Drop-in replacements for supported terraform-aws-modules that enforce SOC 2, PCI DSS, HIPAA, and NIST 800-53 controls at the module level. Change one source line - the resources that the module creates are compliant on apply. No new CLI or policy engine. Works alongside Checkov, Trivy, and AWS Security Hub.
Compliance.tf modules are built on terraform-aws-modules. The upstream modules let you configure security settings. Compliance.tf modules enforce them. Encryption, versioning, logging, and access controls are locked at the module level for the compliance framework you choose.
To adopt, change your module source from registry.terraform.io to soc2.compliance.tf (or pcidss.compliance.tf, hipaa.compliance.tf, nist800-53.compliance.tf). Inputs and outputs stay compatible. Your CI/CD pipeline and scanning tools keep working - compliance.tf does not replace them.
Within the module interface, developers cannot turn off enforced settings. Scanners like Checkov or Trivy evaluate Terraform after it is written and report findings. Compliance.tf removes non-compliant options from the module interface, so those violations cannot be introduced through module inputs.
Validation reports map each enforced control to its framework clause ID. Reports can be exported for use in AWS Audit Manager or GRC tools like Vanta and Drata.
Migrate one module at a time. Compliance.tf modules produce standard Terraform state, so teams can switch back to the upstream source at any time.
Supported framework mappings: SOC 2, PCI DSS v4.0.1, HIPAA Security Rule, NIST 800-53. See docs.compliance.tf for the current list of supported modules and controls.
Highlights
Change your module source from registry.terraform.io to soc2.compliance.tf. Inputs and outputs stay compatible. Your CI/CD pipeline works without changes.
Security settings like encryption, versioning, and access controls are enforced inside the module. Developers cannot turn them off through module inputs.
Validation reports map each enforced control to its framework clause ID. Export to AWS Audit Manager or GRC tools like Vanta and Drata.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This contract offers two billing dimensions. Module Downloads bills by the count of Terraform module downloads in each billing period, so your cost tracks how often you pull modules. Full Access is a fixed contract that covers 34+ compliance frameworks, including CIS, SOC 2, HIPAA, PCI DSS, NIST, NIS2, and FedRAMP. It seats up to 25 team members, allows unlimited downloads, and includes email support. Choose Module Downloads if usage varies and you want to pay per download. Choose Full Access for a set team size with no download limit.
Top-of-mind questions for buyers
What counts as one module download for billing under the Module Downloads dimension?
Each time you pull a Terraform module from the private registry counts as one download. The count includes every module version you retrieve during the billing period. Modules span 35 options across storage, compute, networking, databases, security, messaging, integration, and observability categories.
How do the Module Downloads and Full Access dimensions differ in how my cost behaves?
Module Downloads meters actual download count, so your bill rises as you pull more modules. Full Access is a fixed contract with unlimited downloads for up to 25 team members. Module Downloads suits variable pulling; Full Access suits steady, high-volume use with a set team.
Do the modules keep working if my license or contract ends?
Modules you already downloaded continue to work under a perpetual license, even after your license expires. You lose registry access and stop receiving updates or new versions. If termination results from a breach rather than expiration, you must stop using and delete all copies.
compliance.tf+1
Helpful?
Vendor refund policy
All sales are final
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support is available with a 2-business-day response time. Contact us at https://compliance.tf/contact for assistance.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Cloud Posse provides a comprehensive reference architecture for AWS that encompasses everything from foundational infrastructure and security to the platform and what sits on top of it. We provide a comprehensive release engineering strategy for continuous integration and delivery, as well as SRE practices you need to be successful. Pick and choose what you need. It's all available today and ready to go.
Enterprises running AWS at scale accumulate fragmented account structures through growth, mergers and restructuring, creating security risk from shared accounts, over-privileged roles and inconsistent MFA, alongside increasing compliance exposure.
Computacenter’s serverless AWS migration framework replaces manual migration with a repeatable AWS-native approach using Step Functions, Lambda and Terraform. State machines inspect dependencies, encrypt snapshots and generate validated infrastructure-as-code templates for team review before deployment, ensuring every migrated workload has a version-controlled foundation.
Relevant for organisations undertaking consolidation, divestiture or remediation, the framework is proven at scale, including the migration of 269,000 assets with zero downtime, providing a pre-built capability that reduces delivery cost and accelerates transition to a governed AWS operating model.
Infrastructure as Code consulting and implementation services for AWS environments. QBurst designs and implements IaC frameworks using AWS CloudFormation, CDK, Terraform, and Pulumi to enable automated, repeatable, and auditable infrastructure provisioning across enterprise environments.
The Cloud Governance Accelerator is a consultative design and implementation project that creates a secure multi-account AWS environment based on AWS Control Tower. It is designed for both "greenfield" customers who want to start correctly from day one and "brownfield" customers with existing, complex AWS accounts that need structure, compliance, and security - without a disruptive rebuild.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.