Who Is Responsible for Cloud Compliance? Understanding the Shared Responsibility Model
Understand the cloud shared responsibility model and how compliance responsibilities differ across public and private cloud deployments.
Lire la noteNotes de terrain / Dernières nouvelles
Des notes d’ingénierie issues de l’exploitation d’infrastructures ouvertes : pannes, décisions de conception et travail upstream qui améliorent l’infrastructure ouverte.
Parcourir toutes les notesUnderstand the cloud shared responsibility model and how compliance responsibilities differ across public and private cloud deployments.
Lire la noteHow to evaluate different options to build a software-defined data centre.
Lire la noteEvaluate whether your compute, storage, networking, security, recovery, and operations are ready to support cloud infrastructure growth.
Lire la noteUnderstand the cloud shared responsibility model and how compliance responsibilities differ across public and private cloud deployments.
Cloud compliance is a shared responsibility. While cloud providers secure the underlying infrastructure, organizations remain responsible for protecting their data, managing access, securing workloads, and meeting regulatory requirements. This guide explains how responsibilities differ across public cloud, self-managed private cloud, and managed private cloud environments, helping organizations better understand ownership, reduce compliance risks, and prepare for audits.
One of the most common misconceptions about cloud compliance is that moving to the cloud transfers compliance responsibility to the cloud provider. In reality, cloud compliance follows a shared responsibility model.
While providers secure and operate the underlying infrastructure, organizations remain responsible for protecting their data, managing user access, configuring workloads, and meeting the regulatory requirements that apply to their business.
The importance of clearly defining these responsibilities continues to grow. According to IBM's Cost of a Data Breach Report 2026, 63% of organizations lacked AI governance policies, and 97% of organizations that experienced AI-related security incidents did not have proper AI access controls in place. The report highlights that unclear governance and ownership remain significant contributors to security and compliance risk as organizations adopt new cloud and AI technologies.
Whether you run workloads in a public cloud, a self-managed private cloud, or a managed private cloud, your organization remains accountable for compliance. The difference lies in how operational responsibilities are divided. VEXXHOST helps simplify this model by managing the underlying OpenStack and Kubernetes infrastructure, including platform operations, patching, monitoring, and availability, allowing your team to focus on data governance, application security, access control, and meeting regulatory requirements.
The shared responsibility model defines which security, operational, and compliance responsibilities belong to the cloud provider and which remain with the customer. While the exact division depends on the deployment model, one principle stays the same:
Cloud providers are responsible for securing the infrastructure they operate, while customers are responsible for protecting their data, managing user access, configuring workloads, and meeting the regulatory requirements that apply to their organization.
As we discussed in this blog post, The True Cost of Neglecting Cloud Compliance, failing to clearly define these responsibilities can lead to security gaps, audit challenges, and unnecessary compliance risks. Understanding where responsibility begins and ends is the first step toward building a compliant cloud environment.
The next sections compare how these responsibilities differ across public cloud, self-managed private cloud, and managed private cloud.
In a public cloud environment, the cloud provider is responsible for securing and operating the underlying infrastructure, including physical data centers, networking, storage hardware, and the virtualization layer. This allows organizations to consume infrastructure without managing the physical platform themselves.
However, responsibility does not end with the provider. Customers remain responsible for securing everything they deploy and configure within their cloud environment. This includes managing identities and permissions, protecting data, configuring workloads securely, and ensuring their environment complies with applicable regulations.
Typical customer responsibilities include:
Public cloud providers often maintain certifications such as ISO 27001, SOC 2, or PCI DSS. While these certifications demonstrate that the provider meets specific security and operational standards, they do not automatically extend to customer workloads. Organizations must still configure their environments securely, implement appropriate controls, and provide evidence of compliance during audits.
FIG 1. The division of responsibilities changes depending on the cloud model. The table below shows how common security, operational, and compliance responsibilities are typically assigned across public cloud, self-managed private cloud, and managed private cloud environments.

As the comparison shows, the customer remains responsible for compliance in every deployment model. What changes is who manages the underlying infrastructure and day-to-day platform operations.
In a self-managed private cloud, the organization is responsible for both the infrastructure and the workloads running on it. While this model provides greater control over the environment, it also places more operational and compliance responsibilities on internal teams.
In addition to securing applications and data, organizations are responsible for deploying, maintaining, and updating the private cloud platform itself. This includes managing virtualization, networking, storage, identity services, monitoring, and security updates. They must also maintain the documentation and evidence required to demonstrate compliance during audits.
Typical responsibilities include:
A self-managed private cloud offers the highest level of control and customization, making it well suited for organizations with strict security, sovereignty, or compliance requirements. However, that flexibility comes with the responsibility of operating and securing the entire platform throughout its lifecycle.
A managed private cloud follows the same shared responsibility model, but many of the operational tasks are delegated to the managed service provider. The organization remains responsible for its applications, data, user access, and regulatory obligations, while the provider manages the day-to-day operation of the cloud platform.
Typical provider responsibilities include:
Customer responsibilities typically include:
For organizations that want the control of a private cloud without the operational overhead of managing the platform, VEXXHOST delivers its managed private cloud through Atmosphere, an enterprise-ready OpenStack distribution that combines OpenStack, Kubernetes, and day-two operations into a fully managed platform. This allows organizations to focus on their applications and compliance requirements while VEXXHOST manages the underlying infrastructure and platform lifecycle.
Because Atmosphere combines OpenStack and Kubernetes into a single platform, organizations can manage both virtual machines and cloud-native workloads without maintaining separate infrastructure stacks. Learn more about how these technologies work together in our blog, Why OpenStack and Kubernetes Are Better Together for AI.
Many compliance issues are not caused by vulnerabilities in the cloud platform itself, but by misunderstanding where responsibilities lie. Assuming that the cloud provider manages every aspect of security and compliance can leave important controls unaddressed.
Some of the most common mistakes include:
These issues can often be avoided by clearly documenting ownership, reviewing responsibilities regularly, and implementing security controls throughout the lifecycle of the environment rather than only during audit preparation.
Key Takeaway: A cloud provider's certifications do not automatically make your applications or data compliant. Compliance depends on how your environment is configured, operated, and governed.
Understanding the shared responsibility model is only the first step. Organizations should clearly define ownership of security and compliance tasks and review those responsibilities regularly as their cloud environment evolves.
Some best practices include:
For organizations using a managed private cloud, these responsibilities should be clearly defined in the service agreement. Knowing exactly which tasks are managed by the provider and which remain with your team helps reduce operational risk and simplifies compliance efforts.
Cloud compliance is a shared responsibility, regardless of whether you use a public cloud, a self-managed private cloud, or a managed private cloud. While the division of operational responsibilities changes between deployment models, organizations remain accountable for protecting their data, managing access, and meeting the regulatory requirements that apply to their business.
Understanding who is responsible for each part of the environment helps reduce security gaps, simplify audits, and build a stronger compliance posture over time.
If you're looking to reduce the operational complexity of managing a private cloud while maintaining control over your infrastructure and compliance strategy, VEXXHOST Atmosphere provides a fully managed OpenStack platform with integrated Kubernetes and day-two operations. Our team manages the platform, allowing yours to focus on applications, governance, and business outcomes.
Ready to simplify your private cloud operations? Learn more about Atmosphere or contact our team to discuss your infrastructure and compliance requirements.
Choose from Atmosphere Cloud, Hosted, or On-Premise.
Simplify your cloud operations with our intuitive dashboard.
Run it yourself, tap our expert support, or opt for full remote operations.
Leverage Terraform, Ansible or APIs directly powered by OpenStack & Kubernetes