Listing Thumbnail

    Terraform AWS Modules with Enforced Compliance Controls

     Info
    Deployed on AWS
    Free Trial
    Vendor Insights
    AWS Free Tier
    Drop-in replacements for supported terraform-aws-modules that enforce SOC 2, PCI DSS, HIPAA, and NIST 800-53 controls at the module level. Change one source line - the resources that the module creates are compliant on apply. No new CLI or policy engine. Works alongside Checkov, Trivy, and AWS Security Hub.

    Overview

    Play video

    Compliance.tf modules are built on terraform-aws-modules. The upstream modules let you configure security settings. Compliance.tf modules enforce them. Encryption, versioning, logging, and access controls are locked at the module level for the compliance framework you choose.

    To adopt, change your module source from registry.terraform.io to soc2.compliance.tf (or pcidss.compliance.tf, hipaa.compliance.tf, nist800-53.compliance.tf). Inputs and outputs stay compatible. Your CI/CD pipeline and scanning tools keep working - compliance.tf does not replace them.

    Within the module interface, developers cannot turn off enforced settings. Scanners like Checkov or Trivy evaluate Terraform after it is written and report findings. Compliance.tf removes non-compliant options from the module interface, so those violations cannot be introduced through module inputs.

    Validation reports map each enforced control to its framework clause ID. Reports can be exported for use in AWS Audit Manager or GRC tools like Vanta and Drata.

    Migrate one module at a time. Compliance.tf modules produce standard Terraform state, so teams can switch back to the upstream source at any time.

    Supported framework mappings: SOC 2, PCI DSS v4.0.1, HIPAA Security Rule, NIST 800-53. See docs.compliance.tf for the current list of supported modules and controls.

    Highlights

    • Change your module source from registry.terraform.io to soc2.compliance.tf. Inputs and outputs stay compatible. Your CI/CD pipeline works without changes.
    • Security settings like encryption, versioning, and access controls are enforced inside the module. Developers cannot turn them off through module inputs.
    • Validation reports map each enforced control to its framework clause ID. Export to AWS Audit Manager or GRC tools like Vanta and Drata.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    Terraform AWS Modules with Enforced Compliance Controls

     Info
    Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (4)

     Info
    Dimension
    Description
    Cost/12 months
    Full Access
    34+ compliance frameworks including CIS, SOC 2, HIPAA, PCI DSS, NIST, NIS2, and FedRAMP. Terraform AWS modules with compliance controls applied per framework. 25 team members, unlimited downloads, email support.
    $1,000.00
    Bring Your Own Modules
    Point your own Terraform modules at compliance.tf. Controls from any subscribed framework are applied and reported the same way as built-in modules. Requires Enterprise.
    $0.00
    Enterprise
    Everything in Full Access. Custom compliance frameworks, SSO/SAML login, unlimited team members, priority support. Contact sales@compliance.tf for pricing.
    $0.00
    Priority Support
    Direct access to the engineering team for integration and deployment questions. Guaranteed response times. Add-on to any paid plan.
    $0.00

    Additional usage costs (1)

     Info

    The following dimensions are not included in the contract terms, which will be charged based on your usage.

    Dimension
    Description
    Cost/unit
    Module Downloads
    Count of Terraform module downloads per billing period.
    $10.00

    Vendor refund policy

    All sales are final

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Support

    Vendor support

    Support is available with a 2-business-day response time. Contact us at https://compliance.tf/contact  for assistance.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.