Cloud Shared Responsibility Model: A Compliance Guide for SMBs (2026). 

Knowing who is responsible for cloud security is critical for maintaining a secure and compliant cloud environment. The cloud shared responsibility model outlines how security tasks are divided between the cloud vendor and the customer, ensuring both parties know their roles in protecting sensitive data and systems.

The shared responsibility model in cloud computing varies by cloud service model, such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), or Software as a Service (SaaS). Whether you’re using Amazon Web Services, Microsoft Azure, or other public clouds, knowing “what is the shared responsibility model” helps you address potential security risks, strengthen your security posture, and avoid misunderstandings that could lead to breaches.

What is the Shared Responsibility Model in Cloud Security?

The shared responsibility model in cloud is a framework that defines how security and operational tasks are split between the cloud vendor and their customer. It ensures clarity in managing the cloud security responsibility, reducing the risk of gaps in protection.

At its core, the model works on a simple principle: the cloud vendor is responsible for securing the cloud environment itself, while the customer is responsible for securing their own data, applications, and security configurations within the cloud.

For example, Amazon Web Services (AWS) handles the physical infrastructure and network controls for its data centers, but customers must secure their identity and access management and configure their operating systems correctly.

Learn more: A Guide to Cloud Security Governance

Breakdown of Responsibilities

In the cloud shared responsibility model, security tasks are divided between the cloud vendor and the customer. This division ensures every aspect of the cloud environment is properly managed, reducing the chance of vulnerabilities.

Here’s how the shared responsibility model works in practice:

Cloud Vendor Responsibilities

Cloud providers like AWS and Microsoft Azure are responsible for securing the infrastructure of the public clouds they operate. This includes:

For example, AWS secures its global infrastructure, including power, climate control, and physical server security, while Azure handles the physical and network-level protections for its regions.

Customer Responsibilities

Customers are responsible for managing their data, applications, and any security configurations within the cloud. Key tasks include:

Variations by Cloud Service Model

The shared responsibility model cloud framework adapts depending on the type of cloud service model you are using. The division of security responsibilities shifts, with customers taking on more or less depending on the model.

Infrastructure as a Service (IaaS)

In IaaS, such as AWS EC2, customers handle the majority of security tasks. The cloud vendor manages the physical infrastructure and network controls, but customers must secure the operating system, applications, and their own identity and access management.

Customer Responsible For:

Platform as a Service (PaaS)

In PaaS, like Microsoft Azure App Services, the cloud vendor handles more, including the runtime, middleware, and some server configurations. Customers focus on their applications and data security.

Customer Responsible For:

Software as a Service (SaaS)

In SaaS, such as Microsoft 365 or Google Workspace, the cloud vendor manages nearly all aspects of security, including the software, infrastructure, and underlying systems. Customers primarily focus on their identity and access management and protecting their data.

Customer Responsible For:

Responsibility Matrix at a Glance
Responsibility layer IaaS PaaS SaaS
Physical infrastructure & data centers Vendor Vendor Vendor
Network controls & hypervisor Vendor Vendor Vendor
Operating system patching Customer Vendor Vendor
Middleware & runtime Customer Vendor Vendor
Application code Customer Customer Vendor
Data encryption & classification Customer Customer Customer
Identity & access management Customer Customer Customer
Client/endpoint security Customer Customer Customer
Where AWS, Azure, and GCP Actually Differ
Function AWS Azure GCP
Shared responsibility documentation AWS Shared Responsibility Model Microsoft Shared Responsibility Model Google Cloud Shared Responsibility Model
Native security posture tool AWS Security Hub Microsoft Defender for Cloud Security Command Center
Identity & access service AWS IAM Microsoft Entra ID Google Cloud IAM
Configuration compliance tool AWS Config Azure Policy Policy Intelligence / Asset Inventory
Encryption key management AWS KMS Azure Key Vault Cloud KMS
Visual Responsibility Matrix: AWS vs Azure vs GCP by Service Model

The generic breakdown above holds across providers, but seeing it laid out side by side for AWS, Azure, and GCP at each service model makes the ownership lines easier to spot at a glance. 

AWS

Responsibility layer IaaS (EC2) PaaS (Elastic Beanstalk) SaaS (WorkMail)
Physical infrastructure & data centers Vendor Vendor Vendor
Network controls & hypervisor Vendor Vendor Vendor
Operating system patching Customer Vendor Vendor
Middleware & runtime Customer Vendor Vendor
Application code Customer Customer Vendor
Data encryption & classification Customer Customer Customer
Identity & access management (IAM) Customer Customer Customer
Client/endpoint security Customer Customer Customer

Azure

Responsibility layer IaaS (Virtual Machines) PaaS (App Service) SaaS (Microsoft 365)
Physical infrastructure & data centers Vendor Vendor Vendor
Network controls & hypervisor Vendor Vendor Vendor
Operating system patching Customer Vendor Vendor
Middleware & runtime Customer Vendor Vendor
Application code Customer Customer Vendor
Data encryption & classification Customer Customer Customer
Identity & access management (IAM) Customer Customer Customer
Client/endpoint security Customer Customer Customer

GCP

Responsibility layer IaaS (Compute Engine) PaaS (App Engine) SaaS (Google Workspace)
Physical infrastructure & data centers Vendor Vendor Vendor
Network controls & hypervisor Vendor Vendor Vendor
Operating system patching Customer Vendor Vendor
Middleware & runtime Customer Vendor Vendor
Application code Customer Customer Vendor
Data encryption & classification Customer Customer Customer
Identity & access management (IAM) Customer Customer Customer
Client/endpoint security Customer Customer Customer

Why the Shared Responsibility Model Matters

The cloud shared responsibility model is essential for building a strong security posture in any cloud environment. Misunderstanding this model can lead to secure risks, regulatory issues, and costly breaches.

1. Avoid Security Gaps

Without clear accountability, vulnerabilities in critical areas like identity and access management or operating system security can be overlooked. For example, a cloud vendor may secure the data center, but leaving customer-side misconfigurations unchecked, such as unencrypted data or weak passwords, exposes your organization to attacks.

2. Ensure Regulatory Compliance

In industries with strict compliance requirements, understanding cloud security responsibility is vital. For example, regulations like GDPR and HIPAA expect businesses to safeguard their data within the cloud environment, even when using services like Microsoft Azure or AWS. Knowing which party is responsible helps align your security posture with legal requirements.

3. Mitigate Liability

If a breach occurs, knowing your role within the shared responsibility model cloud is crucial to determine accountability. Mismanaging your customer-side responsibilities—like weak security configurations or poor access controls—can leave you liable, even if the cloud vendor fulfills their obligations.

Common Challenges and Best Practices

While the shared responsibility model clarifies roles, it comes with challenges. Here’s how to overcome them with actionable best practices:

Common Challenges
Best Practices for Shared Responsibility

Compliance-specific sections: HIPAA, FedRAMP, CMMC

The shared responsibility model doesn’t change under different compliance frameworks — but what you’re required to document and prove does. Here’s how it applies to three frameworks Davenport works with regularly. 

Shared Responsibility Under HIPAA

Healthcare organizations remain responsible for protecting patient data (PHI) regardless of which cloud platform hosts it. Cloud vendors can sign a Business Associate Agreement (BAA) and secure the infrastructure, but encryption, access controls, and audit logging for PHI stay the customer’s responsibility. A signed BAA does not transfer HIPAA liability — it clarifies which party handles which technical safeguard. 

Shared Responsibility Under FedRAMP

For organizations working with federal agencies, FedRAMP authorization confirms a cloud provider meets federal security standards — but that authorization covers the vendor’s infrastructure, not how the customer configures their environment. Agencies and contractors are still responsible for their own access controls, data handling, and continuous monitoring within an authorized cloud environment. 

Shared Responsibility Under CMMC

Defense contractors handling Controlled Unclassified Information (CUI) must meet CMMC requirements regardless of hosting model. Using a cloud provider with strong infrastructure security does not, on its own, satisfy CMMC, contractors still own configuration, access management, and evidence collection for their specific certification level. 

Secure Your Future in the Cloud

By understanding the division of security responsibilities between the cloud vendor and the customer, businesses can better protect their data, maintain compliance, and avoid security gaps.

The expert cloud consultants at Davenport Group can help you optimize your security configurations, reduce risks, and ensure compliance with the shared responsibility model. Reach out to us for a free consultation today.

Frequently Asked Questions

Who is responsible for data security in the cloud?

The customer is always responsible for their own data, encryption, access controls, and classification, regardless of cloud provider or service model. The vendor secures the infrastructure the data lives on, not the data itself. 

What is the shared responsibility model in AWS?

The AWS Shared Responsibility Model defines security responsibilities between AWS and the customer. AWS secures the underlying cloud infrastructure, including hardware, software, networking, and facilities. Customers are responsible for securing their data, applications, operating systems, user access, and configurations within AWS services, ensuring proper identity management and compliance with security requirements. 

How does shared responsibility differ between IaaS and SaaS?

In IaaS, the customer manages the operating system, middleware, and applications on top of vendor-managed infrastructure. In SaaS, the vendor manages nearly the entire stack, and the customer's responsibility narrows mainly to identity, access, and data governance. 

Picture of BJ Bradley
BJ Bradley
Chief Operating Officer BJ Bradley leads Davenport Group's engineering team with deep technical expertise and strong business acumen. Since joining in 2013, he has built the end-user computing practice, refined security market approaches, and developed managed services. BJ's leadership has been recognized with the CRN Next Generation Solution Provider Leader award in 2021, 2022, and 2023. With over 15 years in IT, his roles have included Systems Engineer, VMware Engineer, and Director of Engineering, specializing in data center and managed service solutions. View BJ's LinkedIn