Updated September 30, 2026
AWS says 21 of the 110 CMMC Level 2 requirements are fully inheritable from AWS. 79 are shared, and 10 are yours alone. The 21 are almost all about AWS's own data centers, disks, and hardware.
CMMC Level 2 is the Pentagon's list of 110 security requirements for any company holding CUI (controlled unclassified information: the drawings, specs, and technical data the government marks as sensitive). AWS is Amazon's cloud, where companies rent servers, storage, and databases. When someone says AWS "covers" CMMC, that is marketing language. The 21 come off your plate only if you build your AWS setup the way AWS's guidance describes and cite AWS's matrix in your security plan. The other 89 have your name on them.
First: does AWS belong in your count at all?
For most small defense suppliers, no. AWS enters your CMMC scope only if CUI is stored or processed there. If your drawings live in Microsoft 365 GCC High, Google Workspace, or PreVeil, and AWS runs only your public website, AWS is not a CUI system and you don't need its matrix. A website that never holds a drawing is out of scope.
AWS matters when you host something there yourself: a file server or ERP system on an EC2 server, backups of CUI in S3 storage, a virtual desktop on WorkSpaces, or custom software your engineers build and run. If that's you, read on. If it isn't, spend your time on the cloud that actually holds your drawings.
One more case: some services you buy run on AWS underneath. PreVeil, for example, stores its data on AWS GovCloud (PreVeil guide, page 13). You inherit through PreVeil's matrix, not AWS's. See how many controls PreVeil covers.
Where the numbers come from
AWS publishes its Customer Responsibility Matrix (the provider's list of who does each requirement) inside the AWS CMMC Customer Package. You download it from AWS Artifact, the document portal inside the AWS console, so you need an AWS account to read it. AWS says the package covers the controls "customers can inherit from AWS by using the AWS Landing Zone Accelerator in the AWS GovCloud (US)" (AWS CMMC page). Landing Zone Accelerator is AWS's pre-built account setup for regulated workloads.
The public summary is AWS's Preparation guide for CMMC Level 2 on AWS, first published June 14, 2026. It sorts the 110 into Inheritable (21), Partial (79), and Customer Only (10), and it names every inheritable and customer-only control (FAQ). By family:
| Family | What it covers | AWS | Shared | You |
|---|---|---|---|---|
| AC | Who can log in and what they reach | 2 | 16 | 4 |
| AT | Security training | 0 | 3 | 0 |
| AU | Audit logs | 0 | 9 | 0 |
| CM | Settings and software control | 0 | 9 | 0 |
| IA | Passwords and multi-factor login | 0 | 8 | 3 |
| IR | Incident response | 0 | 3 | 0 |
| MA | Maintenance | 5 | 1 | 0 |
| MP | Media: drives, USB sticks, paper | 8 | 1 | 0 |
| PE | Physical security | 6 | 0 | 0 |
| PS | Personnel screening | 0 | 2 | 0 |
| RA | Risk assessment and scanning | 0 | 3 | 0 |
| CA | Security assessment and your SSP | 0 | 4 | 0 |
| SC | Network and encryption | 0 | 13 | 3 |
| SI | Patching and malware | 0 | 7 | 0 |
| Total | 21 | 79 | 10 |
The 21 are all six physical-security requirements, eight of nine media requirements (3.8.1 through 3.8.8), five maintenance requirements (3.7.1–3.7.4 and 3.7.6), and two wireless requirements (3.1.16 and 3.1.17). Nothing in audit logging, configuration, identity, incident response, risk, or system integrity is inheritable. AWS's own blog puts it plainly: inherited controls "exist only at the AWS infrastructure layer" (AWS Public Sector blog, April 2026).
GovCloud or a regular region?
AWS runs two relevant clouds. AWS GovCloud (US) is FedRAMP High, authorized by the Joint Authorization Board in June 2016 (FedRAMP Marketplace). The commercial US East and West regions are FedRAMP Moderate (FedRAMP Marketplace). DFARS 7012 requires any cloud holding CUI to meet FedRAMP Moderate or its equivalent, so both qualify.
AWS's guide gives a simple rule. Use GovCloud if you handle ITAR or EAR export-controlled data, or if a contract calls for DoD Impact Level 4 or 5. GovCloud is run by U.S. persons only and uses FIPS-validated encryption endpoints by default. For other CUI, commercial US East/West works, as long as you point every service at its FIPS endpoint (AWS: choosing your region).
For a machine shop, the tiebreaker is the drawings. A drawing with an ITAR or EAR export-control notice points to GovCloud. Is this drawing CUI? walks through the markings.
AWS offers the CMMC package in both partitions, but the matrix is written around GovCloud with Landing Zone Accelerator. AWS publishes no separate count for commercial regions.
Seven rows people get wrong
Media protection (3.8.1–3.8.8), marked inheritable. This is the row that trips people. AWS inherits it for AWS's disks: how its data-center drives are handled, reused, and destroyed. Your USB sticks, your laptops, and the printed drawing on the inspection bench are not in AWS's building. If CUI exists anywhere outside AWS, those media rows are yours for that place. The media and printers guide covers them.
Who gets in (3.1.1, 3.1.5), shared. AWS supplies IAM, its permission system. You decide which people get which roles, give admin rights to as few as possible, and keep the root account (the all-powerful owner login) locked away and unused. Every quarter, compare the IAM user list with your list of approved people.
Multi-factor login (3.5.3), shared. AWS supports multi-factor. You turn it on for the root account and every person with console access. Multi-factor login is worth 5 points on the DoD scoring method (how scoring works), and one admin account without it is enough to lose them.
Account lockout and password rules (3.1.8, 3.5.7–3.5.9), yours. AWS lists all four as customer-only. Set lockout and password rules in whatever you sign in with, whether that's Entra, Okta, or IAM's own password policy, and write the same numbers into your policy.
Audit logs (3.3.1), shared. AWS writes the logs through CloudTrail. You turn CloudTrail on for every region and account, keep the logs as long as your policy says, and have someone read them on a schedule. A trail nobody reviews fails the review requirement (3.3.5).
Encryption (3.13.11), shared. AWS provides FIPS-validated encryption. In a commercial region it only counts if you use the FIPS endpoints. In GovCloud they're the default. Your laptops and your VPN still need their own FIPS-validated encryption.
Split tunneling (3.13.7), yours. A laptop on your VPN must not also talk straight to the internet. That is a VPN client setting on your computers. AWS lists it customer-only, along with conference-room cameras and microphones (3.13.12) and voice and video calls (3.13.14).
What AWS doesn't cover
AWS counts training (all three AT rows), your System Security Plan (3.12.4), and personnel screening (3.9.1) as partial. Whatever AWS contributes there covers its own staff and systems. Your people, your hires, and your SSP are 100% yours.
Everything outside AWS is also outside the matrix: your office, your Wi-Fi, your laptops, your phones, your printers, the shop floor. So is the AWS configuration itself. AWS gives you the tools. Whether the security settings are actually on, and whether someone checks them, is a shared row every time.
What "inherited" requires
The 21 inheritable rows hold only when three things are true:
- The CUI is inside AWS. The media and physical rows describe AWS's building and disks. CUI kept anywhere else brings them back to you.
- You're built the way the matrix assumes. The package describes an environment built with Landing Zone Accelerator in GovCloud. If you built your accounts by hand, map your setup against it before claiming a row.
- The matrix is cited in your SSP. For each inherited row, name AWS as the provider and point to the CMMC Customer Package from AWS Artifact. AWS's guide says to give that package to your assessor as the evidence.
The Customer Responsibility Matrix explainer shows how to write an inherited row.
Common questions
How many CMMC controls does AWS cover? AWS says 21 of 110 are fully inheritable, 79 are shared, and 10 are yours. Those numbers come from AWS's CMMC Customer Package, built for Landing Zone Accelerator in GovCloud.
Is AWS GovCloud CMMC compliant? No cloud is CMMC compliant. Companies are. GovCloud is FedRAMP High, which clears the DFARS 7012 cloud bar, and it carries 21 requirements for you. Your company still passes or fails its own assessment.
Do I need GovCloud for CMMC Level 2? Not always. AWS says commercial US East/West with FIPS endpoints meets Level 2 for CUI that isn't export-controlled. Export-controlled drawings or an Impact Level 4 or 5 requirement mean GovCloud.
Where is the AWS CMMC customer responsibility matrix? In AWS Artifact, inside the AWS console, as the AWS CMMC Customer Package. It is available in both the standard and GovCloud partitions.
Does AWS cover more than Microsoft or Google? Fewer rows, because AWS sells infrastructure you build on, not finished email and files. Microsoft's placemat marks 52 inherited for GCC High. Google's guide marks 42 for Workspace Enterprise Plus. An endpoint tool sits at the far end: CrowdStrike Falcon's inherited count is zero.
The short version for the owner
If nothing with CUI runs in AWS, leave it out of your matrix and your SSP. If something does, download the package from Artifact this week, list the 10 customer-only rows, and give each one a name and a date. Then take the 79 shared rows to whoever built your AWS account. They're the ones who know which settings are on.
