← Back to News

AWS Releases SOC Reports in OSCAL

2026-06-22 · aws-security

AWS Security announced that Spring 2026 SOC 1 and SOC 2 report packages are now available in the NIST Open Security Controls Assessment Language format. AWS says the OSCAL package is available as a distinct artifact, giving customers a standards-based way to automate compliance evidence handling.


What Happened

AWS made key assurance reports available in OSCAL, a machine-readable JSON format for security and compliance information. The update lets organizations ingest SOC evidence into governance, risk, and compliance workflows without manually parsing static PDFs.

The Cost of Data Loss

Compliance artifacts become critical during audits, incident response, insurance reviews, and vendor risk assessments. If those records are lost, altered, or unavailable during a crisis, an organization may struggle to prove control coverage or restore trust after an incident.

How Cold Storage Prevents This

Cold storage gives compliance teams an immutable offline copy of security reports, control mappings, and audit evidence. Keeping verified OSCAL packages in offline archives helps preserve chain of custody when live cloud accounts, shared drives, or governance platforms are disrupted.

Read Original Post →