Common questions about AuditKit
Common questions about AuditKit.
No. AuditKit automates the technical controls portion of compliance audits, but you still need:
What AuditKit replaces: Technical consultant fees ($30,000 - $100,000) for infrastructure scanning and remediation
What you still need: Certified auditor/assessor for final certification
Think of AuditKit as doing the heavy lifting on infrastructure checks, so you can focus on organizational policies and procedures with your auditor.
No. AuditKit checks compliance controls; it does not look for vulnerabilities itself.
It does read what your vulnerability scanner found. The vulnerability practices (CMMC RA.L2-3.11.2, PCI DSS 11.3.1) are answered from what Amazon Inspector, Microsoft Defender for Cloud or GCP VM Manager actually reaches: every in-scope asset, scanned recently, or a named gap. Pro also measures open findings against a remediation window (RA.L2-3.11.3) and imports Nessus, Trivy and Grype reports for the assets the cloud scanner does not cover.
For security scanning itself, use tools like: - Prowler - AWS security scanner (AuditKit imports its results to broaden NIST 800-53 coverage) - Scout Suite - Multi-cloud security auditing - Trivy - Container vulnerability scanning
| Feature | Free | Pro ($297/mo) |
|---|---|---|
| AWS/Azure/GCP/M365 | Full support | Full support |
| SOC2, PCI-DSS, NIST 800-53 | All frameworks | All frameworks |
| CMMC Level 1 | 5 of 17 practices reach a verdict on AWS | 7 of 17 practices reach a verdict on AWS |
| CMMC Level 2 | All 110 practices reported for evidence | All 110 practices reported; 27 reach a verdict on AWS, 83 carry evidence guidance |
| Controls assessed | 228 AWS, 277 Azure, 173 GCP | 314 AWS, 400 Azure, 293 GCP |
| GCP Advanced | 5 GKE controls | Deep GKE scanning (15) + Vertex AI (10) |
| Multi-Account | One at a time | AWS Orgs, Azure Mgmt, GCP Folders |
| Support | Community | Priority + 14-day trial |
Free version: $0 forever (open source)
Pro version: $297/month with 14-day free trial
Compare to traditional costs: - SOC2 consultant: $50,000+ - CMMC C3PAO assessment: $25,000+ - Compliance platforms (Vanta/Drata): $5,000+/year
Fully supported: - AWS (Amazon Web Services) - Azure (Microsoft Azure) - GCP (Google Cloud Platform) - M365 (Microsoft 365) via ScubaGear integration
Coverage: - AWS: 228 controls - 38 SOC2 criteria, 59 PCI-DSS requirements, 5 of 17 CMMC Level 1 practices automated; all 110 Level 1 + 2 practices reported - Azure: 277 controls - 38 SOC2 criteria, 63 PCI-DSS requirements, 4 of 17 CMMC Level 1 practices automated; Level 2 practices reported - GCP: 173 controls - 32 SOC2 criteria, 50 PCI-DSS requirements, 5 GKE controls; deep GKE scanning and Vertex AI are Pro - M365: 29+ Entra ID rules via ScubaGear
Free version (228 AWS, 277 Azure, 173 GCP controls): - Cloud Storage (GCS) - Cloud IAM - Compute Engine - VPC Networks - Cloud SQL - Cloud KMS - Cloud Logging
Pro version adds (20 additional checks): - GKE Security (10 checks) - Vertex AI Compliance (10 checks)
| Framework | Status | Coverage |
|---|---|---|
| CIS Benchmarks | Production | 70 AWS, 127 Azure, 93 GCP |
| FedRAMP | Production | Low / Moderate / High baselines (149 / 287 / 370 controls reported) |
| SOC2 Type II | Production | 38 criteria |
| PCI-DSS v4.0.1 | Production | 71 requirements |
| CMMC Level 1 | Production | 5 of 17 reach a verdict on AWS |
| CMMC Level 2 | Reported free; automated in Pro | 110 practices |
| NIST 800-53 Rev 5 | Production | 149 technical controls |
| ISO 27001:2022 | Production | 53 controls, derived via crosswalk |
| NIST CSF 2.0 | Production | 65 subcategories, derived via crosswalk |
| GDPR | Production | 16 articles, derived via crosswalk |
| HIPAA | Production | 30 safeguards, derived via crosswalk |
Free version: One account/project at a time. Switch between them:
# AWS - use profiles
auditkit scan -provider aws -profile production
auditkit scan -provider aws -profile staging
# Azure - change subscription
export AZURE_SUBSCRIPTION_ID="sub-1"
auditkit scan -provider azure
# GCP - change project
export GOOGLE_CLOUD_PROJECT=project-1
auditkit scan -provider gcp
Pro version: Scan entire organizations automatically:
# Scan AWS Organization
auditkit-pro scan -provider aws --scan-all
# Scan Azure Management Group
auditkit-pro scan -provider azure --scan-all
# Scan GCP Folders/Organization
auditkit-pro scan -provider gcp --scan-all
Common reasons:
1. Security services not enabled
Enable these first: - AWS: GuardDuty, Config, CloudTrail, Security Hub - Azure: Defender for Cloud, Azure Policy, Activity Logs - GCP: Security Command Center, Cloud Logging, Cloud KMS
2. Basic security controls missing - MFA not enforced - CloudTrail/logging not configured - Encryption not enabled - Public access on storage
3. Old infrastructure - IAM keys older than 90 days - Unpatched EC2 instances - Legacy security groups
Fix critical issues first, then re-scan.
No. AuditKit is read-only. It only: - Reads configuration - Checks security settings - Generates reports
It never modifies your infrastructure.
The auditkit fix command generates a script for you to review and run manually.
AWS: ReadOnlyAccess managed policy
Azure: Reader role
GCP: roles/viewer role
All read-only, no write permissions required.
CMMC Level 1 (17 practices) - 5 of the 17 reach a verdict on AWS in the free Community Edition; all 17 are reported - Protects Federal Contract Information (FCI) - Basic cybersecurity hygiene - Required for all DoW contractors - Self-assessment allowed
CMMC Level 2 (110 practices) - reported free; automated checks in AuditKit Pro - Protects Controlled Unclassified Information (CUI) - Based on NIST SP 800-171 Rev 2 - Required for contractors handling CUI - Requires C3PAO assessment
Example CUI: Technical specs, mission plans, personnel records, logistics data
If your DoW contract mentions CUI, you need Level 2.
$297/month with 14-day free trial (no credit card required)
Compare to: - C3PAO assessment: $25,000 - $150,000 - CMMC consultants: $50,000+ - Traditional compliance platforms: $5,000+/year (without CMMC L2)
November 10, 2025 - CMMC requirements start appearing in DoW contracts
DoW contractors must be compliant when specified in contract solicitations. Many contracts now include CMMC Level 1 or Level 2 requirements.
Yes, for technical controls. AuditKit automates: - Technical security configuration checks - Evidence collection guides - Remediation commands - Assessment reports
You still need to handle: - Organizational policies - Security awareness training - Incident response procedures - Physical security measures
Timeline: Most contractors fix 80%+ of technical issues in 2-4 weeks with AuditKit.
Single account scan: 2-5 minutes
Factors affecting speed: - Number of resources in your account - Number of regions (AWS) - Network latency - API rate limits
Pro multi-account scans: 10-30 minutes depending on organization size
Not currently. AuditKit scans all supported services for the chosen framework. The -services flag shown in auditkit scan --help is accepted but not yet honoured — it does not narrow the scan.
Workaround: Run scan, then filter results in JSON output:
auditkit scan -format json -output results.json
jq '.controls[] | select(.category == "Storage")' results.json
Yes. AuditKit works great in CI/CD:
# In your CI pipeline
auditkit scan -provider aws -framework soc2 -format json -output results.json
# Check compliance score
SCORE=$(jq '.score' results.json)
if (( $(echo "$SCORE < 80" | bc -l) )); then
echo "Compliance score too low: $SCORE%"
exit 1
fi
Cloud providers have API rate limits. If you hit them:
AWS:
# Reduce concurrent requests (Pro only)
auditkit-pro scan --scan-all --max-concurrent 2
All providers: - Run scans during off-peak hours - Increase service quotas in cloud console - Contact cloud provider support
Terminal output - Quick results
auditkit scan
PDF - For auditors and management
auditkit scan -format pdf -output report.pdf
HTML - Tabbed: failed, passed and manual controls
auditkit scan -format html -output report.html
JSON - For automation
auditkit scan -format json -output results.json
Not in the Free version. Reports follow standard compliance framework formats.
Pro version: Reports include: - Watermarking with license info
Not for Jira or ServiceNow. The AuditKit Pro daemon already posts scan alerts natively to Slack and Microsoft Teams, and to any webhook, SMTP mailbox or syslog target.
Workaround: Use JSON output with custom scripts:
# Export results to JSON
auditkit scan -format json -output results.json
# Parse and create Jira tickets
python create-jira-tickets.py results.json
Yes! AuditKit can import Prowler scan results directly:
# Run Prowler scan first
prowler aws --output-formats json -o prowler-output
# Import into AuditKit with framework mapping
auditkit integrate -source prowler -file prowler-output.json
# Generate PDF report from Prowler results
auditkit integrate -source prowler -file prowler-output.json -format pdf -output prowler-report.pdf
This maps Prowler findings to SOC2, PCI-DSS, CMMC, HIPAA, and other compliance frameworks.
AuditKit uses CISA ScubaGear for M365 scanning:
# 1. Install ScubaGear (Windows PowerShell)
Install-Module -Name ScubaGear
# 2. Run ScubaGear
Invoke-SCuBA -ProductNames aad,exo,sharepoint,teams -OutPath ./ScubaResults
# 3. Import into AuditKit
auditkit integrate -source scubagear -file ScubaResults/ScubaResults.json
Solution:
aws configure
# Enter your AWS Access Key ID and Secret Access Key
Solution:
az login
export AZURE_SUBSCRIPTION_ID="your-subscription-id"
Solution:
gcloud auth application-default login
export GOOGLE_CLOUD_PROJECT=your-project-id
Cause: IAM user/service account lacks required permissions
Solution:
- AWS: Attach ReadOnlyAccess policy
- Azure: Grant Reader role
- GCP: Grant roles/viewer role
This is normal. Some controls require manual verification: - Physical security measures - Security awareness training - Vendor management processes - Incident response procedures
Generate evidence tracker for manual controls:
auditkit evidence -format html -output evidence-tracker.html
Vanta/Drata: - Full compliance platforms ($5,000+/year) - Include policy management, vendor tracking, employee training - Automated evidence collection - Great for SOC2, but expensive
AuditKit: - Technical control scanning only - Free for SOC2/PCI/CMMC L1 - $297/month for CMMC L2 + advanced features - Open source, self-hosted
Use AuditKit if: You want technical scanning without paying for full compliance platform
Prowler/Scout Suite: - Security scanners (not compliance-focused) - Check 1000+ security findings - No compliance framework mapping - No evidence collection guides
AuditKit: - Compliance scanners (not security-focused) - Check 219 AWS / 174 Azure / 133 GCP compliance controls - Maps to SOC2, PCI-DSS, CMMC, NIST 800-53 - Includes evidence collection guides
Use both: Prowler for security, AuditKit for compliance
Manual compliance: - Take screenshots manually (days) - Document everything in spreadsheets - Hope you didn't miss anything - Pay consultant $50,000+
AuditKit: - Automated scanning (5 minutes) - Generate reports instantly - Evidence guides included - Free (or $297/month for Pro)
What AuditKit removes: the manual hunt for what to collect. Every control ships with the evidence that triggered it, a console link and a step-by-step collection guide, so the work is a checklist rather than a search.
Documentation: - Getting Started → - Setup Guides → - CLI Reference → - Framework Guides →
Support: - GitHub Issues - Newsletter - Pro Support: info@auditkit.io
Try Pro: - 14-day free trial →