SWAO (Sovereign Workload Assessment and Onboarding) analyses your cloud workloads against industry compliance frameworks, produces audit-grade evidence, and generates a migration plan - all in a single command. Community Edition is free and open source.
Traditional cloud compliance assessments take weeks of manual effort across multiple teams. SWAO compresses the entire workflow into a single automated pipeline - from code to compliance evidence to migration plan.
A full framework evaluation - source code, infrastructure, dynamic UI - completes in minutes. What used to require a team of consultants and a spreadsheet now runs from a single command. Re-assess after every change to catch compliance drift early.
Every finding cites the exact file, line number, or screen element that triggered it. SWAO produces HTML evidence packs, Power BI dashboards, and structured JSON that auditors and GRC platforms can consume directly - no manual transcription.
Runs on your own infrastructure. Choose your LLM provider (Anthropic, OpenAI, or Ollama). Secret redaction runs before any external call. Built for regulated industries where data residency is non-negotiable.
From the consultant running the assessment on a laptop to the CISO signing off on compliance evidence - SWAO serves each stakeholder with the output they need.
A 14-pass analysis pipeline reads your workload, evaluates it against compliance frameworks, and produces a single portable artefact - the Workload Sovereignty Profile - that drives everything downstream.
Single binary or Docker container. Install and run the first assessment in under 10 minutes. Ideal for discovery workshops and client demos. No infrastructure to provision.
Docker or Kubernetes on the client's own infrastructure. Source code never leaves the client environment. Preferred for regulated industries with strict data residency requirements.
SWAO deployed as a Developer Portal Building Block on meshStack. Application teams self-serve assessments from the platform they already operate - no consultant needed for each run.
22 compliance frameworks included in every edition - free, open, and continuously updated. No licence required to run any of them.
The General Data Protection Regulation is the European Union's primary law governing the collection, processing, and storage of personal data for EU residents. It applies to any organisation - worldwide - that processes EU citizen data.
The Health Insurance Portability and Accountability Act establishes US federal requirements for protecting Protected Health Information (PHI) in any system that stores, transmits, or processes patient data. Mandatory for all US healthcare entities and their business associates.
Accenture's Responsible AI framework defines ten pillars for building and deploying AI systems that are fair, transparent, and accountable. It covers the full AI lifecycle -- from data sourcing and model design through deployment and monitoring.
The BSI Cloud Computing Compliance Criteria Catalogue (C5) is the German Federal Office for Information Security's standard for cloud service providers operating in Germany. It covers 17 security domains and is a prerequisite for public sector procurement in Germany.
The Digital Operational Resilience Act (Regulation EU 2022/2554) has been mandatory since 17 January 2025 for banks, insurers, investment firms, payment institutions, and ICT third-party providers operating in the EU.
The ENISA EU Cloud Security Certification Scheme - 66 controls across 12 security domains at three assurance levels (Basic, Substantial, High). The primary EU-wide cloud security certification for IaaS, PaaS, and SaaS providers.
NIS2 (Directive 2022/2555) applies to medium and large essential and important entities across 18 EU sectors, with transposition deadline October 2024. Its ten minimum security measures (Art. 21) and three-tier incident reporting (Art. 23) are the core obligations.
Regulation EU 2024/1689 in force since August 2024. Prohibited AI practices apply from February 2025; high-risk AI system obligations apply from August 2027. Covers risk classification, high-risk requirements, transparency, and GPAI model obligations.
NIST Special Publication 800-66 Revision 2 provides prescriptive implementation guidance for the HIPAA Security Rule. Where HIPAA defines the regulatory requirements, NIST SP 800-66 R2 specifies concrete technical controls - making it the reference of choice for healthcare organisations seeking NIST alignment alongside HIPAA compliance.
ISO/IEC 27001:2022 is the international standard for Information Security Management Systems. The 2022 revision restructured the control set into 93 controls across four themes - Organisational, People, Physical, and Technological - adding 11 new controls for cloud security, threat intelligence, and data masking.
BSI IT-Grundschutz provides modular, prescriptive IT security guidance for German public sector organisations and regulated enterprises. Security measures are organised into building blocks (Bausteine) covering infrastructure, systems, applications, and organisation - forming the basis for BSI certification in Germany.
The AICPA Trust Services Criteria define the security baseline for SaaS and cloud service providers demonstrating controls to enterprise customers. Five TSC categories cover Security (CC), Availability, Processing Integrity, Confidentiality, and Privacy. Security is mandatory; the remaining categories are selected per engagement scope.
Regulation EU 2024/2847 introduces mandatory cybersecurity requirements for all hardware and software products with digital elements sold in the EU. Critical products (class I/II) must comply from June 2027; all other products from December 2027. Annex I defines security requirements and vulnerability handling obligations.
KRITIS-DE implements BSIG ยง8a obligations for operators of critical infrastructure in Germany across 10 sectors - energy, water, transport, health, finance, food, and digital infrastructure. Operators must apply state-of-the-art IT security measures and submit proof of compliance every two years to BSI.
The Open Source Security Foundation Scorecard defines 17 automated security checks covering supply chain integrity, CI/CD security, dependency management, vulnerability response, and code review practices. Weighted scoring produces a 0-10 summary score used in procurement decisions and supply chain risk assessments.
PCI DSS 4.0.1 is mandatory for any organisation that stores, processes, or transmits payment card data. The 2024 revision introduced 64 new requirements focused on targeted risk analysis, customised implementation, and stronger authentication. All PCI DSS v3.2.1 deadline extensions expired in March 2025.
The Saudi Arabian Monetary Authority Cyber Security Framework v1.0 is mandatory for all SAMA-regulated financial institutions - banks, insurance companies, fintech providers, and payment processors. Five domains cover Leadership and Governance, Risk Management and Compliance, Operations, Third-Party Risk, and Cyber Resilience.
The Saudi National Cybersecurity Authority Cloud Cybersecurity Controls v2.0 (CSP edition) defines mandatory requirements for cloud service providers operating in Saudi Arabia, particularly those serving public sector or critical infrastructure clients. Updated in 2024 with stronger controls for data localisation and supply chain security.
The NCA Cloud Cybersecurity Controls v2.0 (Tenant edition) defines security obligations for organisations consuming cloud services in Saudi Arabia. It complements the CSP edition by addressing tenant responsibilities for access management, data classification, configuration, and incident response within shared cloud environments.
The NCA Essential Cybersecurity Controls v2.0 are mandatory for all Saudi government entities and critical national infrastructure operators. Five domains cover Cybersecurity Governance, Risk Management, Compliance, Human Aspects, and Technology Controls - establishing the baseline cybersecurity floor for Saudi digital government.
Accenture's LLM Selection framework provides sovereignty benchmarking criteria for evaluating AI and large language model providers. It assesses data residency, training data jurisdiction, fine-tuning data handling, inference endpoint location, and contractual data processing guarantees - enabling informed LLM provider selection under sovereign or regulated workload constraints.
SecNumCloud v3.2 is the ANSSI qualification scheme for sovereign cloud services in France and a reference standard for EU sovereign cloud procurement. Nine qualified providers hold or pursue qualification. Its 65 controls across 19 chapters cover governance, supply chain, physical, technical, and operational security at the highest EU sovereign cloud assurance tier.
The European Commission Cloud Sovereignty Framework v1.2.1 (October 2025) defines sovereignty requirements for cloud procurement across EU institutions. Eight SOV domains - Strategic, Legal, Data, Operational, Supply Chain, Technology, Security, and Environmental - are assessed at SEAL-0 to SEAL-4 maturity levels. Used in EUR 180M EU institutional cloud procurement.
Not covered by the 22 community frameworks? SWAO's framework format is a plain YAML file - no TypeScript, no compilation, no specialist tooling required. Define your own controls, risk levels, remediation guidance, and regime metadata. Point SWAO at your YAML file and it runs immediately alongside the community frameworks.
Custom frameworks are ideal for internal security policies, client-specific contractual requirements, sector-specific regulations not yet in the community catalogue, or proprietary control frameworks. Contribute your framework back to the community via a GitHub pull request and help the ecosystem grow.
SWAO ships with a curated catalogue of cloud providers - covering major hyperscalers and EU-dedicated sovereign clouds. Each provider entry defines a set of readiness checks that SWAO validates automatically during a Landing Zone Assessment. The catalogue is customisable and updated with every SWAO release.
Dedicated sovereign cloud providers operating under EU or national legal jurisdiction. These providers offer contractual data residency guarantees, EU-domiciled operating entities, and - in several cases - BSI C5 or ISO 27001 attestations. SWAO's catalogue includes provider-specific checks tailored to each platform's service portfolio, Terraform resource types, and sovereignty evidence.
Major hyperscalers with EU-located regions and - in the case of AWS ESC - dedicated sovereign cloud infrastructure. SWAO evaluates these providers against the same sovereignty and compliance criteria as the dedicated EU clouds, surfacing the controls that are satisfied, the gaps that remain, and the configuration changes required to meet EU data residency requirements.
The cloud provider catalogue is a plain YAML file - no TypeScript, no compilation. Add a new provider entry with its service portfolio, sovereignty evidence, and readiness checks. Point SWAO at your YAML and it runs immediately alongside the built-in providers. Custom entries are ideal for private cloud platforms, managed hosting providers, or internal platform teams that operate their own landing zones.
SWAO also updates the catalogue automatically when new provider data becomes available:
run swao catalogue update to pull the latest provider checks without
upgrading the full binary.
From a fresh install to a full compliance report in under 15 minutes.
Download the SWAO binary and run swao init to configure your workspace, LLM provider, and target compliance frameworks via a guided wizard.
Point SWAO at your application repository. Static code analysis, dynamic UI crawling (Playwright), SBOM generation, and secret detection run automatically across 14 passes.
Explore results in the interactive TUI or HTML evidence report. Filter by severity, framework control, or file path. Every finding links back to the exact source that triggered it.
Export a migration runbook, risk register, and Terraform landing-zone scaffold. Re-assess after remediation to track compliance improvement over time.
Community Edition is free and Apache 2.0 licensed. Consultant and Enterprise editions add production outputs, portal integration, and programme-scale capabilities via Accenture Professional Services.
| Feature | Community | Consultant | Enterprise |
|---|---|---|---|
| Assessment Types | |||
| Application Assessment (AI-assisted: static, dynamic, SBOM) | Yes | Yes | Yes |
| Landing Zone Assessment (fit/gap vs. your existing LZ) | Yes | Yes | Yes |
| LLM Assessment (sovereignty benchmarking across LLM providers) | Yes | Yes | Yes |
| Portfolio Assessment (100+ apps, wave planning) | - | - | Roadmap |
| Adversarial Challenge Review (second LLM agent independently challenges every finding) | - | - | Yes |
| Tools and Interface | |||
| CLI and interactive TUI | Yes | Yes | Yes |
| LLM integration (Anthropic, OpenAI, Ollama, Amazon Bedrock Gateway, open-LLM providers) | Yes | Yes | Yes |
| Context ingestion (CMDB, ServiceNow, FinOps reports, architecture docs) | Yes | Yes | Yes |
| MCP server (Claude Code, Cursor, and other AI tools) | - | - | Yes |
| Frameworks | |||
| 22 Community Frameworks (AI 10 Pillars, BSI C5, BSI IT-Grundschutz 2023, DORA, EC CSF, EU AI Act, EU CRA, EUCS, GDPR, ISO 27001:2022, KRITIS-DE, LLM Selection, NCA CCC 2024 CSP, NCA CCC 2024 CST, NCA ECC 2024, NIS2, NIST SP 800-66r2 / HIPAA, OpenSSF Scorecard, PCI-DSS v4, SAMA CSF v1, SecNumCloud v3.2, SOC 2 Type II) | Yes | Yes | Yes |
| Landing Zone Catalogues (12 EU sovereign and hyperscaler providers; customisable) | Yes | Yes | Yes |
| Reports and Outputs | |||
| HTML evidence report (single-file, offline-capable) | - | Yes | Yes |
| Portal and programme dashboard (HTML Editor) | - | - | Yes |
| PDF report (branded with licensee details) | - | Yes | Yes |
| Power BI export (.pbit template for dashboards and trends) | - | - | Yes |
| Terraform and landing zone generation | - | - | Yes |
| Advanced Delivery | |||
| Terraform LZ module stubs (pre-populated from LZ readiness assessment output) | - | - | Roadmap |
| meshStack Developer Portal Building Block deployment | - | - | Roadmap |
| Custom LZ catalogue standard (organisation-wide configuration replacement) | - | - | Roadmap |
| Licence and Support | |||
| Licence | Apache 2.0 | Proprietary | Proprietary |
| Support | GitHub Discussions | Accenture PS | Accenture PS |
Live HTML publications generated by SWAO against the Sovereign Health demo workspace. Open in your browser - no login required.
SWAO is open source. Whether you are building with SWAO, contributing frameworks, or exploring an Accenture-led migration engagement, there is a path for you.
Ask questions, share custom frameworks, report issues, and follow release announcements on GitHub Discussions. The SWAO development team monitors this channel and welcomes community contributions.
Open DiscussionsFor Consultant or Enterprise Edition licences, programme-scale deployments, meshStack integration, or a guided cloud migration engagement, reach out via GitHub Discussions or your Accenture account team.
Contact via Discussions