Kiro is covered by AWS ISO/IEC 27001:2022 certification

Kiro is now included among the AWS services covered by ISO/IEC 27001:2022 certification. This gives security, procurement, and vendor-risk teams a recognized, independently verified reference point when evaluating Kiro as part of their reviews.

ISO/IEC 27001 sets requirements for an information security management system: the policies, processes, responsibilities, and controls an organization uses to identify and manage information security risks. These certifications are performed by independent third-party auditors.

Note: The certified scope is Kiro, excluding Fable. Unless a service is specifically excluded, AWS states that all of its features are in scope. Refer to the current AWS services-in-scope listing when documenting coverage in your own reviews.

For details on Kiro's compliance posture, see the Compliance validation documentation.