What AuditKit assesses, and how much of each
These are checked against your cloud configuration. Counts are distinct criteria, requirements or practices per provider.
| Framework | AWS | Azure | GCP |
|---|---|---|---|
| SOC 2 Type II | 38 of 38 | 37 of 38 | 32 of 38 |
| PCI DSS v4.0.1 | 59 | 59 | 49 |
| CMMC Level 1 | 13 of 17 | 13 of 17 | 9 of 17 |
| CIS Benchmarks | 125 | 108 | 26 |
CMMC Level 2 (110 practices) is available in AuditKit Pro.
These are not separate checks. Each is derived from the frameworks above through NIST 800-53, so coverage follows from what the scanner already assessed.
| Framework | AWS | Azure | GCP | Unit |
|---|---|---|---|---|
| NIST 800-53 Rev 5 | 77 | 82 | 82 | controls (96 across all providers) |
| ISO 27001:2022 | 46 | 46 | 46 | controls |
| NIST CSF 2.0 | 75 | 82 | 83 | subcategories |
| HIPAA Security Rule | 17 | 17 | 17 | safeguards |
| GDPR | 13 | 14 | 14 | articles |
| FedRAMP | Low, Moderate and High baselines | filtered views of NIST 800-53 | ||
Compliance versus hardening: the first table is what an auditor asks for. CIS Benchmarks are security hardening, which improves your posture but is not itself a certification.