---
name: vmwaresolutions-opsprocs-compliance
title: Compliance
description: As of 17 July 2025, new automated installations of Red Hat&reg; OpenShift&reg; for VMware® are no longer available for new or existing deployments of VMware Cloud Foundation for Classic - Automated instances. You can still use or delete your existing Red Hat OpenShift for VMware automated installations until 16 July 2026. The service will no longer be available from 17 July 2026.
last-updated: 2026-01-27
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/vmwaresolutions?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Compliance
{: #opsprocs-compliance}

As of 17 July 2025, new automated installations of Red Hat&reg; OpenShift&reg; for VMware® are no longer available for new or existing deployments of VMware Cloud Foundation for Classic - Automated instances. You can still use or delete your existing Red Hat OpenShift for VMware automated installations until 16 July 2026. The service will no longer be available from 17 July 2026.
{: deprecated}

Compliance is a set of requirements necessary to meet the minimum controls established by either a regulatory agency or industry best practices. Regularity compliance frameworks are usually broad frameworks that provide guidance on a broad range of technology, whereas industry best practices from vendors are typically technology specific to address technological risks.

The VMware Security Hardening Guides provide prescriptive guidance on how to deploy and operate VMware products in a secure manner. Guides for vSphere are provided in spreadsheet format, with rich metadata to allow for guideline classification and risk assessment. They also include script examples for enabling security automation. Comparison documents are provided if the list changes in guidance in successive versions of the guide.

Many of the controls that are documented in the VMware® Security Hardening Guides are incorporated in the IBM Cloud&reg; for VMware Solutions reference architecture and therefore, automatically deployed, ensure that you tailor the security posture of the platform to your own needs and enterprise policy. The VMware Security Hardening Guides provide the technology-specific controls that are required for you to complete this review. Caveonix RiskForesight automates this compliance task and provides additional regulatory agency guidance.

VMware Aria® Operations™ Manager provides monitoring of VMware objects for violations against the compliance rules in the vSphere Security Configuration Guide. The compliance alerts trigger on the VMware Cloud Foundation for Classic - Automated instance, hosts, virtual machines, distributed port groups, or distributed switches, allowing the investigation of the compliance violation. For Health Insurance Portability and Accountability Act (HIPAA) and Payment Card Industry Data Security Standard (PCI DSS) compliance, you can download VMware Aria Operations Manager Compliance Packs from the VMware Solutions Exchange website, licensed, and installed. These Compliance Packs provide Alerts, policies, and Reports to validate the vSphere resources against the HIPAA and PCI hardening guides.

## Related links
{: #opsprocs-compliance-links}

* [FortiGate Virtual Appliance](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-fortinetvm_considerations&format=markdown)
* [F5 BIG-IP](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-f5_considerations&format=markdown)
* [Caveonix RiskForesight](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-caveonix_considerations&format=markdown)
* [Operations Management on IBM Cloud](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-opsmgmt-intro&format=markdown)
* [VMware security hardening guides](https://www.vmware.com/resources/hardening-guides){: external}