Comparison · Objective · v1.1

Framework Comparison

An honest, capability-based look at how WAF++ fits next to AWS Well-Architected, Azure CAF, the GCP Framework and CNCF. The goal is context, not competition: each framework solves a different slice of the cloud puzzle.

8
Pillars
83+
Controls
50+
Frameworks mapped
15+
Countries / regions
Unique to WAF++

Where WAF++ stands apart

Six capabilities that no other framework in this comparison covers fully — the reasons WAF++ exists alongside them, not instead of them.

Sovereignty as a first-class pillar Only WAF++

Data residency, vendor lock-in avoidance and exit strategies are not an afterthought — Pillar 7 is sovereign by design and scoreable.

Agentic controls New in v1.1

Identity, governance, guardrails and observability for autonomous AI agents — covered by WAF-AGN-010 through WAF-AGN-100.

Full auditability via RFCs

Every rule and decision is traceable through a public RFC with evidence. Provider frameworks update silently; WAF++ requires justification.

Neutral assessment + open governance

CNCF has open governance but no assessment. Provider frameworks assess, but are vendor-bound. WAF++ is the only option with both.

Open-source CLI: WAFPass v1.1.0

Run assessments locally, export evidence and track posture over time. Apache 2.0 code, CC BY 4.0 docs, with Docker Compose in minutes.

83+ vendor-neutral controls

Security, cost, operations, reliability, performance, sustainability, sovereign and agentic — all mapped across providers.

At a glance

Side-by-side comparison

Ten criteria across five frameworks. WAF++ is highlighted to show where it uniquely adds value.

Criterion WAF++ v1.1 AWS WA Azure CAF GCP Framework CNCF
Vendor-neutral Yes No No No Yes
Open governance (TSC / Maintainers / WGs) Yes No No No Yes
Assessment framework & scoring Yes Yes Yes Yes No
Multi-cloud focus Yes Partial Partial Partial Yes
Sovereignty & exit capability as a pillar Yes No No No Partial
Agentic AI controls (identity, guardrails, observability) Yes No No Partial Partial
Auditability & traceability (evidence, RFCs) Yes Partial Partial Partial Partial
Open source & open license Apache 2.0 + CC BY 4.0 Proprietary Proprietary Proprietary Open
CLI assessment tool WAFPass v1.1.0 Provider tools Advisor Partial No
Provider-specific implementation guidance Cross-provider Deep Deep Deep No
Yes / explicit Partial / context-dependent No / not a primary objective
How to read this

What does this mean in practice?

The table shows coverage, not a winner. Pick the right tool for the job — and let WAF++ handle the parts the others leave open.

01
You need provider-specific implementation

AWS WA, Azure CAF and GCP Framework are the right choice for deep, service-aligned guidance within a single provider. They know their products — use that. WAF++ is not a replacement.

02
You need vendor-neutral governance

When architectural decisions span providers — or must survive a future migration — WAF++ gives you a neutral lens: principles, evidence and traceable decisions independent of today's provider.

03
You are adopting agentic AI

Only WAF++ ships a dedicated agentic pillar with controls for identity, guardrails and observability. Use it alongside provider AI services to keep autonomy, compliance and accountability in check.

Next step

Ready to go deeper?

Read the full positioning context, explore the 8 pillars or install WAFPass locally to run your first assessment.