Azure Compliance Frameworks
Survey the regulatory frameworks available in the Azure compliance portfolio, and understand how Microsoft's shared-responsibility model divides compliance obligations.
Azure Compliance Frameworks is a free Cloud & IT Cert Prep lesson on CoddyKit — lesson 1 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Cloud & IT Cert Prep learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.
Why Compliance Matters in the Cloud
Moving workloads to Azure does not eliminate compliance obligations — it changes how they are met. Organisations must still comply with industry regulations, government laws, and contractual obligations even when their infrastructure is in the cloud. Understanding which compliance frameworks apply to your workload, and how Azure helps you meet them, is a key topic in the AZ-900 exam and in real enterprise Azure deployments.
The Shared Responsibility Model Revisited
Compliance in the cloud is governed by the shared responsibility model. Microsoft is responsible for the security and compliance of the cloud infrastructure (physical data centres, networking hardware, host OS). Customers are responsible for the security and compliance of what runs in the cloud (their applications, data, identities, and configurations). The boundary shifts depending on whether you use IaaS, PaaS, or SaaS.
Microsoft's Compliance Portfolio
Microsoft maintains compliance certifications for Azure across more than 100 regulatory standards and frameworks. These cover regions, industries, and security disciplines, including:
- International — ISO 27001, ISO 27018, SOC 1/2/3
- EU/Regional — GDPR, ENS, UK Cyber Essentials
- Industry — HIPAA (healthcare), PCI DSS (payments), FedRAMP (US government)
ISO 27001 on Azure
ISO 27001 is an international standard for information security management systems (ISMS). Microsoft has achieved ISO 27001 certification for Azure, meaning the infrastructure and operational processes have been audited by an independent third party. However, customers must separately certify their own applications and data management practices — Microsoft's certification does not extend automatically to customer workloads.
PCI DSS for Payment Workloads
PCI DSS (Payment Card Industry Data Security Standard) applies to organisations that store, process, or transmit cardholder data. Azure is a PCI DSS Level 1 certified service provider, the highest certification level. Customers running payment workloads on Azure can build on this foundation, but must implement additional controls in their application layer (tokenisation, encryption, access logging) to meet their own PCI DSS obligations.
HIPAA for Healthcare
HIPAA (Health Insurance Portability and Accountability Act) governs the protection of Protected Health Information (PHI) in the United States. Microsoft offers a HIPAA Business Associate Agreement (BAA) for Azure services, confirming that Microsoft will safeguard PHI it processes on your behalf. Healthcare customers must sign the BAA and configure their Azure workloads to comply with HIPAA technical safeguards.
SOC 1, SOC 2, and SOC 3 Reports
SOC (System and Organisation Controls) reports are independent auditor assessments of Azure's controls:
- SOC 1 — financial reporting controls (relevant for SaaS products that affect customer financial statements)
- SOC 2 — security, availability, processing integrity, confidentiality, and privacy controls
- SOC 3 — a public summary of SOC 2 findings, available to anyone
SOC 2 reports are available to Azure customers under NDA via the Service Trust Portal.
FedRAMP for US Government
FedRAMP (Federal Risk and Authorization Management Program) is a US government framework for cloud service authorisation. Azure has FedRAMP High authorisation for government regions (USGov and USDoD). US federal agencies must use FedRAMP-authorised cloud services. Commercial Azure regions have FedRAMP Moderate authorisation, which covers a large proportion of government workloads.
The Microsoft Service Trust Portal
The Microsoft Service Trust Portal (STP) at servicetrust.microsoft.com is a one-stop shop for compliance documentation, audit reports, and certification information about Microsoft cloud services. From the STP you can download ISO 27001 certificates, SOC 2 reports, penetration test results, and data protection impact assessments. Access to some documents requires an Azure or Microsoft 365 account and NDA acceptance.
Data Residency and Sovereignty
Data residency requirements mandate that certain data must be stored and processed within a specific geographic boundary. Azure addresses this through region selection — you choose which region to deploy resources in, and your data stays in that region by default. Azure also offers sovereign cloud instances (Azure Government, Azure China 21Vianet, Azure Germany) that are operated independently to meet specific national data sovereignty requirements.
Compliance as a Continuous Process
Achieving compliance is not a one-time event — it requires ongoing monitoring and evidence collection. Microsoft Compliance Manager within the Microsoft Purview compliance portal helps organisations track their compliance posture continuously, map controls to regulations, and generate evidence for auditors. Regular internal audits, automated policy checks via Azure Policy, and centralised log collection are all part of a mature compliance programme.
Quick Check
Test your understanding of Microsoft Azure Fundamentals (AZ-900) concepts from this lesson.
Lesson Recap
In this lesson you learned: Azure holds certifications for over 100 compliance frameworks including ISO 27001, PCI DSS, HIPAA, and FedRAMP; the shared responsibility model divides compliance obligations between Microsoft and the customer; and the Service Trust Portal is the source for audit reports and certification documents. Next up we explore Microsoft Purview for data governance and classification.
Frequently asked questions
Is the “Azure Compliance Frameworks” lesson free?
Yes — the full text of “Azure Compliance Frameworks” is free to read here on the web, and the Cloud & IT Cert Prep course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Cloud & IT Cert Prep course, upgrade to CoddyKit PRO.
What will I learn in “Azure Compliance Frameworks”?
Survey the regulatory frameworks available in the Azure compliance portfolio, and understand how Microsoft's shared-responsibility model divides compliance obligations. You practise Cloud & IT Cert Prep with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start Cloud & IT Cert Prep?
No prior experience is required. Cloud & IT Cert Prep on CoddyKit is structured for beginners through advanced learners; this is — lesson 1 of 4, so you can start here or from the beginning and move at your own pace.
How long does the “Azure Compliance Frameworks” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this Cloud & IT Cert Prep lesson?
Yes. Every Cloud & IT Cert Prep lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- Azure Compliance Frameworks
- Microsoft Purview and Data Governance
- Microsoft Compliance Manager
- GDPR on Azure