Skip to main content

Part of Infrastructure hosting standards for the NHS

Appendix A Cloud Hyperscaler shared responsibility model

Current Chapter

Current chapter – Appendix A Cloud Hyperscaler shared responsibility model


Where cloud hyperscalers provide cloud-based infrastructure, a shared responsibility model defines the division of security and compliance obligations between cloud hyperscalers and their customers. Hyperscalers should be accountable for the security of the cloud infrastructure itself, including physical facilities, hardware, networking, and foundational services. Customers, in turn, remain responsible for the security and compliance of their data, applications, configurations, and user access within that environment.

To ensure effective governance, in-scope entities must recognize that while certain operational controls should be managed by the hyperscaler, ultimate accountability for compliance remains with them. This requires implementing appropriate assurance processes such as configuration management, monitoring, and auditing, and ensuring that contractual arrangements with hyperscalers explicitly reflect these responsibilities and obligations.  In summary,

  • Hyperscaler responsibilities: Security of the cloud infrastructure (facilities, hardware, networking, foundational services)
  • Entity responsibilities: Security and compliance of data, applications, configurations, and user access
  • Accountability: In-scope entities retain ultimate responsibility for compliance, even when controls should be managed by the hyperscaler
  • Assurance: Monitoring, auditing, and contractual arrangements must reflect and enforce these shared obligations

Last edited: 17 June 2026 3:59 pm