Overview

Product video
Compliance.tf modules are built on terraform-aws-modules. The upstream modules let you configure security settings. Compliance.tf modules enforce them. Encryption, versioning, logging, and access controls are locked at the module level for the compliance framework you choose.
To adopt, change your module source from registry.terraform.io to soc2.compliance.tf (or pcidss.compliance.tf, hipaa.compliance.tf, nist800-53.compliance.tf). Inputs and outputs stay compatible. Your CI/CD pipeline and scanning tools keep working - compliance.tf does not replace them.
Within the module interface, developers cannot turn off enforced settings. Scanners like Checkov or Trivy evaluate Terraform after it is written and report findings. Compliance.tf removes non-compliant options from the module interface, so those violations cannot be introduced through module inputs.
Validation reports map each enforced control to its framework clause ID. Reports can be exported for use in AWS Audit Manager or GRC tools like Vanta and Drata.
Migrate one module at a time. Compliance.tf modules produce standard Terraform state, so teams can switch back to the upstream source at any time.
Supported framework mappings: SOC 2, PCI DSS v4.0.1, HIPAA Security Rule, NIST 800-53. See docs.compliance.tf for the current list of supported modules and controls.
Highlights
- Change your module source from registry.terraform.io to soc2.compliance.tf. Inputs and outputs stay compatible. Your CI/CD pipeline works without changes.
- Security settings like encryption, versioning, and access controls are enforced inside the module. Developers cannot turn them off through module inputs.
- Validation reports map each enforced control to its framework clause ID. Export to AWS Audit Manager or GRC tools like Vanta and Drata.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Description | Cost/12 months |
|---|---|---|
Full Access | 34+ compliance frameworks including CIS, SOC 2, HIPAA, PCI DSS, NIST, NIS2, and FedRAMP. Terraform AWS modules with compliance controls applied per framework. 25 team members, unlimited downloads, email support. | $1,000.00 |
Bring Your Own Modules | Point your own Terraform modules at compliance.tf. Controls from any subscribed framework are applied and reported the same way as built-in modules. Requires Enterprise. | $0.00 |
Enterprise | Everything in Full Access. Custom compliance frameworks, SSO/SAML login, unlimited team members, priority support. Contact sales@compliance.tf for pricing. | $0.00 |
Priority Support | Direct access to the engineering team for integration and deployment questions. Guaranteed response times. Add-on to any paid plan. | $0.00 |
The following dimensions are not included in the contract terms, which will be charged based on your usage.
Dimension | Description | Cost/unit |
|---|---|---|
Module Downloads | Count of Terraform module downloads per billing period. | $10.00 |
Vendor refund policy
All sales are final
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Support is available with a 2-business-day response time. Contact us at https://compliance.tf/contact for assistance.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.