
© 2026
Compliance Posture Transfer
A certificate describes their controls. It says nothing about yours.
Most compliance conversations with a cloud provider end the same way. You ask how they handle data protection, and they hand you a certificate. ISO 27001. SOC 2. Sometimes both. The conversation stops there, as if the certificate answered the question. It didn't. It answered a different question.
What a Certificate Actually Covers
An ISO 27001 or SOC 2 certification describes the provider's own internal controls: how they manage risk, how they handle their own infrastructure, how they respond to incidents on their side of the relationship. It's a real, useful thing to have. It is not a description of your compliance obligations, and it was never designed to be one.
When a regulator, an auditor, or a client asks where a specific record sits, who has accessed it, and when, a provider's certificate doesn't answer any of those questions. It answers "is this provider generally well-run," which is a different question with a different owner.
The Question a Certificate Doesn't Answer
Try asking your current provider these three questions directly:
Which specific jurisdiction is this record stored in, right now
Who, by name or role, has access to it
What happens to it if you terminate the contract tomorrow
For most organisations running on shared cloud infrastructure, the honest answer to at least one of these is "it depends" or "let us check." That gap, between what a certificate implies and what you can actually state with certainty, is what we mean by compliance posture transfer. The certificate creates an impression of assurance. It does not transfer the underlying facts.
What Compliance Posture Actually Means for You
Your compliance posture is the set of things you can state, directly and without needing to escalate to a vendor, about where your data lives, who can reach it, and what your recourse is if something goes wrong. It's yours, not something you inherit by paying a subscription to a certified provider.
This matters most in the moment it's tested: an audit, a client due diligence questionnaire, a regulatory inquiry. That's not the moment to discover you don't actually know the answer.
What This Looks Like in Practice
An organisation with a real compliance posture, rather than a borrowed one, can typically state plainly:
The named jurisdiction their data is stored in
Who has access, and how that access is logged
What their backup policy is, specifically, not generally
What happens to their data if the relationship with their provider ends
If you can't answer all four without checking with someone else first, that's the gap this whole conversation is about.
Final Thoughts
A certificate is a real thing, and it's not nothing. But it describes a provider's homework, not yours. The organisations that hold up best under scrutiny are the ones who built their own answer to these questions instead of borrowing one, and that starts with an architecture you can actually point to, not a badge you can show.
References
ISO/IEC 27001, the international standard for information security management systems: https://www.iso.org/standard/27001
AICPA & CIMA, System and Organization Controls (SOC) suite of services: https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
[02]
//READ MORE

Compliance Posture Transfer

The Hidden Cost of the Cloud

Why We Build on Refurbished Hardware

Singapore's PDPA and the EU's GDPR: Building Infrastructure That Satisfies Both

Why Sovereign Cloud Spend Is Projected to Reach $80B by 2026

What Actually Happens to Your Data When You Delete a File in Google Workspace

Microsoft 365's Default Retention Settings, and Why Most Admins Never Change Them

How to Actually Test a Backup Restore, Not Just Confirm One Exists

The Difference Between a Backup and a Disaster Recovery Plan

Self-Hosted vs. Managed SaaS: What You Actually Give Up in Each Direction

