant
CostFreeVaries by support plan

Use Both: Artifact for AWS compliance; Audit Manager for your compliance.


TL;DR

  • AWS Artifact = Central repository for AWS compliance documentation
  • Contains = Audit reports (SOC, ISO, PCI), agreements (BAA), certifications
  • Use For = Compliance audits, regulatory requirements, customer due diligence
  • Self-Service = Download documents without contacting support
  • Pricing = Free
  • Recent Enhancement = Access previous report versions (Dec 2025)
  • Complementary = Use with Audit Manager (Artifact = AWS; Audit Manager = You)

Resources

AWS Artifact Documentation Complete Artifact user guide.

AWS Artifact Console Access compliance documents.

AWS Compliance Programs Overview of all AWS compliance certifications.