AWS Artifact

AWS Artifact is a self-service portal of Amazon Web Services that provides on-demand access to security and compliance reports.

AI Practitioner focus

  • Artifact supplies AWS compliance reports/certifications and agreements for due diligence. It does not assess a customer’s AI workload or collect evidence about the customer’s configuration.
  • AWS Audit Manager organizes evidence about customer AWS usage; Amazon Config evaluates resource configuration; compliance still depends on the complete workload and applicable obligations.

Key points

  • Provides an enterprise with access to security and compliance reports about the AWS public cloud, including ISO certifications, PCI DSS reports, and SOC (Service Organization Control) reports.
  • Also provides agreements for download, such as the Business Associate Addendum (BAA) for HIPAA and a Nondisclosure Agreement (NDA).
  • Supports security and compliance review processes for the organization.
  • Complements AWS Security Hub’s compliance-standard checks (PCI DSS, CIS) by supplying the underlying audit reports on demand.
  • Distinct from Amazon Config, which continuously monitors and records actual AWS resource configurations — Artifact only provides static, on-demand third-party audit reports and agreements, not live resource compliance data.
  • The console is organized into two sections: Artifact Reports — on-demand download of AWS’s compliance and security reports (SOC, PCI DSS, ISO certifications, and similar) — and Artifact Agreements — reviewing, accepting, and tracking the status of agreements with AWS, such as the Business Associate Addendum (BAA) for HIPAA workloads or a Nondisclosure Agreement (NDA), for a single account or across multiple accounts in an organization.
  • Any AWS customer can access Artifact through their AWS account at no extra cost; some agreements can only be accepted by the account owner or another individual explicitly authorized to accept agreements on the account’s behalf.
  • It is free — AWS provides Artifact reports and agreements at no charge.
  • Fits the AWS Shared Responsibility Model: Artifact is how a customer obtains evidence of AWS’s side of the shared responsibility split (AWS’s compliance with security standards and certifications) — it does not produce or certify evidence about the customer’s own configuration of their workload.

Sources