What is compliance-as-code?
Compliance-as-code means writing regulatory and security requirements as code kept under version control, which automated tooling then evaluates so that infrastructure gets checked against those requirements prior to or during deployment.
How it works
Take a requirement like "data at rest must be encrypted". It begins as prose inside a framework such as SOC 2, PCI DSS or HIPAA, and compliance-as-code converts it into a technical check. That check sits in a repository alongside the infrastructure code and executes on every change. It can live in three common places:
| Approach | Where the check runs | What happens on a violation |
|---|---|---|
| Policy-as-code | A policy engine evaluates the Terraform plan | The plan gets rejected |
| IaC compliance scanning | A scanner inspects HCL or plan JSON in CI | A finding is raised |
| Controls built into modules | The module itself, during terraform plan | The plan fails with a validation error |
Since the checks themselves are code, they are reviewed, versioned and reproducible. An auditor can then see a record of which rule applied to which change, rather than a policy document that might not reflect what was actually deployed.
How compliance.tf applies it
compliance.tf places the controls directly inside the Terraform module. Every module served from a framework endpoint works as a drop-in replacement for the matching terraform-aws-modules module, and it carries that framework's controls as built-in module defaults together with input validation. When a value violates a control, terraform plan fails, and the error identifies the control along with the frameworks that require it.
module "logs" {
source = "soc2.compliance.tf/terraform-aws-modules/s3-bucket/aws"
version = "~> 5.0"
bucket = "example-logs"
}With a framework endpoint, the controls are versioned together with the module, so pinning an exact module version pins the controls enforced by that version as well.
Limits
Technical configuration is the scope of compliance-as-code. Organizational, HR, physical, incident-response and access-management controls still demand their own evidence, and compliance.tf enforces controls only on resources created through its modules. See compliance scope boundary.