Article

AWS Europe (London) renews its 2026 PASF accreditation: what the facility audit covers

AWS Europe (London) renewed its Police-Assured Secure Facilities (PASF) accreditation, which the Police Digital Service confirmed on May 28, 2026. The renewal continues assurance at the facility layer, while workload configuration and data handling still require each customer organization's assessment.

Share

Koharu's reading tip

An accredited Region does not automatically make every workload compliant. The useful reading angle is to separate controls inherited from the facility layer from those the customer must design and evidence.

Koharu's reading tip

AWS Europe (London) renewed its United Kingdom Police-Assured Secure Facilities (PASF) accreditation for 2026. The Police Digital Service (PDS) confirmed the renewal on May 28, 2026.

For UK law enforcement organizations, this is an important continuation of the assurance needed to run workloads that require PASF in the London Region. But does the phrase "PASF-accredited Region" mean that every system deployed there is automatically compliant?

The short answer is no. The facility layer assessed by PASF must be separated from the data, identity, and application controls owned by the customer. Once that boundary is clear, the announcement reads as evidence of continuing assurance rather than a migration or product-change notice.

The PASF audit covers the facility layer of Europe (London)

PASF is designed to risk-assure locations and facilities where policing-owned data and other information used by policing is held. The PDS Third Party Assurance for Policing (TPAP) page describes a control set of security questions, an on-site inspection, and an audit interview with facility owners or managers.

The assessment is intended to understand site security, business continuity, ownership, and the security posture of the facility's owners or managers. It is therefore assurance of the physical foundation used to hold policing data, not merely a document review.

AWS's general infrastructure documentation lists Europe (London) as Region code eu-west-2 with three Availability Zones. However, the AWS Regions table describes Region infrastructure; it is not the audit evidence that identifies PASF facilities or individual controls. The public renewal post does not enumerate facilities, so procurements and assessments that need precise scope should review the confirmation letter itself.

OFFICIAL-SENSITIVE is not a blanket certification label for a system

The renewal concerns Official-Sensitive data. Here, SENSITIVE is not a separate classification tier; it is a handling caveat applied to some OFFICIAL information. GOV.UK guidance says that risk-appropriate measures depend on the circumstances around the information and warns against treating all sensitive information alike.

The same guidance says organizations should not look for a blanket assurance that a system is "good for OFFICIAL-SENSITIVE." They must apply procedural and personnel controls and make risk-based decisions about technical controls such as access control and audit logging. PASF accreditation is a valuable foundation, but it does not finish the handling decision for an individual system.

PASF and AWS shared responsibility reveal the controls that remain

Under the AWS Shared Responsibility Model, AWS protects the cloud infrastructure, including facilities, while customers manage responsibilities that vary by service, such as data, permissions, operating systems, applications, and network configuration. Physical and environmental controls can be inherited, while areas such as configuration and patch management still include customer responsibilities.

Putting that model beside the PASF facility assessment separates what the 2026 renewal does and does not establish.

Area What the 2026 PASF renewal establishes Decision left to the customer organization
Facilities and environment Facility assurance for Europe (London) continues Match the current confirmation letter's scope to organizational requirements
Data and access The renewal does not define the workload design Design and evidence data classification, IAM, encryption, logging, and sharing boundaries
Application operations No service or API change was announced Manage OS and dependency updates, application configuration, and operating procedures

This does not reduce the value of the accreditation. Inheriting evidence for facility-level controls lets an organization focus its assessment on the controls it owns. The practical point is to keep that boundary explicit.

The 2026 renewal continues assurance that began in 2017

Europe (London) has been accredited under PASF since 2017. PDS confirmed the 2024 renewal on May 24, 2024, the 2025 renewal on May 27, 2025, and the latest renewal on May 28, 2026. This is a recurring reassessment, not the launch of a new AWS feature.

Consequently, the announcement does not ask ordinary AWS customers to change code or move Regions. Its direct relevance is greatest for UK law enforcement organizations, suppliers serving them, and assurance teams that need current PASF evidence.

The repeated confirmation also shows why teams should not assume that an old accreditation remains the right evidence indefinitely. Compliance documents should match the point in time of an architecture review, procurement, or audit.

Pair the Artifact letter with the organization's own control set

The 2026 confirmation letter is available through AWS Artifact. The AWS Artifact documentation explains that security and compliance reports can be downloaded from the console. Where PASF is a requirement, the practical step is to obtain the letter and map its scope and assessment point to the organization's control inventory instead of relying only on the public announcement.

A useful sequence is:

  1. Identify workloads that require PASF from the information handled and the organization's security policy.
  2. Use the 2026 letter in AWS Artifact, or confirmation from PDS, to verify the Region and evidence scope.
  3. Separate inherited facility controls from customer-owned IAM, encryption, logging, and application operations controls.
  4. Return any gaps and accepted risks to the system assurance process.

Separate from facility accreditation, PDS describes the Police Assured Landing Zone (PALZ) as a multi-account foundation combining security, monitoring, and management services. Even with that foundation, PDS says forces must perform their own assurance to assess gaps between the initial landing zone and the finished solution. The same separation applies: facility, cloud foundation, and workload are different layers.

The PASF renewal is a foundation for a cloud decision, not its completion

The 2026 renewal means that AWS Europe (London) continues to provide the facility-level assurance required by UK law enforcement organizations using PASF. For relevant workloads, it preserves an important part of the evidence needed to keep the Region under consideration.

The answer to the opening question is still that accreditation alone does not make the whole system compliant. Teams need to verify what can be inherited from the current confirmation letter, then complete the data, identity, technical, and operational controls appropriate to the risks around their Official-Sensitive information. That is how an accreditation update becomes an actionable cloud decision.

Source

Share

Related Articles

These articles share nearby categories or tags, so you can keep reading along the same thread.