"Cloud-agnostic under the name 'WAF++' is emerging. Cloud-agnostic means here that the guidelines do not bind to individual hyperscalers, but remain compatible with multi-cloud and hybrid setups."
Everything you need to cover WAF++ — brand assets, boilerplate text, key facts, and a direct line to the press team.
The essential numbers and milestones for your coverage of WAF++.
Security · Reliability · Performance · Cost · Operations · Sustainability · Sovereign · Agentic.
Concrete, auditable controls across all eight pillars, mapped to compliance frameworks and cloud services.
Open Framework v1.1 is the current stable release.
All decisions via public RFCs in GitHub Discussions — traceable and community-reviewed.
Works across AWS, Azure, GCP, on-premises, and hybrid environments.
Four maturity levels per pillar — Poor, Adequate, Strong, Superior.
Code under Apache 2.0. Documentation under CC BY 4.0. Free to use, adapt, and build upon.
All WAF++ brand assets are available for editorial use under the project's open-source licence. Please do not alter colours or proportions.
Additional assets and source files are available in the GitHub repository.
Use the following text when describing WAF++ in articles, podcasts, or presentations.
WAF++ is an open-source, vendor-neutral framework for assessing and improving the quality of cloud workloads across 8 pillars: Security, Reliability, Performance Efficiency, Cost Optimisation, Operational Excellence, Sustainability, Sovereign, and Agentic.
WAF++ is an open-source, vendor-neutral framework for cloud architecture quality — 8 pillars, transparent scoring, community-governed via public RFCs. Docs under CC BY 4.0, code under Apache 2.0. waf2p.dev
WAF++ (Well-Architected Framework Plus Plus) is an open-source, community-driven framework for assessing and improving cloud workload quality. It covers 8 pillars — Security, Reliability, Performance Efficiency, Cost Optimisation, Operational Excellence, Sustainability, Sovereign, and Agentic — with a transparent scoring model called PASS.
Unlike proprietary vendor frameworks, WAF++ is governed openly via RFCs in GitHub Discussions, making every decision traceable and every control citable. The framework is free to use, contribute to, and build upon.
WAF++ — pronounced "waf plus plus" — is an open-source framework that gives engineering and architecture teams a vendor-neutral lens for evaluating cloud workloads. It organises everything across eight pillars: Security, Reliability, Performance Efficiency, Cost Optimisation, Operational Excellence, Sustainability, Sovereign, and Agentic.
What makes WAF++ different is how it's built: every guideline, scoring rule, and design decision goes through a public RFC process on GitHub — fully transparent, fully community-driven. There's no vendor behind it, no upsell, and no black box. Anyone can read the criteria, challenge them, and improve them.
Articles and references about WAF++ from the press and media community.
"Cloud-agnostic under the name 'WAF++' is emerging. Cloud-agnostic means here that the guidelines do not bind to individual hyperscalers, but remain compatible with multi-cloud and hybrid setups."
"Das Community-basierte Open-Source-Framework Waf++ wurde erstmals auf der Cloud Native Conference 2026 in Frankfurt vorgestellt. Entwickelt von Sascha Lewandowski, Artem Lajko, Tim Urlaub und Sebastian Meyer, soll das Framework Architekturbewertungen über Cloud-Grenzen hinweg vereinheitlichen und Multicloud- sowie Hybrid-Cloud-Strategien unterstützen."
For interview requests, fact-checking, or editorial questions — and how to refer to WAF++ correctly.
How to refer to WAF++ correctly in editorial content.
Drop us a line at page@waf2p.dev or share your article in our Slack community. We respond to all press enquiries within 2 business days.
WAF++ now includes an eighth pillar — AI-assisted architecture reviews, autonomous remediation, and policy-aware agents for secure cloud operations.