SOC
System and Organization Controls — audit reports on a provider's security controls.
System and Organization Controls (SOC) reports are independent third-party audits of a cloud provider’s internal controls. SOC 1 addresses controls relevant to financial reporting, while SOC 2 covers the trust services criteria: security, availability, processing integrity, confidentiality, and privacy. AWS maintains SOC 1, 2, and 3 reports across in-scope services, including AI services like Amazon Bedrock and SageMaker. The key exam distinction: SOC 2 is a restricted, detailed report requiring an NDA, whereas SOC 3 is a publicly shareable summary of the same audit. Customers download these on demand through AWS Artifact at no cost.
PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →