Kiro adds ISO/IEC 27001:2022 coverage
Kiro is included in the defined scope of AWS's ISO/IEC 27001:2022 certification. This gives security, procurement, and vendor-risk teams independently verified evidence they can use when evaluating Kiro.
ISO/IEC 27001 sets requirements for an information security management system: the policies, processes, responsibilities, and controls an organization uses to identify and manage information security risks. AWS's certification is verified by EY CertifyPoint, an ISO certification body accredited by the Dutch Accreditation Council.
Organizations can consider this evidence alongside their own policies, intended use, data requirements, and governance controls.
For details about Kiro's compliance programs and access to available third-party reports, see Compliance validation. To learn how Kiro stores, processes, and protects customer data, see Data protection.