2026-06-22 · aws-security
AWS Security announced that Spring 2026 SOC 1 and SOC 2 report packages are now available in the NIST Open Security Controls Assessment Language format. AWS says the OSCAL package is available as a distinct artifact, giving customers a standards-based way to automate compliance evidence handling.
AWS made key assurance reports available in OSCAL, a machine-readable JSON format for security and compliance information. The update lets organizations ingest SOC evidence into governance, risk, and compliance workflows without manually parsing static PDFs.
Compliance artifacts become critical during audits, incident response, insurance reviews, and vendor risk assessments. If those records are lost, altered, or unavailable during a crisis, an organization may struggle to prove control coverage or restore trust after an incident.
Cold storage gives compliance teams an immutable offline copy of security reports, control mappings, and audit evidence. Keeping verified OSCAL packages in offline archives helps preserve chain of custody when live cloud accounts, shared drives, or governance platforms are disrupted.
Read Original Post →