Skip to main content
Pulumi logo Pulumi logo
  1. Docs
  2. Discovery & Governance
  3. Policies
  4. Policy Packs
  5. Pre-Built Packs

Pre-Built Packs

    Pulumi Cloud comes with pre-built policy packs that codify best practices for common security and compliance frameworks. These packs allow you to quickly evaluate your organization’s compliance posture and “shift left,” embedding continuous compliance directly into your IaC workflow. Proactively enforce controls, reduce misconfiguration risks before deployment, and help your organization meet its regulatory obligations with confidence.

    Why use pre-built packs?

    • Accelerate Adoption: Implement comprehensive governance controls in minutes without having to author policies from scratch.
    • Leverage Expert Knowledge: Packs are authored and maintained by Pulumi, incorporating deep expertise in cloud security best practices.
    • Enforce Consistency: Apply a single, version-controlled policy pack across your entire organization to ensure all teams and projects adhere to the same standards.
    • Proactive Risk Reduction: Catch common security risks and compliance violations during pulumi preview, long before they reach your production environments.

    Available policy packs

    This Pulumi Cloud feature is available in the Business Critical edition.

    That applies to every pack below except Pulumi Best Practices and AWS Organizations Tag Policies, which are available on the Team edition and above.

    The following pre-built policy packs are available out of the box in Pulumi Cloud.

    FrameworkSupported Cloud ProvidersEditionDescription
    CIS 8.1AWS, Azure, Google CloudBusiness CriticalEnforces CIS 8.1 controls to help organizations implement industry-recognized security best practices and benchmarks across multiple cloud providers.
    CIS KubernetesAWS (EKS), Azure (AKS), Google Cloud (GKE)Business CriticalEnforces CIS Kubernetes Benchmark controls for managed Kubernetes services, helping organizations secure their container orchestration platforms with industry-recognized best practices.
    CMMC 2.0AWSBusiness CriticalEnforces CMMC 2.0 practices for AWS resources, helping defense-industrial-base organizations meet Department of Defense cybersecurity maturity requirements.
    HITRUST CSF 11.5AWS, Azure, Google CloudBusiness CriticalProvides predefined controls that align cloud resources with HITRUST CSF requirements, helping organizations enforce security and compliance baselines across multiple providers.
    ISO/IEC 27001:2022AWS, Azure, Google CloudBusiness CriticalEnforces ISO/IEC 27001:2022 Annex A controls across multiple cloud providers, helping organizations align their cloud infrastructure with the international standard for information security management.
    NIST SP 800-53AWS, Azure, Google CloudBusiness CriticalEnforces NIST SP 800-53 rev. 5 security and privacy controls across multiple cloud providers, helping federal agencies and organizations meet rigorous compliance requirements.
    PCI DSS v4.0.1AWS, Azure, Google CloudBusiness CriticalEnforces PCI DSS v4.0.1 compliance controls across multiple cloud providers, ensuring payment card data security and helping organizations meet payment card industry standards.
    Pulumi Best PracticesAWS, Azure, Google CloudTeam and aboveOffers a foundational set of recommended governance and security controls, serving as a strong starting point for organizations seeking comprehensive security coverage.
    AWS Organizations Tag PoliciesAWS and AWS-NativeTeam and aboveIntegrates with AWS Organizations Tag Policies to validate that infrastructure as code resources have required tags before deployment. Learn more.

    A foundation for your governance strategy

    Our pre-built packs provide a strong foundation for cloud governance by covering common controls for major frameworks. However, every organization has unique requirements.

    We recommend that you enhance these pre-built packs with your own custom policies tailored to your specific business, security, and operational needs. Pulumi’s flexible Policy as Code framework allows you to author your own packs and add them to the same Policy Groups alongside pre-built packs, giving you complete and comprehensive coverage.

    Frequently asked questions (FAQ)

    How are pre-built packs updated and versioned?

    Policy Packs in the Pulumi Registry follow semantic versioning. We release new versions when we add coverage for new controls or fix existing policies. You can choose when to update to a new version in your Policy Group configuration.

    How do pre-built packs work with my own custom policies?

    They are designed to work together. You can add both a pre-built pack (like Pulumi Best Practices) and your own custom-authored policy pack to the same Policy Group. This allows you to enforce both general best practices and your organization-specific rules on the same set of stacks.

    For more information on authoring custom policy packs, see our Policy as Code get started guide.

      The infrastructure as code platform for any cloud.