Standard Azure tenancy with customer-managed keys in standard Key Vault. No Confidential Computing. Partial or aspirational EU Data Boundary commitment. Customer Lockbox not enabled. Compliance attestation produced manually for annual audit.
Typical concerns
- ·Auditor flagged key custodianship as inadequate
- ·EU Data Boundary commitment unclear in current architecture
- ·Microsoft engineer access not gated by Customer Lockbox
- ·Confidential Computing not in scope but required for some workloads
- ·Compliance attestation reactive rather than continuous
Capability gaps
- ·Sovereign Landing Zone architecture
- ·FIPS 140-3 Level 3 customer-managed keys
- ·Confidential Computing for the regulated tier
- ·Customer Lockbox enabled
- ·Continuous compliance attestation