Open Source by Accenture

Cloud compliance assessments
in minutes, not months.

SWAO (Sovereign Workload Assessment and Onboarding) analyses your cloud workloads against industry compliance frameworks, produces audit-grade evidence, and generates a migration plan - all in a single command. Community Edition is free and open source.

Why SWAO?

Traditional cloud compliance assessments take weeks of manual effort across multiple teams. SWAO compresses the entire workflow into a single automated pipeline - from code to compliance evidence to migration plan.

Speed

Weeks to minutes

A full framework evaluation - source code, infrastructure, dynamic UI - completes in minutes. What used to require a team of consultants and a spreadsheet now runs from a single command. Re-assess after every change to catch compliance drift early.

Evidence

Audit-ready by design

Every finding cites the exact file, line number, or screen element that triggered it. SWAO produces HTML evidence packs, Power BI dashboards, and structured JSON that auditors and GRC platforms can consume directly - no manual transcription.

Sovereignty

Your data stays yours

Runs on your own infrastructure. Choose your LLM provider (Anthropic, OpenAI, or Ollama). Secret redaction runs before any external call. Built for regulated industries where data residency is non-negotiable.

What is SWAO? Full Product Overview
What is SWAO? Full Product Overview

Built for every role in your programme

From the consultant running the assessment on a laptop to the CISO signing off on compliance evidence - SWAO serves each stakeholder with the output they need.

Cloud Migration Consultants

Compress 7R engagements from weeks to days

Run a full Rehost / Replatform / Refactor analysis for an application in a single command. SWAO produces a portable Workload Sovereignty Profile (WSP) that carries the assessment forward into planning and onboarding - no re-entry, no drift between phases.
  • Single binary, works on a laptop or client-hosted container
  • Unlimited assessments in Community Edition (no licence required)
  • Interactive TUI for guided exploration of findings
  • Generates migration runbook, risk register, and training plan
Compliance and Risk Officers

Audit-ready evidence, generated automatically

Every SWAO finding links back to the specific file, configuration line, or screen element that triggered it. Multi-regime assessments (GDPR + HIPAA + COBIT 5 in a single run) give a complete picture without duplicate effort.
  • HTML evidence packs and structured JSON for GRC platforms
  • Full human-override audit trail - every manual decision is logged
  • 22 frameworks included free: GDPR, ISO 27001, DORA, NIS2, EU AI Act, BSI C5, EUCS, and more
  • Confidence scoring flags areas that need human review
Enterprise and Cloud Architects

From compliance gaps to sovereign landing zones

SWAO maps workload constraints to a target landing zone and emits a Terraform module tailored to your cloud provider and sovereign requirements. One assessment drives both compliance evidence and infrastructure design.
  • Landing Zone Assessment: fit/gap vs. your existing landing zone
  • meshStack Developer Portal Building Block deployment
  • Pluggable VCS, scanner, and tracker connectors
  • Portfolio assessment and wave planning (Enterprise Edition)
Developers and DevSecOps Teams

Compliance checks inside your development workflow

The SWAO MCP server lets AI coding assistants such as Claude Code and Cursor query your compliance findings directly from the editor. Ask about control status, browse blockers, and get remediation guidance without leaving your workflow.
  • MCP server on localhost:3737 - connects to Claude Code and Cursor
  • Integrate findings into Jira, GitHub Issues, or Azure Boards
  • SAST, container scan, IaC scan, and secrets detection built in
  • Re-assess after every PR to detect compliance regression

How SWAO works

A 14-pass analysis pipeline reads your workload, evaluates it against compliance frameworks, and produces a single portable artefact - the Workload Sovereignty Profile - that drives everything downstream.

1. Input Sources
Source code repository
Infrastructure as Code (Terraform, Helm)
CMDB / FinOps data export
Dynamic web UI (Playwright crawl)
Workshop transcripts / runbooks
Your LLM (bring your own)
Anthropic Claude
OpenAI / Open-LLM providers
Ollama (fully local)
→
2. Analysis Pipeline (14 Passes)
01Inventory
02State
03Data Class.
04Context
05SBOM
06Terraform
07Egress
08Crypto
09Synthesis
10Dynamic UI
11Compliance
12Blockers
13Scope & 7R
14Evidence Gallery
Each pass adds findings to the Workload Sovereignty Profile (WSP) -- a versioned YAML artefact that carries the full assessment state forward into planning and onboarding.
→
3. Output Artefacts
WSP.yaml Portable, versioned, machine-readable - flows into planning and onboarding
HTML Evidence Report Per-control findings with file:line traceability
7R Disposition Rehost / Replatform / Refactor / Repurchase / Retire / Retain / Relocate
Migration Runbook Risk register, data plan, rollback plan, training plan
Terraform Scaffold Landing zone tailored to workload's sovereign constraints
Power BI / CSV / JSON For dashboards, GRC platforms, and portfolio roll-ups
Deployment Mode A

Consultant laptop

Single binary or Docker container. Install and run the first assessment in under 10 minutes. Ideal for discovery workshops and client demos. No infrastructure to provision.

Deployment Mode B

Client-hosted

Docker or Kubernetes on the client's own infrastructure. Source code never leaves the client environment. Preferred for regulated industries with strict data residency requirements.

Deployment Mode B-DevX

meshStack Building Block

SWAO deployed as a Developer Portal Building Block on meshStack. Application teams self-serve assessments from the platform they already operate - no consultant needed for each run.

Community Frameworks

22 compliance frameworks included in every edition - free, open, and continuously updated. No licence required to run any of them.

GDPR EU / Data Privacy

The General Data Protection Regulation is the European Union's primary law governing the collection, processing, and storage of personal data for EU residents. It applies to any organisation - worldwide - that processes EU citizen data.

Assessment benefit: SWAO evaluates 47 controls covering data residency enforcement, consent management, retention policies, encryption at rest and in transit, data subject rights, and breach notification readiness. Each finding cites the specific GDPR article and the code or configuration that triggered it.
HIPAA US / Healthcare

The Health Insurance Portability and Accountability Act establishes US federal requirements for protecting Protected Health Information (PHI) in any system that stores, transmits, or processes patient data. Mandatory for all US healthcare entities and their business associates.

Assessment benefit: SWAO checks administrative, physical, and technical safeguards - ePHI encryption, workforce access controls, audit logging, automatic logoff, data backup, and disaster recovery configurations - against the HIPAA Security Rule's required and addressable implementation specifications.
AI 10 Pillars Responsible AI

Accenture's Responsible AI framework defines ten pillars for building and deploying AI systems that are fair, transparent, and accountable. It covers the full AI lifecycle -- from data sourcing and model design through deployment and monitoring.

Assessment benefit: SWAO assesses AI and ML workloads against all ten pillars: fairness, transparency, explainability, robustness, privacy, security, reliability, inclusiveness, accountability, and sustainability. Identifies gaps in model governance, bias controls, explainability tooling, and audit logging.
BSI C5 Cloud / Germany

The BSI Cloud Computing Compliance Criteria Catalogue (C5) is the German Federal Office for Information Security's standard for cloud service providers operating in Germany. It covers 17 security domains and is a prerequisite for public sector procurement in Germany.

Assessment benefit: SWAO evaluates 62 controls across all 17 BSI C5 domains - from organisation and personnel through cryptography, network security, logging, and business continuity. Essential for cloud providers serving German public or regulated private sector clients.
DORA EU / Financial Services

The Digital Operational Resilience Act (Regulation EU 2022/2554) has been mandatory since 17 January 2025 for banks, insurers, investment firms, payment institutions, and ICT third-party providers operating in the EU.

Assessment benefit: SWAO evaluates 31 controls across 5 pillars: ICT risk management, incident reporting, resilience testing, TPP risk, and information sharing - surfacing gaps and evidence requirements for each pillar.
EUCS EU / Cloud Certification

The ENISA EU Cloud Security Certification Scheme - 66 controls across 12 security domains at three assurance levels (Basic, Substantial, High). The primary EU-wide cloud security certification for IaaS, PaaS, and SaaS providers.

Assessment benefit: SWAO maps your cloud service posture to the EUCS assurance level required by EU customers or authorities, surfacing domain gaps at the correct assurance tier.
NIS2 EU / Critical Infrastructure

NIS2 (Directive 2022/2555) applies to medium and large essential and important entities across 18 EU sectors, with transposition deadline October 2024. Its ten minimum security measures (Art. 21) and three-tier incident reporting (Art. 23) are the core obligations.

Assessment benefit: SWAO evaluates 46 controls covering all Art. 21 measures - from access control and cryptography to supply chain security and business continuity - with evidence indicators per control.
EU AI Act EU / Artificial Intelligence

Regulation EU 2024/1689 in force since August 2024. Prohibited AI practices apply from February 2025; high-risk AI system obligations apply from August 2027. Covers risk classification, high-risk requirements, transparency, and GPAI model obligations.

Assessment benefit: SWAO runs Risk Classification first, then evaluates only the applicable downstream controls - HR for high-risk systems, TR for limited-risk and above, GP for GPAI models. 37 controls total.
NIST SP 800-66 R2 US / Healthcare (NIST)

NIST Special Publication 800-66 Revision 2 provides prescriptive implementation guidance for the HIPAA Security Rule. Where HIPAA defines the regulatory requirements, NIST SP 800-66 R2 specifies concrete technical controls - making it the reference of choice for healthcare organisations seeking NIST alignment alongside HIPAA compliance.

Assessment benefit: 9 control families and 66 individual controls across Access Control (AC), Audit and Accountability (AU), Configuration Management (CM), Contingency Planning (CP), Identification and Authentication (IA), Incident Response (IR), Risk Assessment (RA), System and Communications Protection (SC), and System and Information Integrity (SI). Run alongside the HIPAA framework for a complete regulatory and implementation-guidance picture.
ISO 27001:2022 Information Security / Global

ISO/IEC 27001:2022 is the international standard for Information Security Management Systems. The 2022 revision restructured the control set into 93 controls across four themes - Organisational, People, Physical, and Technological - adding 11 new controls for cloud security, threat intelligence, and data masking.

Assessment benefit: SWAO evaluates 93 controls with 14 cloud-relevant controls marked as CSP-inherited, giving a clear split between what your workload must demonstrate and what your cloud provider already covers by default.
BSI IT-Grundschutz 2023 IT Security / Germany

BSI IT-Grundschutz provides modular, prescriptive IT security guidance for German public sector organisations and regulated enterprises. Security measures are organised into building blocks (Bausteine) covering infrastructure, systems, applications, and organisation - forming the basis for BSI certification in Germany.

Assessment benefit: SWAO maps workloads to the cloud-relevant IT-Grundschutz building blocks covering server security, network, web services, identity, and logging - surfacing gaps against the 2023 edition requirements.
SOC 2 Type II SaaS / Cloud / US

The AICPA Trust Services Criteria define the security baseline for SaaS and cloud service providers demonstrating controls to enterprise customers. Five TSC categories cover Security (CC), Availability, Processing Integrity, Confidentiality, and Privacy. Security is mandatory; the remaining categories are selected per engagement scope.

Assessment benefit: SWAO evaluates 64 controls across all five TSC categories, producing evidence indicators suitable for Type II audit sampling periods. Security category findings align directly with GDPR and ISO 27001 outputs.
EU Cyber Resilience Act Product Security / EU

Regulation EU 2024/2847 introduces mandatory cybersecurity requirements for all hardware and software products with digital elements sold in the EU. Critical products (class I/II) must comply from June 2027; all other products from December 2027. Annex I defines security requirements and vulnerability handling obligations.

Assessment benefit: SWAO evaluates 35 controls covering secure design, default configuration, vulnerability disclosure, SBOM completeness, and incident reporting timelines against both Annex I Part I (security) and Part II (vulnerability handling) obligations.
KRITIS-DE Critical Infrastructure / Germany

KRITIS-DE implements BSIG ยง8a obligations for operators of critical infrastructure in Germany across 10 sectors - energy, water, transport, health, finance, food, and digital infrastructure. Operators must apply state-of-the-art IT security measures and submit proof of compliance every two years to BSI.

Assessment benefit: SWAO evaluates 40 controls across 7 domains: governance, risk management, incident response, business continuity, supply chain, physical security, and technical controls - producing the evidence package required for the biennial BSI audit submission.
OpenSSF Scorecard Open Source / Global

The Open Source Security Foundation Scorecard defines 17 automated security checks covering supply chain integrity, CI/CD security, dependency management, vulnerability response, and code review practices. Weighted scoring produces a 0-10 summary score used in procurement decisions and supply chain risk assessments.

Assessment benefit: SWAO runs all 17 Scorecard checks against application source repositories, identifying missing branch protection, unsigned artefacts, unpinned dependencies, and absent security policies - with per-check remediation guidance.
PCI-DSS v4 Payment Security / Global

PCI DSS 4.0.1 is mandatory for any organisation that stores, processes, or transmits payment card data. The 2024 revision introduced 64 new requirements focused on targeted risk analysis, customised implementation, and stronger authentication. All PCI DSS v3.2.1 deadline extensions expired in March 2025.

Assessment benefit: SWAO evaluates workloads against all 12 PCI DSS requirements - from network segmentation and cardholder data protection through access control, monitoring, and penetration testing requirements - flagging in-scope components and control gaps.
SAMA CSF v1 Financial / Saudi Arabia

The Saudi Arabian Monetary Authority Cyber Security Framework v1.0 is mandatory for all SAMA-regulated financial institutions - banks, insurance companies, fintech providers, and payment processors. Five domains cover Leadership and Governance, Risk Management and Compliance, Operations, Third-Party Risk, and Cyber Resilience.

Assessment benefit: SWAO evaluates controls across all five SAMA domains, identifying gaps in cloud governance, third-party vendor risk, incident response readiness, and resilience architecture for Saudi-regulated financial workloads.
NCA CCC 2024 - Cloud Service Provider Cloud Security / Saudi Arabia

The Saudi National Cybersecurity Authority Cloud Cybersecurity Controls v2.0 (CSP edition) defines mandatory requirements for cloud service providers operating in Saudi Arabia, particularly those serving public sector or critical infrastructure clients. Updated in 2024 with stronger controls for data localisation and supply chain security.

Assessment benefit: SWAO evaluates CSP-side controls covering data residency, isolation, logging, penetration testing, cryptography, and incident reporting - with Saudi data localisation requirements explicitly flagged per control.
NCA CCC 2024 - Cloud Service Tenant Cloud Security / Saudi Arabia

The NCA Cloud Cybersecurity Controls v2.0 (Tenant edition) defines security obligations for organisations consuming cloud services in Saudi Arabia. It complements the CSP edition by addressing tenant responsibilities for access management, data classification, configuration, and incident response within shared cloud environments.

Assessment benefit: SWAO evaluates tenant-side controls covering identity and access management, data classification, security configuration, monitoring, and shared-responsibility boundary awareness for Saudi cloud deployments.
NCA ECC 2024 Cybersecurity / Saudi Arabia

The NCA Essential Cybersecurity Controls v2.0 are mandatory for all Saudi government entities and critical national infrastructure operators. Five domains cover Cybersecurity Governance, Risk Management, Compliance, Human Aspects, and Technology Controls - establishing the baseline cybersecurity floor for Saudi digital government.

Assessment benefit: SWAO evaluates workloads against ECC controls covering asset management, access control, vulnerability management, secure configuration, logging, and incident response - producing a gap analysis against Saudi government compliance requirements.
LLM Selection AI/ML / Cross-sector

Accenture's LLM Selection framework provides sovereignty benchmarking criteria for evaluating AI and large language model providers. It assesses data residency, training data jurisdiction, fine-tuning data handling, inference endpoint location, and contractual data processing guarantees - enabling informed LLM provider selection under sovereign or regulated workload constraints.

Assessment benefit: SWAO evaluates LLM-integrated workloads against provider-specific sovereignty criteria, surfacing risks when inference or training data crosses jurisdictional boundaries relevant to GDPR, NIS2, or national AI regulations.
SecNumCloud v3.2 Sovereign Cloud / France and EU

SecNumCloud v3.2 is the ANSSI qualification scheme for sovereign cloud services in France and a reference standard for EU sovereign cloud procurement. Nine qualified providers hold or pursue qualification. Its 65 controls across 19 chapters cover governance, supply chain, physical, technical, and operational security at the highest EU sovereign cloud assurance tier.

Assessment benefit: SWAO evaluates landing zone and governance posture against SecNumCloud chapter requirements, identifying gaps for organisations seeking qualification or procuring from qualified providers under French or EU sovereign cloud mandates.
EC Cloud Sovereignty Framework Sovereign Cloud / EU

The European Commission Cloud Sovereignty Framework v1.2.1 (October 2025) defines sovereignty requirements for cloud procurement across EU institutions. Eight SOV domains - Strategic, Legal, Data, Operational, Supply Chain, Technology, Security, and Environmental - are assessed at SEAL-0 to SEAL-4 maturity levels. Used in EUR 180M EU institutional cloud procurement.

Assessment benefit: SWAO evaluates 40 controls across all eight SOV domains, producing a SEAL maturity score per domain and an overall sovereignty posture profile for organisations procuring or delivering EU institutional cloud services.

Build your own framework

Not covered by the 22 community frameworks? SWAO's framework format is a plain YAML file - no TypeScript, no compilation, no specialist tooling required. Define your own controls, risk levels, remediation guidance, and regime metadata. Point SWAO at your YAML file and it runs immediately alongside the community frameworks.

Custom frameworks are ideal for internal security policies, client-specific contractual requirements, sector-specific regulations not yet in the community catalogue, or proprietary control frameworks. Contribute your framework back to the community via a GitHub pull request and help the ecosystem grow.

Framework authoring guide Share your framework

Landing Zone Catalogues

SWAO ships with a curated catalogue of cloud providers - covering major hyperscalers and EU-dedicated sovereign clouds. Each provider entry defines a set of readiness checks that SWAO validates automatically during a Landing Zone Assessment. The catalogue is customisable and updated with every SWAO release.

STACKIT (Schwarz Group) OTC (T-Systems) IONOS Cloud OVHcloud CloudFerro Exoscale Hetzner Cloud gridscale PlusServer Microsoft Azure (EU) AWS (eu-central-1 / ESC) Google Cloud (EU regions)
Sovereign EU clouds STACKIT, OTC, IONOS, OVHcloud, CloudFerro, Exoscale, Hetzner, gridscale, PlusServer

Dedicated sovereign cloud providers operating under EU or national legal jurisdiction. These providers offer contractual data residency guarantees, EU-domiciled operating entities, and - in several cases - BSI C5 or ISO 27001 attestations. SWAO's catalogue includes provider-specific checks tailored to each platform's service portfolio, Terraform resource types, and sovereignty evidence.

Assessment benefit: SWAO generates a fit/gap report for your chosen target provider. Blocker checks flag services your workload depends on that are not yet available on the target platform. Warning checks surface configuration steps required before cutover. Informational checks document the sovereignty evidence trail.
Hyperscaler EU regions Microsoft Azure (West Europe), AWS eu-central-1 + ESC, Google Cloud EU

Major hyperscalers with EU-located regions and - in the case of AWS ESC - dedicated sovereign cloud infrastructure. SWAO evaluates these providers against the same sovereignty and compliance criteria as the dedicated EU clouds, surfacing the controls that are satisfied, the gaps that remain, and the configuration changes required to meet EU data residency requirements.

Assessment benefit: Produces a comparative fit/gap report across multiple target providers so migration architects can select the landing zone that best matches the workload's compliance profile and operational constraints.

Add your own landing zone

The cloud provider catalogue is a plain YAML file - no TypeScript, no compilation. Add a new provider entry with its service portfolio, sovereignty evidence, and readiness checks. Point SWAO at your YAML and it runs immediately alongside the built-in providers. Custom entries are ideal for private cloud platforms, managed hosting providers, or internal platform teams that operate their own landing zones.

SWAO also updates the catalogue automatically when new provider data becomes available: run swao catalogue update to pull the latest provider checks without upgrading the full binary.

Request a provider Report a catalogue issue

Getting started in four steps

From a fresh install to a full compliance report in under 15 minutes.

1
Install and initialise

Download the SWAO binary and run swao init to configure your workspace, LLM provider, and target compliance frameworks via a guided wizard.

2
Run an assessment

Point SWAO at your application repository. Static code analysis, dynamic UI crawling (Playwright), SBOM generation, and secret detection run automatically across 14 passes.

3
Review findings

Explore results in the interactive TUI or HTML evidence report. Filter by severity, framework control, or file path. Every finding links back to the exact source that triggered it.

4
Plan and migrate

Export a migration runbook, risk register, and Terraform landing-zone scaffold. Re-assess after remediation to track compliance improvement over time.

Choose your edition

Community Edition is free and Apache 2.0 licensed. Consultant and Enterprise editions add production outputs, portal integration, and programme-scale capabilities via Accenture Professional Services.

Feature Community Consultant Enterprise
Assessment Types
Application Assessment (AI-assisted: static, dynamic, SBOM) Yes Yes Yes
Landing Zone Assessment (fit/gap vs. your existing LZ) Yes Yes Yes
LLM Assessment (sovereignty benchmarking across LLM providers) Yes Yes Yes
Portfolio Assessment (100+ apps, wave planning) - - Roadmap
Adversarial Challenge Review (second LLM agent independently challenges every finding) - - Yes
Tools and Interface
CLI and interactive TUI Yes Yes Yes
LLM integration (Anthropic, OpenAI, Ollama, Amazon Bedrock Gateway, open-LLM providers) Yes Yes Yes
Context ingestion (CMDB, ServiceNow, FinOps reports, architecture docs) Yes Yes Yes
MCP server (Claude Code, Cursor, and other AI tools) - - Yes
Frameworks
22 Community Frameworks (AI 10 Pillars, BSI C5, BSI IT-Grundschutz 2023, DORA, EC CSF, EU AI Act, EU CRA, EUCS, GDPR, ISO 27001:2022, KRITIS-DE, LLM Selection, NCA CCC 2024 CSP, NCA CCC 2024 CST, NCA ECC 2024, NIS2, NIST SP 800-66r2 / HIPAA, OpenSSF Scorecard, PCI-DSS v4, SAMA CSF v1, SecNumCloud v3.2, SOC 2 Type II) Yes Yes Yes
Landing Zone Catalogues (12 EU sovereign and hyperscaler providers; customisable) Yes Yes Yes
Reports and Outputs
HTML evidence report (single-file, offline-capable) - Yes Yes
Portal and programme dashboard (HTML Editor) - - Yes
PDF report (branded with licensee details) - Yes Yes
Power BI export (.pbit template for dashboards and trends) - - Yes
Terraform and landing zone generation - - Yes
Advanced Delivery
Terraform LZ module stubs (pre-populated from LZ readiness assessment output) - - Roadmap
meshStack Developer Portal Building Block deployment - - Roadmap
Custom LZ catalogue standard (organisation-wide configuration replacement) - - Roadmap
Licence and Support
Licence Apache 2.0 Proprietary Proprietary
Support GitHub Discussions Accenture PS Accenture PS

See real assessment results

Live HTML publications generated by SWAO against the Sovereign Health demo workspace. Open in your browser - no login required.

Application Assessment
Full GDPR + BSI C5 compliance report for a fictitious patient-management application. Signal findings, risk register, and 7R migration strategy - all sourced from static and LLM analysis.
Open live report
Landing Zone Assessment
Fit/gap analysis comparing EU sovereign and hyperscaler cloud providers for the Sovereign Health application. Shows which providers meet data-residency and compliance requirements.
Open live report
LLM Assessment
Multi-LLM sovereignty benchmarking report. Evaluates language models against data-residency, GDPR, and BSI C5 requirements - per-model verdicts with sourced rationale.
Open live report
View all screenshots and samples

Get involved

SWAO is open source. Whether you are building with SWAO, contributing frameworks, or exploring an Accenture-led migration engagement, there is a path for you.

💬

Community Discussions

Ask questions, share custom frameworks, report issues, and follow release announcements on GitHub Discussions. The SWAO development team monitors this channel and welcomes community contributions.

Open Discussions
🏢

Accenture Professional Services

For Consultant or Enterprise Edition licences, programme-scale deployments, meshStack integration, or a guided cloud migration engagement, reach out via GitHub Discussions or your Accenture account team.

Contact via Discussions