Assessed directly

These are checked against your cloud configuration. Counts are distinct criteria, requirements or practices per provider.

FrameworkAWSAzureGCP
SOC 2 Type II38 of 3837 of 3832 of 38
PCI DSS v4.0.1595949
CMMC Level 113 of 1713 of 179 of 17
CIS Benchmarks12510826

CMMC Level 2 (110 practices) is available in AuditKit Pro.

Derived through the crosswalk

These are not separate checks. Each is derived from the frameworks above through NIST 800-53, so coverage follows from what the scanner already assessed.

FrameworkAWSAzureGCPUnit
NIST 800-53 Rev 5778282controls (96 across all providers)
ISO 27001:2022464646controls
NIST CSF 2.0758283subcategories
HIPAA Security Rule171717safeguards
GDPR131414articles
FedRAMPLow, Moderate and High baselinesfiltered views of NIST 800-53

Compliance versus hardening: the first table is what an auditor asks for. CIS Benchmarks are security hardening, which improves your posture but is not itself a certification.