View a markdown version of this page

Compliance validation for Amazon Bedrock AgentCore - Amazon Bedrock AgentCore
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Compliance validation for Amazon Bedrock AgentCore

Amazon Bedrock AgentCore is HIPAA eligible and FedRAMP (Class C and Class D), SOC 2 and ISO (27001:2022, 27017:2015, 27018:2019, 27701:2019, 22301:2019, 20000-1:2018, 9001:2015) and CSA STAR compliant. In addition, Amazon has completed its internal assessment to validate that Amazon Bedrock AgentCore aligns with the following Amazon compliance programs: BIO, C5, CISPE, CPSTIC, ENS High, FINMA, GNS, GSMA, HITRUST, IRAP, ISMAP, MTCS, OSPAR, PCI, Pinakes and PiTuKri. Our third-party auditors will review and test Amazon Bedrock AgentCore during the next audit cycles for these compliance programs.

To learn whether an Amazon service is within the scope of specific compliance programs, see Amazon services in Scope by Compliance Program and choose the compliance program that you are interested in. For general information, see Amazon Compliance Programs.

You can download third-party audit reports using Amazon Artifact. For more information, see Downloading Reports in Amazon Artifact.

Your compliance responsibility when using Amazon services is determined by the sensitivity of your data, your company’s compliance objectives, and applicable laws and regulations. For more information about your compliance responsibility when using Amazon services, see Amazon Security Documentation.