Framework · Controls Overview

Controls Showcase

A comprehensive overview of all WAF++ controls, organized by country and regulatory framework coverage. Validate your infrastructure against 73+ controls across 7 pillars.

By Country By Framework All Controls
COUNTRY COVERAGE

Controls by Country / Region

WAF++ controls support compliance with regulations across multiple jurisdictions worldwide.

🇩🇪
Germany (DE)
BSI C5, BSI C3A, IT-Grundschutz, DORA, NIS2, GDPR
29 controls | BSI C3A, DORA, NIS2, GDPR
🇫🇷
France (FR)
ANSSI SecNumCloud, GDPR, DORA, NIS2, EUCS
14 controls | ANSSI, DORA, NIS2, GDPR
🇦🇹
Austria (AT)
BSI C5, GDPR, DORA, NIS2
25 controls | BSI C5, DORA, NIS2, GDPR
🇨🇭
Switzerland (CH)
BSI C5, GDPR, DPDP Act
3 controls | DPDP Act, GDPR
🇳🇱
Netherlands (NL)
BIO, GDPR, DORA, NIS2
14 controls | BIO, DORA, NIS2, GDPR
🇬🇧
United Kingdom (UK)
UK GDPR, UK NCSC CAF, UK Cyber Essentials, NIS2
14 controls | UK GDPR, NCSC, Cyber Essentials, NIS2
🇺🇸
United States (US)
NIST SP 800-53, FedRAMP, CMMC 2.0, HIPAA, CCPA, SOC 2, PCI DSS
15 controls | NIST, FedRAMP, CMMC 2.0, HIPAA, PCI DSS
🇦🇺
Australia
ASD Essential 8, IRAP
13 controls | ASD Essential 8, IRAP
🇨🇦
Canada
PIPEDA
3 controls | PIPEDA
🇸🇬
Singapore
PDPA SG
2 controls | PDPA SG
🇮🇳
India
MEITY CSMP, DPDP Act
3 controls | MEITY CSMP, DPDP Act
🇧🇷
Brazil
LGPD
3 controls | LGPD

Key Regional Frameworks

GDPR (EU/EEA) NIS2 (EU) DORA (EU Financial) BSI C5/C3A (Germany) ANSSI (France) UK GDPR/NCSC (UK) NIST/FedRAMP (US) ASD Essential 8 (Australia) PIPEDA (Canada) PDPA (Singapore) DPDP Act (India) LGPD (Brazil)
REGULATORY FRAMEWORKS

All Supported Compliance Frameworks

WAF++ maps controls to regulatory frameworks across security, compliance, and governance domains.

🇬🇧

United Kingdom

Cloud Frameworks

AWS Well-Architected Azure Well-Architected Google Cloud Framework

Germany Specific

BSI C5:2020 BSI C3A:2026 IT-Grundschutz DORA NIS2

France Specific

ANSSI SecNumCloud GDPR DORA EUCS

Switzerland Specific

BSI C5:2020 GDPR DPDP Act

Total: 50+ regulatory frameworks supported

CONTROLS

Controls by Pillar

73 total controls across 7 pillars. Each control includes machine-readable checks for automated validation.

Security (WAF-SEC)
13 controls | Critical, High severity
WAF-SEC-010 WAF-SEC-020 WAF-SEC-030 WAF-SEC-040 WAF-SEC-050 WAF-SEC-060 WAF-SEC-070 WAF-SEC-080 WAF-SEC-090 WAF-SEC-100 WAF-SEC-110 WAF-SEC-120 WAF-SEC-130
Cost Optimization (WAF-COST)
10 controls | High, Medium severity
WAF-COST-010 WAF-COST-020 WAF-COST-030 WAF-COST-040 WAF-COST-050 WAF-COST-060 WAF-COST-070 WAF-COST-080 WAF-COST-090 WAF-COST-100
Operational Excellence (WAF-OPS)
10 controls | High, Medium severity
WAF-OPS-010 WAF-OPS-020 WAF-OPS-030 WAF-OPS-040 WAF-OPS-050 WAF-OPS-060 WAF-OPS-070 WAF-OPS-080 WAF-OPS-090 WAF-OPS-100
Reliability (WAF-REL)
10 controls | Critical, High severity
WAF-REL-010 WAF-REL-020 WAF-REL-030 WAF-REL-040 WAF-REL-050 WAF-REL-060 WAF-REL-070 WAF-REL-080 WAF-REL-090 WAF-REL-100
Performance Efficiency (WAF-PERF)
10 controls | Medium severity
WAF-PERF-010 WAF-PERF-020 WAF-PERF-030 WAF-PERF-040 WAF-PERF-050 WAF-PERF-060 WAF-PERF-070 WAF-PERF-080 WAF-PERF-090 WAF-PERF-100
Sovereign (WAF-SOV)
10 controls | Critical, High severity
WAF-SOV-010 WAF-SOV-020 WAF-SOV-030 WAF-SOV-040 WAF-SOV-050 WAF-SOV-060 WAF-SOV-070 WAF-SOV-080 WAF-SOV-090 WAF-SOV-100
Sustainability (WAF-SUS)
10 controls | High, Medium severity
WAF-SUS-010 WAF-SUS-020 WAF-SUS-030 WAF-SUS-040 WAF-SUS-050 WAF-SUS-060 WAF-SUS-070 WAF-SUS-080 WAF-SUS-090 WAF-SUS-100
View Full Documentation →
WAFPASS · CLI TOOL · v1.0.0

Validate controls against your IaC

Automated controls for every pillar — Terraform, CDK, and more. Static analysis, no cloud credentials required, results in seconds.

✓ PASS ✗ FAIL – SKIP
Learn about WAFPass →
GET STARTED

Ready to validate your infrastructure?

Dive into the documentation, validate your infrastructure with WAFPass, or join the community to contribute controls.

GDPR compliant SOC 2 ready HIPAA BSI C5 ISO 27001 NIS2
COMING SOON · 12 MAY 2026
WAF++ 1.0
incl. WAFPass 1.0

The first stable release of the WAF++ Framework and WAFPass CLI.

Launching on the pre-eve of Cloud Native Conference DE12 May 2026 · 20:00 CEST