An automated AWS Well-Architected review — across all six pillars
CloudArq reads your live AWS configuration through a read-only role and reports where it drifts from Well-Architected guidance — not just Security, but Cost, Reliability, Performance, Operational Excellence and Sustainability too. Every finding is tagged to its pillar control area and ships with the exact fix. An automated review that makes the official AWS workshop faster, not a replacement for it.
Updated 2026-07-20 · ~11 minute read
Who this is for
Teams running production workloads on AWS who want a fast, honest read on how their account stacks up against the Well-Architected Framework — before an official review workshop, before a funding round’s technical due diligence, or just as a standing health check. If you already run the AWS Well-Architected Tool with your account team, use this to gather the configuration evidence the questions ask for. If you’ve never done a review, start here to see where the obvious gaps are across all six pillars.
What the Well-Architected Framework is (one paragraph)
The AWS Well-Architected Framework is AWS’s set of design principles and best practices for building on AWS, organised into six pillars: Security, Cost Optimization, Reliability, Performance Efficiency, Operational Excellence, and Sustainability. An official Well-Architected Framework Review (WAFR) is a question-driven workshop you run in the AWS Well-Architected Tool. CloudArq automates the evidence side of that: it inspects your live configuration and reports, pillar by pillar, where real resources diverge from the framework’s guidance.
What each pillar asks of your AWS account
A whole-framework review touches all six — not the security pillar alone. Here is the one-line goal of each, with the control areas CloudArq maps checks to detailed below.
Security
Protect data, systems and identities across their lifecycle.
Cost Optimization
Run only what you need, at the right price, with no silent waste.
Reliability
Recover from failure and meet your availability commitments.
Performance Efficiency
Use the most efficient compute and storage for the job.
Operational Excellence
Run and evolve workloads through automation and observability.
Sustainability
Minimise the footprint of the cloud you actually consume.
Pillar by pillar, mapped to real checks
Each control area lists the scanner checks that evidence it. These are the real check IDs CloudArq runs — every finding carries remediation steps, and the whole audit is read-only.
How CloudArq groups the findings by pillar
Each finding ships with a copy-paste CLI / Terraform remediation step. CloudArq is read-only and never auto-fixes.
What this does — and does not do
CloudArq runs an automated review aligned to the six Well-Architected pillars: 105 distinct checks are mapped to pillar control areas, and each finding is grouped by pillar with an exact remediation step. It is read-only — a read-only IAM role with an ExternalId, AES-256-GCM at rest, EU-hosted in Helsinki — and it never stores your credentials, application data, database contents or S3 objects, and never auto-fixes.
It is not an official AWS Well-Architected Framework Review (WAFR), it confers no AWS badge, and a scanner shows posture — it does not certify or guarantee that your workload is Well-Architected. The framework’s question-based workshop covers design decisions and organisational context that live configuration cannot see; run that with your AWS account team and use this review to bring the evidence. CloudArq the business holds zero certifications of its own.
Frequently asked
- 01Is this an official AWS Well-Architected Framework Review (WAFR)?
- No. An official WAFR is a workshop you run in the AWS Well-Architected Tool with your account team or an APN partner, answering the framework’s questions across each pillar. CloudArq runs an automated, read-only review ALIGNED to the same six pillars: it inspects your live AWS configuration and metadata and reports where your resources drift from Well-Architected guidance. It is not a substitute for the AWS workshop and it confers no AWS badge — think of it as the evidence layer that makes the workshop faster.
- 02Which pillars does CloudArq actually cover?
- All six: Security, Cost Optimization, Reliability, Performance Efficiency, Operational Excellence, and Sustainability. This is a whole-framework review, not a security-only scan. The checks below are grouped under real pillar control areas — SEC, COST, REL, PERF, OPS and SUS — so a finding always tells you which pillar it belongs to.
- 03Does CloudArq change my AWS to fix the findings?
- No. CloudArq connects through a read-only IAM role with an ExternalId and reads configuration and metadata only — it never stores your credentials, application data, database contents, or S3 objects, and it never auto-fixes anything. Each finding ships with exact remediation steps (a CLI command or Terraform block) that you review and apply yourself. Detection plus the fix, never a hidden change to your account.
- 04How does CloudArq decide which checks map to which pillar?
- Each scanner check is mapped to a Well-Architected pillar control area in a backend mapping table that is the single source of truth. The count on this page is the number of distinct checks that carry a Well-Architected mapping — it is pinned by a drift-guard test, so the figure can never silently disagree with the backend. Cost-optimization waste alone (COST-3) spans around twenty distinct checks, which is why Cost is one of the deeper pillars here.
- 05Which CloudArq tier includes the Well-Architected mapping?
- The underlying resource checks run from the free Starter tier upward. The Well-Architected framework grouping is part of the Max tier’s full 8-framework set; the Pro tier maps four frameworks (CIS, SOC 2, ISO 27001, GDPR). Max also unlocks the AI Workload lens and AI-assisted remediation. See the pricing page for the exact tier breakdown.
- 06Does passing these checks make me “Well-Architected certified”?
- There is no such thing as a Well-Architected certification, and CloudArq does not issue or imply one. A scanner shows posture against the framework’s guidance; it does not certify or guarantee an outcome. CloudArq the business holds zero certifications of its own. What you get is an honest, current map of where your account aligns with the six pillars and exactly what to change.