Microsoft 365How-To & HardeningRetrospectives

Annual Cloud Provider Security Review Checklist

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from April 2024, written in 2026 with the benefit of hindsight.

Use this checklist to review each major cloud provider's security each year.

Evidence

  • Current SOC 2 Type II report reviewed (including exceptions and complementary user entity controls).
  • ISO 27001 and cloud-specific certifications current.
  • Sector-specific attestations (HIPAA BAA, PCI DSS, FedRAMP) in place where required.
  • Penetration test summaries or bug bounty program information reviewed.

Incidents

  • Provider incidents in the past year identified (public disclosures, notifications to you).
  • Root cause reports obtained for incidents affecting your services.
  • Your own response to provider incidents reviewed.

Contract

  • Incident notification terms meet your needs.
  • Logging and audit data availability confirmed.
  • Data residency commitments match requirements.
  • Subprocessor list reviewed.

Your configuration

  • Shared responsibility mapping current.
  • Customer-side controls (complementary user entity controls) implemented.
  • Provider security recommendations reviewed (for example, secure score or Trusted Advisor).

Resilience

  • Dependency on the provider for critical services documented.
  • Exit or contingency plan exists for critical services.
  • Backups stored independently where required.

Outcome

  • Risk rating updated.
  • Actions assigned with owners.
  • Summary reported to leadership or risk committee.
cloud provider security review checklistCSRB report2024

More on this story