Open Framework v1.1

The 8 Pillars

A vendor-neutral structure that covers every critical dimension of cloud architecture quality — from security and cost to digital sovereignty and agentic operations.

GDPR BSI C5 ISO 27001 SOC 2 NIS2
8
Pillars
83
Controls
50+
Compliance frameworks
15+
Countries & regions
THE FRAMEWORK

All 8 pillars at a glance

Every pillar is a lens for making better cloud decisions. Explore the overview or dive into the full documentation.

Pillar 01

Security

Controls, threat modeling, policy-as-code, and secure defaults across every layer.

Pillar 02

Cost Optimization

FinOps, cost transparency, budget guardrails, and right-sizing.

Pillar 03

Performance Efficiency

Performance as a product: architecture, scaling, latency, and efficiency.

Pillar 04

Reliability

Resilience, HA/DR, error budgets, and robust operating models.

Pillar 05

Operational Excellence

Runbooks, incident response, standards, and automation.

Pillar 06

Sustainability

Efficiency, resource consumption, and sustainable platform decisions.

Pillar 07

Sovereign

Data sovereignty, compliance, vendor neutrality, and exit strategies. The first plus of WAF++.

Pillar 08

Agentic

AI-assisted architecture reviews, autonomous remediation, and policy-aware agents. The second plus of WAF++.

PRACTICE

How to use the 8 pillars

Architecture Reviews

Evaluate every new platform or cloud architecture against all eight pillars before go-live.

Platform Standards

Build golden paths, guardrails, and default configurations on top of the pillars.

Audit & Compliance

Use the pillars as a governance reference mapped to GDPR, BSI C5, ISO 27001, and SOC 2.

GET STARTED

Ready to design with all 8 pillars?

Dive into the documentation, validate your infrastructure with WAFPass, or join the community to contribute controls and governance feedback.

GDPR SOC 2 HIPAA BSI C5 ISO 27001 NIS2