Skip to content

Compliance-Ready Terraform Modules

Drop-in replacements for terraform-aws-modules with compliance controls enforced by default. Change the source URL — same interface, same arguments, same outputs.

34 modules · 300+ controls · 36 frameworks


How It Works

  1. Pick your framework — SOC 2, PCI DSS, CIS, HIPAA, NIST, and 30+ more
  2. Change the source URL — from terraform-aws-modules/... to soc2.compliance.tf/...
  3. Run terraform plan — controls are validated automatically at plan time

Storage

Compute & Containers

Networking & Edge

Databases, Caching & Analytics

DMSDatabase Migration Service replication instances, source and target endpoints, replication tasks, subnet groups, logging, and controlled network placement for data migration. 3 controls16 frameworksDynamoDB TableDynamoDB tables with server side encryption, point in time recovery, TTL, streams, autoscaling, global tables, IAM access controls, and backup oriented settings. 4 controls20 frameworksElasticacheRedis or Memcached clusters and replication groups with subnet groups, security groups, transit and at rest encryption, auth tokens, parameter groups, and automatic failover. 6 controls19 frameworksEMREMR clusters and instance groups with security configurations, encryption in transit and at rest, Kerberos, IAM roles, bootstrap actions, logging, and deployment in private subnets. 2 controls9 frameworksOpenSearchOpenSearch domains with VPC placement, encryption at rest, node to node encryption, fine grained access control, audit logs, TLS enforcement, and snapshot configuration. 11 controls21 frameworksRDSRDS instances with subnet groups, security groups, storage encryption, automated backups, maintenance windows, performance insights, IAM authentication, and log exports. 19 controls27 frameworksRDS AuroraAurora clusters and instances with private subnet placement, storage encryption, automated backups, reader endpoints, IAM authentication, log exports, and multi AZ high availability. 10 controls15 frameworksRedshiftRedshift clusters or serverless workgroups with VPC networking, encryption, audit logging, snapshot settings, parameter groups, enhanced VPC routing, and controlled access. 13 controls23 frameworks

Security, Keys & Configuration

Messaging & Streaming

API & Application Integration

Observability