Cloud Shared Responsibility Mapper
For whoever has to tell the assessor which controls are yours

Paste the cloud services you use. See which controls are yours, the provider's, or shared.

Specimen: an invented 600-person software company8 of its 36 services, 14 control areas

Swipe sideways for all 14 areas.

ServiceGOVIAMDATKEYNETLOGVULCFGAPPINCBCPPHYSUPAIR
S1 Virtual machines for the claims APIsharedyoursyoursyoursyoursyoursyoursyoursyourssharedyoursthe provider'ssharedyours
S2 Virtual machines for batch reportingsharedno ownerno ownerno ownerno ownerno ownerno ownerno ownerno ownersharedno ownerthe provider'ssharedno owner
S7 Object storage buckets holding customer filessharedyoursyoursyourssharedyoursyoursyoursyourssharedyoursthe provider'ssharedyours
S10 Managed relational databasesharedyoursyourssharedsharedsharedsharedsharedyourssharedsharedthe provider'ssharedyours
S16 Hosted LLM API for the support chatbotsharedyoursyourssharedsharedsharedthe provider'ssharedsharedsharedsharedthe provider'ssharedyours
S19 Identity provider (SSO)sharedyoursyoursthe provider'sthe provider'ssharedthe provider'ssharedthe provider'ssharedsharedthe provider'ssharedshared
S22 Managed firewallsharedno ownerno ownersharedrun by the MSPsharedsharedsharedno ownersharedsharedthe provider'ssharedno owner
S30 CRMsharedsharedyoursthe provider'sthe provider'ssharedthe provider'ssharedthe provider'ssharedsharedthe provider'ssharedshared

36 services, 38 controls nobody owns.

yoursno ownerthe provider'ssharedMSP

504 bays: 159 yours, 67 the provider's, 246 shared, 4 run by the MSP, 28 not drawn.

Cloud Shared Responsibility Mapper reads your list of cloud services and maps the shared responsibility model onto it, service by service and control area by control area. Paste the cloud services you use. Get a shared responsibility map per service and control area, what the provider owns, what you own and what is shared, with the Cloud Controls Matrix, ISO/IEC 27017 and 27018 clauses behind each split, and the customer-owned controls nobody has named.

Paste service names and service models only: no account ids, no architecture, nothing from inside your cloud. The list is read in your browser and nothing is stored until you save.

Pick your frameworks and, for CMMC, your level: the split is shown for what you are assessed against.

The split follows the published shared responsibility model for each service model, with the clause behind it. Check it against your provider's own documentation before you hand it to an assessor.

Map your own servicesEight services free, no account. A published dictionary of 48 service categories, 14 control areas and the clause text load with the page; every split is drawn in your browser.
An engineer at his desk reading code on a monitor in an open office
Go into the SOC 2, CMMC or ISO/IEC 27001 assessment with a named owner against every control your cloud leaves to you, and the clause that puts it there. It works from the service list you already keep: no account access to grant, no provider documents to reconcile by hand, no workshop to wait weeks for.
01

Paste the service list you already keep

One service per line: the name alone, or with any of provider, service model, region, data classification, CMMC scope, SOC 2 scope, owner, MSP and notes. Each is placed on one of 48 published service categories; a line that matches none is marked unplaced and never guessed. Anything that looks like an account id, a resource name, an address, a hostname or a key is removed before it is read.

02

Read the responsibility plan

Every service a strip, every control area a bay: edged red where the shared responsibility model makes it yours, shaded where the provider retains it, hatched where it is shared. A bay that is yours with no owner on the line carries a red corner: the orphaned control an assessor finds first.

03

Hand over the customer responsibility matrix

Eleven findings in fixed order, each with the services it names, the clause quoted from the Cloud Controls Matrix, ISO/IEC 27017 and 27018, SOC 2, CMMC, C5 or ISO/IEC 27001, and the question to take to the platform owner. The matrix exports in the columns an assessor expects.

One service per line: Service, or Service | Provider | Model | Data | Owner | Notes, or a CSV export with a header row. Tabs, pipes, commas or double spaces. A first line such as frameworks: SOC 2, CMMC Level 2 | msp: network | as at: 2026-09-25 sets the frameworks, the managed service provider and the date.
Nothing is sent anywhere until you choose to save.
Frameworks you are assessed against (the clauses quoted beside each split)

The Cloud Controls Matrix, ISO/IEC 27017 and the STAR shared responsibility disclosure are always shown: they are the cloud-specific codes that allocate each control.

Why a responsibility plan and not a consultant's workshop

Every provider publishes its side of the shared responsibility model, and every assessor asks for yours: a customer responsibility matrix that names who owns each control on each service. Most estates keep that as a spreadsheet of services with no column for control ownership, so the orphaned control, the one the model makes yours and nobody on your side runs, is found in the assessment. This draws the SSRM over the list you already have, in your browser, with the clause behind every split, and names every orphaned control before the assessor does.

The dictionary is ours and published in full: every service category in nine groups, the fourteen control areas, the split for each service model and the clauses each framework attaches. It reads service names and models only, never connects to a cloud account, and never reproduces a provider's own matrix: the split is ours, from the model and the clauses.