

# Compliance validation for Amazon Bedrock AgentCore
<a name="compliance-validation"></a>

Amazon Bedrock AgentCore is HIPAA eligible and FedRAMP (Class C and Class D), SOC 2 and ISO (27001:2022, 27017:2015, 27018:2019, 27701:2019, 22301:2019, 20000-1:2018, 9001:2015) and CSA STAR compliant. In addition, Amazon has completed its internal assessment to validate that Amazon Bedrock AgentCore aligns with the following Amazon compliance programs: BIO, C5, CISPE, CPSTIC, ENS High, FINMA, GNS, GSMA, HITRUST, IRAP, ISMAP, MTCS, OSPAR, PCI, Pinakes and PiTuKri. Our third-party auditors will review and test Amazon Bedrock AgentCore during the next audit cycles for these compliance programs.

To learn whether an Amazon service is within the scope of specific compliance programs, see [Amazon services in Scope by Compliance Program](https://www.amazonaws.cn/compliance/services-in-scope/) and choose the compliance program that you are interested in. For general information, see [Amazon Compliance Programs](https://www.amazonaws.cn/compliance/programs/).

You can download third-party audit reports using Amazon Artifact. For more information, see [Downloading Reports in Amazon Artifact](https://docs.amazonaws.cn/artifact/latest/ug/downloading-documents.html).

Your compliance responsibility when using Amazon services is determined by the sensitivity of your data, your company’s compliance objectives, and applicable laws and regulations. For more information about your compliance responsibility when using Amazon services, see [Amazon Security Documentation](https://docs.amazonaws.cn/security/).