FedRAMP Compliant Terraform Modules
Enforced Before terraform apply
The FedRAMP Moderate baseline (Rev 4) includes 325 NIST 800-53 controls. The subset tied to AWS infrastructure configuration is enforced before deployment, so your 3PAO assessment starts clean.
If you sell cloud services to US federal agencies, FedRAMP authorization is required. The Moderate baseline (325 controls) covers most SaaS applications that handle non-classified government data.
96
Mapped Controls
70 enforced by modules
98
Clauses
35
AWS Modules
No credit card or AWS account needed to start.
From the maintainer of terraform-aws-modules - 2B+ downloads.
Three Steps to FedRAMP Compliant Infrastructure
For terraform-aws-modules users, migration is a one-line change. Same workflow, same interface. Bringing your own modules? We can make those compliant too. Join the beta.
Change One Line
Run Terraform Commands
Compliance Enforced
Controls with module coverage are enforced automatically. Enforced controls ship as compliant defaults; mapped controls without module coverage stay visible for your team.
Controls Mapped for FedRAMP
96 controls mapped, 70 enforced by modules, across 98 clauses and AWS services
Enforced: the module configures this by default. Detected: mapped for visibility and evidence, not set by the module.
Additional Controls
50 additional controls mapped for FedRAMP
FedRAMP Scope: What We Handle vs. What You Own
compliance.tf handles the infrastructure configuration layer for FedRAMP. Here is what it covers and what stays with your team.
compliance.tf Enforces for FedRAMP
- Infrastructure-level FedRAMP Moderate baseline controls
- NIST 800-53-based control mapping with specific control IDs
- Deployment-time evidence generation via AWS-native tools
- Upstream module updates (terraform-aws-modules kept in sync)
- Exception management with audit trail
- Control documentation and baseline mapping matrices
Your Team Still Handles for FedRAMP
- 3PAO assessment engagement and coordination
- System Security Plan (SSP) documentation
- Plan of Action and Milestones (POA&M) management
- Continuous monitoring program implementation
- Incident response and reporting to FedRAMP PMO
- Personnel security and access authorization
- Physical and environmental protection controls
compliance.tf covers the technical infrastructure controls in the FedRAMP Moderate baseline. Your 3PAO still assesses your full authorization boundary, but the infrastructure configuration layer is already compliant.
Operational Rules (lifecycle blocks, tagging, instance restrictions) are also applied alongside FedRAMP compliance controls.
FedRAMP Audit Evidence - Built Into Your Workflow
Your auditor does not need to trust compliance.tf. Evidence comes from AWS-native tools they already accept.
Evidence your auditor already trusts
Every compliance.tf module enforces controls before terraform apply. When AWS Config, Security Hub, or Audit Manager evaluates your resources, they report clean findings because the controls are built into the modules, not bolted on after the fact.
- AWS Config rules validate resource configuration continuously
- Security Hub aggregates findings across accounts and regions
- Audit Manager generates assessment reports mapped to FedRAMP
- Downloadable control mapping matrices for your auditor
Prevention vs. Detection for FedRAMP
compliance.tf prevents non-compliant deployments. Scanning tools detect them after the fact. Most mature programs use both.
| Dimension | IaC Scanning Checkov / Trivy / Prowler | Compliance.tf |
|---|---|---|
| Prevents non-compliant configs before terraform apply | No (post-plan scan) | Yes |
| Maps controls to framework clause IDs | Partial | Yes |
| Produces auditor-accepted evidence (AWS-native) | Scan reports only | Yes |
| Exception management with audit trail | Suppression rules | Yes |
| Same interface as terraform-aws-modules | N/A | Yes |
| Keeps pace with upstream module updates | N/A | Yes |
| Catches runtime drift / console changes | Yes | No |
| Covers non-Terraform resources | Yes | No |
| Internal engineering time | Medium | Low |
We recommend keeping scanning tools active alongside compliance.tf for defense in depth. The scanner validates what compliance.tf already enforces.
FedRAMP Compliance Questions
Which FedRAMP baseline does this cover?
Does this help with FedRAMP authorization?
How is this different from Checkov, Trivy, or Prowler?
Can I adopt this gradually, or is it all-or-nothing?
Will my auditor accept this as evidence?
What if I want to switch back or compliance.tf shuts down?
Start Deploying FedRAMP-Compliant Infrastructure
$1,000/year for all 35 modules, all frameworks. 30-day free trial.
No credit card required. Switch back at any time.
Or browse the FedRAMP registry first - no signup needed: fedrampmoderate.compliance.tf
Stay Informed About New Features
Join the mailing list for releases, new modules, and roadmap updates. No spam. Unsubscribe anytime.
Not convinced yet, or missing a feature you need? Send us an email - we really want to hear your feedback!