Audit and compliance
Shared responsibility model
Also called: cloud shared responsibility
The shared responsibility model is the division of security duties between a cloud provider and its customer. The provider secures the underlying infrastructure; the customer secures configuration, identity, access and data. A provider's own compliance certifications do not transfer to the customer's system.
The recurring error is treating a provider's SOC 2 as covering your product. It covers their infrastructure. Your configuration, your access model and your application are yours to evidence.
Testing, with the report an auditor can actually use
A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.