Tech riderRev. 3 Oct 2026
- 1Runs onLinux, Mac, self-hosted
- 2CostsFree plan
- 3Terraform analysisNo
- 4Kubernetes analysisNo
- 5CloudFormation analysisYes
- 6Custom policiesYes
- 7Secrets detectionYes
7 lines stated Written from the maker's own pages: github.com

Overview
cfn-nag is ranked #15 of 27 in infrastructure testing tools on Specifiction. It runs on Linux, macOS, Self-hosted. There is a free plan.
cfn-nag plans and pricing
All plansCompared on infrastructure testing tools
- Free plan
- Yesgithub.com
- Terraform analysis
- Nogithub.com
- Kubernetes analysis
- Nogithub.com
- CloudFormation analysis
- Yesgithub.com
- Custom policies
- Yesgithub.com
- Secrets detection
- Yesgithub.com
Facts
- Purpose
- cfn-nag scans CloudFormation templates for patterns that may indicate insecure infrastructure.github.com · 3 Oct 2026
- Checks
- The project lists checks for overly permissive IAM and security group rules, disabled access logs or encryption, and password literals.github.com · 3 Oct 2026
- Install
- The project documents installation with RubyGems and Homebrew, and requires Ruby 2.5 or later for gem installation.github.com · 3 Oct 2026
- Template inputs
- The scanner processes JSON, .template, YAML, and YML files and recursively scans subdirectories when given a directory.github.com · 3 Oct 2026
- Output
- Results go to standard output; JSON output is available, and failures return a non-zero exit code while warnings return success.github.com · 3 Oct 2026
- Docker
- A Dockerfile is provided, and the project says its image is published as stelligent/cfn_nag on Docker Hub.github.com · 3 Oct 2026
- Integrations
- The project documents running cfn-nag in GitHub Actions workflows and deploying it in AWS CodePipeline through the AWS Serverless Application Repository.github.com · 3 Oct 2026
- Rule customization
- Users can filter checks with profiles and deny lists, suppress rules per resource, and develop custom rules distributed as gems or loaded from S3.github.com · 3 Oct 2026
- Template analysis limit
- Static analysis cannot see parameter values supplied at deployment unless users provide those values through a JSON file.github.com · 3 Oct 2026
- Conditional analysis limit
- By default, cfn-nag substitutes the true outcome for Fn::If, so rules do not inspect false outcomes unless condition values are provided.github.com · 3 Oct 2026
- Offline use
- The gem specification describes cfn-nag as a static analysis tool that must work without network connectivity, while noting S3 rule retrieval is optional.github.com · 3 Oct 2026
- License
- The project uses the MIT License, which grants permission to use, copy, modify, merge, publish, distribute, sublicense, and sell the software subject to its terms.github.com · 3 Oct 2026
- Support
- The project directs users to submit bug reports and feature requests through its GitHub issue tracker.github.com · 3 Oct 2026
Best cfn-nag alternatives
See all 12 All accessCh 01 Chef InSpec Free planFree trialAPI Free to start7.5 All accessCh 02 Conftest Free planLinuxMac Free to start7.4 All accessCh 03 kubeconform Free planLinuxMac Free to start7.2 All accessCh 04 Test Kitchen Free planLinuxMac Free to start7.2 All accessCh 05 AWS CloudFormation Free planAPILinux Free to start7.1 All accessCh 06 Sonobuoy LinuxMac 7.1
Where it ranks on Specifiction
Is cfn-nag yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- github.com/stelligent/cfn_nag· checked 3 Oct 2026
- github.com/stelligent/cfn_nag/blob/master/cfn-nag.· checked 3 Oct 2026
- github.com/stelligent/cfn_nag/blob/master/LICENSE.· checked 3 Oct 2026
