Skip to content
In progressAWS Competency

Security Competency

Submitted for residency-first architecture, least-privilege identity, and audit trails designed in from the first schema.

Status
Under review
Submitted
August 2026
Decision
Expected Q1 2027
References
2 submitted

What it covers

Constraints, not configuration flags.

Our submission centres on workloads where residency and auditability were architectural constraints from the first schema — public health records and regulated lending.

Data residency

Region-pinned storage and processing designed in, not retrofitted.

Identity & access

Least-privilege models with access reviewed as a standing practice.

Audit logging

Immutable trails that stand up to external examination.

Secure delivery

Scanning and policy checks inside the pipeline, not after release.

Validation criteria

What AWS assessed.

This competency is under AWS review. Two regulated engagements have been submitted; the technical review is scheduled for early next year.

How validation works

Regulated workloads

Public sector and fintech engagements with residency requirements.

Submitted

Control mapping

PCI and SOC control coverage documented against real architectures.

Submitted

Technical review

AWS security review scheduled for Q1 2027.

Pending

Final validation

Decision expected in the first half of next year.

Not started

Services

What we build it on.

  • IAM
  • KMS
  • CloudTrail
  • Config
  • WAF
  • Shield
  • Security Hub

Team on this practice

Security sits with the cloud practice — the same nine people who own the landing zone own the posture.

Work with this practice

Workload an auditor will examine?

Discovery comes first — a short, bounded review that ends in an architecture, a scope, and a price. You keep the output either way.