On this page
TLDR
Compliance is a match-the-surface-to-the-regime exercise: an architect picks the deployment surface (API direct, AWS Bedrock, GCP Vertex, Microsoft Foundry, Claude for Government) and account tier the workload requires, then explicitly turns on the controls that are not on by default. HIPAA BAA coverage is admin opt-in, not automatic, and has three distinct paths (Enterprise self-activation, sales-enabled API, or the cloud provider's own BAA on Bedrock/Vertex), and FedRAMP High/DoD IL4-5 is tied to specific US-only surfaces that are not simultaneously combinable with an EU-resident deployment on the same workload. Anthropic Trust Center
What it is
An architect's compliance job is to match the deployment surface an organization uses, API direct, AWS Bedrock, GCP Vertex, Azure/Microsoft Foundry, or Claude for Government, and the account tier, to the regulatory regime the workload requires, then explicitly enable the controls that are not on by default. Anthropic's compliance posture is real but conditional: several protections require administrator action rather than automatic inclusion, and the exact certification set differs for consumer versus commercial products.
This is a verify the current tier's paperwork discipline, not a one-time checkbox. GDPR, HIPAA, and FedRAMP are three different kinds of regime, a legal framework, a US healthcare law with a contractual mechanism (the BAA), and a federal authorization program, and each maps to a different artifact or deployment path rather than one universal "Anthropic is compliant" answer.
How it works
Commercial certification baseline. Anthropic's commercial products, Claude for Work and the Anthropic API, maintain HIPAA-ready configuration (BAA available), ISO 27001:2022, ISO/IEC 42001:2023 (AI Management Systems), and SOC 2 Type I & II. These are explicitly scoped to commercial products, not consumer plans, a team prototyping on a free or consumer account cannot point to this certification set at all, regardless of what it builds.
HIPAA BAA coverage is opt-in, and it has three genuinely different paths, not one workflow with two names. (1) On Claude Enterprise, an administrator self-activates HIPAA compliance under "Data & Privacy" admin settings and signs Anthropic's BAA directly, standard Enterprise plans do not include this automatically. (2) On the direct 1P API, BAA eligibility is a *separate*, sales-mediated path: the organization's administrator signs Anthropic's BAA and then has to contact Anthropic sales to get it turned on, it is not the same self-service toggle as Enterprise. (3) Via a cloud-provider surface (AWS Bedrock, GCP Vertex), coverage runs under that provider's own BAA (the AWS or Google Cloud Business Associate Addendum), not Anthropic's BAA at all, the model provider never sees the raw prompts/completions in that path. Conflating the Enterprise activation workflow with API BAA eligibility, or assuming either one covers a Bedrock/Vertex deployment, is a live compliance gap: a healthcare workload touching PHI before the *specific* path's activation step is complete is uncovered, independent of which model or feature is in use.
FedRAMP High and DoD IL4/5 live on a different surface, not a policy toggle, and that surface is not freely combinable with an EU-resident deployment for the same workload. Claude models are approved for FedRAMP High and DoD Impact Level 4/5 workloads via Amazon Bedrock in AWS GovCloud (US) regions, and Anthropic separately offers Claude Gov models for classified environments plus a dedicated Claude for Government application at FedRAMP High, all US-only, isolated surfaces. EU data/inference residency is a *different* regional deployment (available across AWS Bedrock, GCP Vertex, and Microsoft Foundry EU regions). A single workload runs in one geographic surface at a time, so "FedRAMP High AND EU-resident" isn't a combinable pair of controls on one deployment, it describes two separate workloads on two separate surfaces. Reaching the federal regime means routing through a GovCloud/Government surface, not requesting paperwork against the standard commercial API.
Regional residency and GDPR run on a DPA plus a data-location choice. GDPR itself is not an Anthropic certification but a legal regime; the load-bearing artifact for an EU deployment is typically the Data Processing Addendum governing Anthropic's role as processor, combined with a regional data-residency choice available across AWS Bedrock, GCP Vertex, and Microsoft Foundry. Architects should verify current DPA terms against the live document rather than assume blanket "GDPR compliant" status.
The Trust Center is the canonical, living source. trust.anthropic.com hosts the current SOC 2 Type 2 and CSA STAR L2 reports, the DPA, and security-control documentation, request-gated rather than fully public. Because certifications and terms change, the compliance check is per-deployment verification against that live source, not a fact memorized once.

Where you'll see it
Healthcare clinical-notes summarizer
Use Claude for Work/Enterprise or the API, never a consumer plan; have an administrator explicitly enable HIPAA compliance and execute the BAA before any PHI touches the system; choose a regional deployment matching data-residency requirements.
Federal internal research assistant
Route through Bedrock GovCloud or Claude for Government to land inside the FedRAMP High / IL4-5 boundary, a fundamentally different deployment path than the healthcare case, not just a policy toggle on the same one.
Side-by-side
| Surface | Geography | HIPAA path if PHI involved | FedRAMP High / IL4-5? | Combinable with EU residency on the same workload? |
|---|---|---|---|---|
| Claude for Work / Enterprise (admin BAA) | Anthropic-hosted, region per Anthropic's offering | Path 1 - admin self-activates under Data & Privacy, signs Anthropic BAA | No | N/A - not the FedRAMP surface |
| Direct 1P API (sales-enabled BAA) | Anthropic-hosted | Path 2 - admin signs Anthropic BAA + contacts sales to enable | No | N/A - not the FedRAMP surface |
| AWS Bedrock / GCP Vertex (regional) | Region-selectable, incl. EU | Path 3 - covered under the cloud provider's own BAA, not Anthropic's | No (this is the commercial regional path, not GovCloud) | Yes - this IS the EU-residency surface |
| AWS Bedrock in AWS GovCloud (US) | US-only, isolated | Covered under AWS's GovCloud BAA where applicable | Yes | No - GovCloud (US) and EU-resident Bedrock are different, non-overlapping regions |
| Claude for Government / Claude Gov models | US-only, isolated | Government-contract terms, not the standard BAA paths above | Yes | No - a separate, US-only surface |
Decision tree
Does the workload process Protected Health Information (PHI)?
Does the workload need to sit inside a FedRAMP High or DoD IL4/5 boundary?
Does the same workload ALSO need FedRAMP High/IL4-5 AND EU-resident data/inference at once?
Does the workload require EU or cross-border data-residency guarantees?
Is the workload currently running on a consumer Claude plan rather than Claude for Work/Enterprise/API?
How each cert tests this
CCA-P
CCARP-D5-O4 (Governance, Safety & Risk, 14%): tests matching deployment surface, API direct, Bedrock GovCloud, Enterprise plus admin-activated BAA, or a regional choice, to the specific regulatory regime a workload requires, and knowing which controls need explicit activation versus which are automatic.
CCA-A
CCAOF-D6-O2 (Governance, Risk & Responsible Use, 15%): tests applying data-sensitivity, regulatory, and privacy considerations at the business-user level, recognizing when a task touches PHI, regulated data, or cross-border residency before routing it to Claude, without necessarily architecting the deployment surface.
Question patterns

A healthcare startup is on Claude's standard Enterprise plan and starts processing PHI without any additional setup. Are they covered by a BAA?
"Enterprise plans always include HIPAA BAA coverage by default" - the opposite of Anthropic's documented opt-in mechanism.A team already has an Anthropic BAA signed for their Claude Enterprise seats. They now start sending PHI through the direct 1P API for a separate batch-processing pipeline. Does the Enterprise BAA cover the API usage?
"one signed BAA with Anthropic covers all surfaces, Enterprise and API alike" - it conflates two distinct activation workflows into one.A federal agency wants a FedRAMP High / DoD IL4-5 workload and is currently calling the standard Anthropic API directly. What is the compliance gap?
"request FedRAMP paperwork for the existing API deployment" - the gap is the deployment surface itself, not missing paperwork layered onto the same one.An architect tells a customer "we're GDPR compliant because we use Claude." What's wrong with that claim?
"GDPR compliance is bundled automatically into every commercial Claude plan" - no such blanket certification exists in Anthropic's documented posture.A team needs to show SOC 2 Type II compliance to a security-sensitive customer but is prototyping on a free consumer Claude plan. What has to change first?
"SOC 2 coverage applies to any Claude usage, including consumer plans" - directly contradicted by the documented scoping.A workload needs PHI handling, FedRAMP High authorization, AND EU data residency, all for the same single deployment. Can an architect combine all three on one surface?
"picking the highest-tier surface (FedRAMP High) automatically satisfies EU residency too" - FedRAMP High is a US-only surface; it does not satisfy an EU-residency requirement at all.Frequently asked
Does using the Anthropic API automatically give me a HIPAA BAA?
If I use Claude via AWS Bedrock or GCP Vertex, do I need Anthropic's BAA?
Can one deployment be both FedRAMP High and EU data-resident?
Where do I find current compliance artifacts like SOC 2 reports or the DPA?
Work this with your AI
Work this concept hands-on with Claude Code, Codex, or claude.ai. Copy a prompt, paste it into your assistant, and practise in tandem. Each one keeps you active (explain it back, get drilled, or build) rather than just reading.
- Drill it like the exam (scenario MCQs)Practice in the exam's scenario-MCQ format with trap awareness.
- Explain it back (Feynman)Build durable, transferable understanding of a concept you can half-state.
- Test me, adapting the difficultyActive recall practice on a concept you think you know.
- Check my prerequisites firstBefore studying a concept that keeps not sticking.
- Find the high-leverage 20%When a domain feels too big and you are short on time.
