Find Every Gap Before Your Auditor Does
Multi-cloud compliance scanning with specific remediation for every finding. CLI scanner for engineers. Desktop dashboard for teams. Evidence packages your auditor expects.
14-day free trial • $297/month after trial • Cancel anytime
Stop Paying Consultants to Run Scans
What AuditKit Replaces
AuditKit replaces expensive consultants, not your auditors. You still need your auditor for official certification (CPA for SOC2, QSA for PCI-DSS, C3PAO for CMMC), but you arrive at that assessment already knowing:
- Exactly which controls you're failing
- Specific AWS/Azure/GCP configurations to fix
- What evidence your auditor will ask for
- That you'll pass before paying the assessment fee
Pay consultants $50K to tell you what's wrong, then pay auditors to verify you fixed it.
Pay $297/month to know what's wrong, fix it yourself, then pay your auditor knowing you'll pass.
That's $46,000+ back in your budget.
One Platform, Two Interfaces
A CLI scanner for engineers who automate everything, and a desktop dashboard for teams who need visibility. Both included with AuditKit Pro.
CLI Scanner
Terminal-based scanning for engineers. Run compliance checks from your command line, integrate with CI/CD pipelines, automate with cron. Works in air-gapped environments with zero external dependencies.
- 350+ automated checks across 10 frameworks
- AWS, Azure, GCP (Microsoft 365 via ScubaGear import)
- PDF, HTML, JSON, CSV output
- Fix scripts for every finding
Desktop GUI
Everything the CLI does, made visual. A local web dashboard with real-time compliance scores, findings explorer, scan history, and evidence management. Runs in your browser, no cloud dependencies.
- Real-time compliance scores and trends
- Search and filter findings by severity
- Scan history with drift tracking
- Evidence package management
Desktop GUI
Web-based dashboard that runs locally. No cloud dependencies. Air-gap compatible.
Visual Dashboard
Real-time compliance scores, trends, and critical findings at a glance. Track progress across all your cloud accounts and frameworks.
Scan History & Findings
Browse all past scans with search and filtering. Drill into findings by severity, framework, or provider. Export to PDF/HTML/CSV.
Everything in One Place
Evidence packages, exception management, drift detection, and scheduled scans, all accessible from your browser. No cloud account required.
How It Works
Built for CMMC Level 2
Every one of the 110 CMMC Level 2 practices assessed: automated checks where your cloud configuration can prove it, and structured evidence guidance where an assessor needs a document or a screenshot. Know exactly what to fix before your C3PAO assessment.
Defense Contractors
CMMC is now in effect for all new DoW contracts. AuditKit assesses all 110 Level 2 practices across your AWS, Azure and GCP environments, and folds in Microsoft 365 findings imported from ScubaGear: automated checks where your cloud configuration can prove it, and structured evidence guidance where an assessor needs a document. It generates C3PAO-ready evidence packages and remediation commands for every automated finding.
The Community Edition reports all 110 practices for free and automates Level 1. AuditKit adds automated Level 2 checks, multi-account scanning, evidence packages, and continuous monitoring.
Pro Features
Available with an AuditKit Pro subscription.
Multi-Account Scanning
Scan entire AWS Organizations, Azure Management Groups, and GCP Folders with one command. Unified compliance reports across all accounts. Perfect for separate dev/staging/prod environments.
Evidence Packages
Generates auditor-ready ZIP files with configuration dumps, logs and documentation in the format auditors expect, with a folder per control holding the finding, a console link and a step-by-step evidence guide.
Custom Controls NEW
Define your own security checks in YAML. Create organization-specific controls, tag requirements, naming conventions, and resource count validations. Execute custom checks alongside built-in frameworks.
Continuous Monitoring
Scheduled scans with automated alerting via syslog, email, or webhook. Detects compliance drift in real-time between assessments. Air-gapped friendly.
Drift Detection
Compare dev/staging/prod environments to identify configuration drift. Ensures consistent security posture across all environments before your audit.
Exceptions & Waivers
Record an approved exception against a control with a reason, an approver and an expiry date, so accepted risks stop appearing as open findings and the waiver register is ready for your assessor.
Auditor-Ready Evidence Packages
The evidence-package command generates an organized folder of evidence for every control, or a ZIP archive when the output path ends in .zip.
What AuditKit Finds
Representative scenarios from real compliance scans.
CMMC Level 2 Scan
Defense contractor • AWS, Azure, GCP
15 Level 2 practice gaps surfaced in seconds from a single AWS account, concentrated in identification and authentication, audit logging and protecting CUI. The same 110 practices are assessed on Azure and GCP. Every gap ships with the evidence that triggered it, a direct console link, and a remediation step. Evidence package generated with per-practice folders for C3PAO review.
SOC2 Audit Prep
SaaS company • AWS, Azure, GCP
Evidence package turned a scattered screenshot hunt into a checklist: every control gets its own folder with the finding, a direct console link, and a step-by-step evidence guide. PDF report, JSON export and an organised evidence ZIP, in one command.
PCI-DSS Assessment
E-commerce • AWS, Azure, GCP
Flagged SSH ports open to 0.0.0.0/0, console access without MFA and missing CloudTrail audit logging on AWS, with equivalent PCI requirements assessed on Azure and GCP. The kind of findings a QSA fails an assessment over.
Frequently Asked Questions
What compliance frameworks does AuditKit support?
AuditKit supports SOC2, PCI-DSS v4.0.1, CMMC (Level 1 + Level 2), HIPAA, NIST 800-53, NIST CSF 2.0, CIS Benchmarks (AWS, Azure, GCP), ISO 27001, FedRAMP, and GDPR. Cross-framework mappings mean a single scan maps findings across all applicable frameworks simultaneously.
Do I still need an auditor?
Yes. AuditKit replaces consultants, not auditors. You still need your CPA for SOC2, QSA for PCI-DSS, or C3PAO for CMMC. AuditKit ensures you arrive at that assessment already knowing every gap is fixed and your evidence is organized, so you pass on the first attempt instead of paying for a failed audit.
How is this different from hiring consultants?
Consultants charge $15-30K just to run scans and tell you what's wrong, then another $20-40K for remediation guidance. AuditKit runs the same scans for $297/month and gives you specific fix-it commands for every finding. You may still want consultants for complex architecture decisions, but you won't pay them $50K+ to run automated scans.
What's the difference between the CLI and Desktop GUI?
Both are included in your subscription. The CLI scanner is a terminal-based tool for engineers, good for automation, CI/CD integration, and scripting. The Desktop GUI is a local web dashboard that provides the same scanning capabilities with visual compliance scores, findings explorer, scan history, and evidence management. Use whichever fits your workflow, or both.
Does this work for CMMC Level 2?
Yes. AuditKit assesses all 110 CMMC Level 2 practices across AWS, Azure and GCP, folding in Microsoft 365 findings imported from ScubaGear - checked automatically against your cloud configuration where that is possible, and reported with evidence-collection guidance where an assessor needs a document or a screenshot. It generates C3PAO-ready evidence packages and remediation commands for every automated finding. The Community Edition reports all 110 practices for free and automates Level 1.
Can I re-scan after fixing issues?
Yes, unlimited re-scanning is included. Fix issues, re-scan immediately, and track compliance progress over time. No per-scan fees, no usage limits. Most customers scan daily during their prep period.
How does the 14-day trial work?
Click "Start 14-Day Free Trial" to begin. You'll get an email with your licence file (license.lic) attached - save it to ~/.auditkit-pro/license.lic - and reply with your GitHub username to be added to the private release repository, usually within 4 hours. Full access to all features including the Desktop GUI. Cancel anytime during trial, no questions asked.
Do all features work in air-gapped environments?
Yes, all features work offline including the Desktop GUI, daemon, evidence package generator, and drift detection. No cloud account, no SaaS dashboard, no telemetry. The tool runs wherever you have credentials.
What if I'm already working with consultants?
Use AuditKit to validate their work. Run scans after they make changes to verify gaps are actually fixed. Many customers use this to reduce consultant hours by 50%+ since you're not paying them to manually check configurations.
Know Exactly Where You Stand in 30 Minutes
350+ automated checks. 10 compliance frameworks. Specific remediation for every finding. Evidence packages your auditor expects. CLI + Desktop GUI included.
Start 14-Day Free Trial14-day free trial • $297/month after trial • Cancel anytime • No setup fees