AWS Security Testing: What Needs Prior Approval and What Does Not

When you run a vulnerability assessment or penetration test against systems on AWS, where the line falls between what needs prior approval and what does not is easy to get wrong. This article sets out what AWS's official policy page said when it was checked on 4 August 2026. The policy is revised over time, so always read the current official version yourself before testing.

Please read first: this article summarises what the official AWS page "AWS Customer Support Policy for Penetration Testing" said when it was checked on 4 August 2026. The policy can change without notice. Do not decide whether testing is permissible on the basis of this article alone. Read the current official page yourself before testing, and contact AWS Support or your account representative if anything is unclear.
Official page: https://aws.amazon.com/security/penetration-testing/
Note that at the time of checking, the page carried no "last updated" date. There is no way to detect a revision other than by comparing the page text directly.

What exactly does "no prior approval" cover?

The opening of the official page states that customers may carry out security assessments or penetration tests of their own AWS infrastructure without prior approval for the services listed under "Permitted Services". In other words, the request form that used to be required is no longer needed for those services.

That exemption is not unconditional. At the time of checking, the page carried at least three accompanying constraints.

Services listed as testable without prior approval

At the time of checking, the "Permitted Services" list read as follows, in the page's own order.

#Service (as written)
1Amazon EC2 instances, WAF, NAT Gateways, and Elastic Load Balancers
2Amazon RDS
3Amazon CloudFront
4Amazon Aurora
5Amazon API Gateways
6AWS AppSync
7AWS Lambda and Lambda Edge functions
8Amazon Lightsail resources
9Amazon Elastic Beanstalk environments
10Amazon Elastic Container Service
11AWS Fargate
12Amazon OpenSearch Service
13Amazon FSx
14Amazon Transit Gateway
15Amazon Bedrock AgentCore

For anything not on the list, the page states: "Customers seeking to test non approved services will need to work directly with AWS Support or your account representative." So services absent from the list are handled by talking to AWS directly. The list is added to and revised, so always check the live page before testing.

Activities listed as prohibited

The "Prohibited Activities" section listed the following at the time of checking.

A further sub-list, "Prohibited Services for Outbound Penetration Testing", named Amazon API Gateway and Amazon Bedrock AgentCore. Note that API Gateway appears both among the permitted services and in this outbound prohibition, so take care not to conflate the two.

DoS is prohibited even against your own assets: the policy says you are not limited in your choice of tools, but that "you ARE prohibited from utilizing any tools or services in a manner that perform Denial-of-Service (DoS) attacks or simulations of such against ANY AWS asset, yours or otherwise." Read plainly, DoS and simulated DoS are off limits even against your own resources in your own account. This is an easy point to get wrong.

The policy also drew some related distinctions.

What the page says needs a form submitted in advance

Under "Other Simulated Events", the page stated that a Simulated Events form must be submitted for the following.

ActivityHow the page treats it
Red / Blue / Purple Team testing, and hosting C2Simulated Events form required
Simulated phishingSimulated Events form required
Malware testingSimulated Events form required
iPerf measurementSimulated Events form required
Network stress testing / load testingDirected to review the Stress Test policy
DDoS simulationDirected to review the DDoS Simulation Testing policy

The submission is expected to include dates, the account IDs involved, the assets involved, contact information including a phone number, and a detailed description of the planned events. A non-automated acknowledgement is said to arrive within two business days, and "All Simulated Event requests must be submitted to AWS at least two (2) weeks in advance of the start date." After authorisation, the page states that no further action is required and testing may run through the end of the period indicated.

Requests go through a Support console form, not email. The link targets at the time of checking were:

Responsibilities the page places on the tester

A checklist to use while reading the official page

Do not launch tests against production on the strength of this article. With that said, here are the questions worth answering against the live policy.

  1. Is the target service on the current Permitted Services list?
  2. Is the scope strictly your own assets, with no multi-tenant neighbours or third-party-managed assets mixed in?
  3. Do your tools include any DoS-equivalent capability, and if so can it be reliably disabled?
  4. Does the plan involve C2, simulated phishing, malware testing or load testing? If so the page states a form is required at least two weeks in advance.
  5. Do you have internal approval, sign-off from the system owner and a record-keeping plan? (These sit outside the AWS policy but are still necessary.)

Sources and date checked

No other source was used. Quotations reproduce the original wording, and anything that could not be verified has been left out.

Frequently Asked Questions

Do I need prior approval to run a penetration test on AWS?

The official AWS page states that customers may carry out security assessments of their own AWS infrastructure without prior approval for the services listed under Permitted Services (checked 4 August 2026). Services not on that list are handled by working directly with AWS Support or an account representative. The policy is revised over time, so check the current official page before testing.

Can I run a DoS test against resources in my own account?

The official policy states that using tools or services in a manner that performs denial-of-service attacks or simulations of such against any AWS asset, yours or otherwise, is prohibited (checked 4 August 2026). Tools that have such a capability are required to be able to disable it.

How far in advance must a Simulated Events form be submitted?

The official page states that all Simulated Event requests must be submitted to AWS at least two weeks in advance of the start date (checked 4 August 2026). A non-automated acknowledgement is said to arrive within two business days.

May I test the security of AWS services themselves?

The official page states that customers are not permitted to conduct security assessments of AWS infrastructure or the AWS services themselves. If you discover a security issue in an AWS service during your assessment, you are asked to contact AWS Security immediately (checked 4 August 2026).

← Back to Tech Blog