Framework · Open · Community-driven

The 7 Pillars of WAF++

A vendor-neutral structure that covers every critical dimension of cloud architecture quality — from security and cost to digital sovereignty. Built for real engineering, not marketing slides.

Security Cost Optimization Performance Reliability Operational Excellence Sustainability Sovereign ★
60+
documented controls
3
maturity levels
6+
compliance frameworks
CC BY 4.0
docs license
Apache 2.0
source license
Compliance coverage
GDPR BSI C5 ISO 27001 SOC 2 NIS2
PRACTICE

How to use the 7 Pillars

The 7 Pillars are a living reference — not a one-time audit. They guide architecture decisions, platform standards, and continuous governance across your engineering organization.

Architecture Reviews

Evaluate every new platform or cloud architecture against all seven pillars — covering security, cost, resilience, and sovereignty in one structured pass before production.

Platform Standards

Build golden paths, guardrails, and default configurations on top of the pillars. Define what "good" looks like — enforced automatically by WAFPass in CI/CD.

Audit & Compliance

Use the pillars as a governance reference mapped to GDPR, BSI C5, ISO 27001, and SOC 2 — turning architecture decisions into auditable, traceable evidence.

Architecture Review · 7-Pillar Checklist
01 SEC Security controls reviewed
02 COST Cost model validated
03 PERF Performance targets defined
04 REL Resilience & SLOs defined
05 OPS Runbooks & alerts documented
06 SUS Carbon impact assessed
07 SOV Sovereignty & exit strategy confirmed
5/7 pillars reviewed · 2 items pending
MATURITY

Three levels of maturity across all pillars

WAF++ defines a maturity model for each pillar — assess where you are, plan what to improve, and track progress over time.

01
Baseline

Foundational standards and minimum requirements in place. Security basics, cost tagging, SLO definitions, and data residency configured. The starting point for any cloud workload.

02
Standardize

Repeatable patterns, automation, and clearly defined guardrails. Golden paths in use, WAFPass integrated in CI/CD, architecture decisions documented as ADRs across all seven pillars.

03
Optimize

Measurable optimization in cost, performance, resilience, and governance. Continuous feedback loops, proactive capacity planning, and sovereign-by-design infrastructure at scale.

WAFPASS · CLI TOOL Beta

Validate all 7 pillars against your IaC

Automated controls for every pillar — Terraform, CDK, and more. Static analysis, no cloud credentials, results in seconds.

✓ PASS ✗ FAIL – SKIP
Learn about WAFPass →
GET STARTED

Ready to design with all 7 pillars?

Dive into the documentation, validate your infrastructure with WAFPass, or join the community to contribute controls and governance feedback.

GDPR compliant SOC 2 ready HIPAA BSI C5 ISO 27001 NIS2
COMING SOON · 12 MAY 2026
WAF++ 1.0
incl. WAFPass 1.0

The first stable release of the WAF++ Framework and WAFPass CLI.

Launching on the pre-eve of Cloud Native Conference DE12 May 2026 · 20:00 CEST