The exact split shifts by service model: with IaaS the customer owns more of the stack (OS, middleware, data); with SaaS the provider owns more, leaving the customer mainly identities, access, and data. Every provider publishes its own model, and the boundary is always documented per service — never assumed.
Key points
Per-service mappingThe split differs between IaaS, PaaS, SaaS, and even between individual services from the same vendor.
Non-delegable partsIdentity, access rights, data classification, configuration, and usage remain the customer’s in every model — provider certifications do not cover them.
Important limitation“Shared” does not mean “halved.” Breaches blamed on providers often trace to customer-side configuration, credentials, or data decisions — the model describes who is accountable, not who is at fault when something fails.