What is OpenTofu compatibility?
OpenTofu compatibility is the property that a Terraform module, registry, or tool runs with OpenTofu, the open-source Terraform fork and a Cloud Native Computing Foundation (CNCF) project, through the shared configuration language and module registry protocol.
Why it matters
OpenTofu split from Terraform in 2023 after HashiCorp revised Terraform's license, and it entered the CNCF as a sandbox project in April 2025. Many teams run one tool or the other, and some run both. A compatible module, plus the registry that distributes it, does not force that choice. HCL, the module registry protocol, and the TF_TOKEN_* credential variables remain common ground; even so, capabilities introduced after the fork may diverge. A module built on a newer capability from one tool can therefore fail on the other. One case: OpenTofu 1.12 permits an expression, such as an input variable, in prevent_destroy; Terraform does not.
What to check
| Area | What to confirm |
|---|---|
| Version floor | The earliest Terraform and OpenTofu releases the module supports |
| Registry access | tofu login succeeds for the registry hostname |
| Language features | No required language feature exists in just one tool |
| CI tooling | Scanners and wrappers parse OpenTofu files and plan output |
How compliance.tf applies it
| Terraform | OpenTofu | |
|---|---|---|
| Supported versions | 1.0 and later | 1.6 and later |
| Login | terraform login soc2.compliance.tf | tofu login soc2.compliance.tf |
| Module source line | The same | The same |
| Operational Rules | Supported | Supported, identical behavior |
compliance.tf modules rely on input validation for control enforcement, a mechanism supported by both tools. ctfkit accepts .tofu files and tofu show -json output alongside the Terraform counterparts.