AuditKit supports multiple compliance frameworks for automated technical control scanning.

Supported Frameworks

Framework Status Automated Controls Cloud Providers
SOC2 Type II Production 38 of 43 criteria AWS, Azure, GCP
PCI-DSS v4.0.1 Production 71 requirements across all 12 groups AWS, Azure, GCP
CMMC Level 1 Production 5 of 17 practices AWS, Azure, GCP
CMMC Level 2 Reported; automated in Pro 110 practices AWS, Azure, GCP
CIS Benchmarks Production AWS: 70, Azure: 127, GCP: 93 AWS, Azure, GCP
NIST 800-53 Rev 5 Production 149 technical controls (covers FedRAMP), derived, of 1,196 in the catalog AWS, Azure, GCP
FedRAMP Production Low 81 of 149, Moderate 131 of 287, High 133 of 370 on AWS AWS, Azure, GCP
ISO 27001:2022 Production 53 controls, derived (53 on every provider, of 93 in Annex A) AWS, Azure, GCP
NIST CSF 2.0 Production 67 subcategories, derived (67 AWS, 65 Azure and GCP, of 106) AWS, Azure, GCP
GDPR Production 16 articles, derived AWS, Azure, GCP
HIPAA Security Rule Production 30 safeguards, derived AWS, Azure, GCP

Framework Categories

Production Ready

Fully tested, comprehensive coverage, used in production environments:

Automated in Pro

Community reports all 110 CMMC Level 1 and Level 2 practices - every failing check with its fix and the screen to photograph (5 of the 17 Level 1 practices reach a verdict on AWS, 4 on Azure and GCP). An AuditKit subscription turns those findings into the assessor's evidence package and adds deeper automated coverage:

Quick Comparison

By Industry

SaaS/Startups: SOC2 Type II
E-commerce/Payment Processing: PCI-DSS v4.0.1
DoW Contractors (FCI): CMMC Level 1
DoW Contractors (CUI): CMMC Level 2 (reported free, automated in Pro)
Federal Contractors: NIST 800-53 Rev 5
Healthcare: HIPAA (18 safeguards, derived via crosswalk)
Security Hardening: CIS Benchmarks

By Requirements

Customer demands compliance: SOC2
Processing credit cards: PCI-DSS
DoW contract requires it: CMMC
Federal agency requires it: NIST 800-53
Handling PHI: HIPAA
Security best practices: CIS Benchmarks

By Timeline

2-4 weeks: CMMC Level 1, Basic SOC2 prep, CIS hardening
2-3 months: SOC2 Type II certification
3-6 months: CMMC Level 2, PCI-DSS
6-12 months: NIST 800-53, HIPAA

Framework Details

SOC2 Type II

Purpose: Trust Services Criteria for service organizations
Certification: Requires CPA firm audit
Cost: $15,000 - $30,000 for audit
Timeline: 3-6 months preparation + 3-12 month observation period

Learn more →

PCI-DSS v4.0.1

Purpose: Payment Card Industry Data Security Standard
Certification: Requires QSA assessment
Cost: $15,000 - $50,000 for assessment
Timeline: 3-6 months preparation

Learn more →

CMMC

Purpose: Cybersecurity Maturity Model Certification for DoW
Certification:

Timeline:

Learn more →

CIS Benchmarks

Purpose: Security configuration best practices
Certification: Not a certification - industry-recognized hardening standards
Cost: Free to implement
Timeline: 2-4 weeks for basic hardening (IG1)

Current Coverage:

Learn more →

NIST 800-53 Rev 5

Purpose: Security controls for federal information systems
Certification: Not a certification (used by FedRAMP, FISMA)
Coverage: 149 automated technical controls
Timeline: 6-12 months for full implementation

Learn more →

HIPAA

Purpose: Healthcare data protection
Status: Production - 30 of the 75 Security Rule safeguards are reached on AWS
Note: Covers all 12 Technical Safeguards (164.312) and 18 of the 31 Administrative Safeguards (164.308). Does not cover Physical Safeguards (164.310), Organizational Requirements (164.314) or Policies and Documentation (164.316)

Learn more →

Scanning Frameworks

Single Framework

# SOC2
auditkit scan -provider aws -framework soc2

# PCI-DSS
auditkit scan -provider aws -framework pci

# CMMC Level 1
auditkit scan -provider aws -framework cmmc

# CMMC Level 1 + 2 - all 110 practices (Community reports all 110; Pro adds the evidence package and deeper automation)
auditkit-pro scan -provider aws -framework cmmc

# CIS Benchmarks
auditkit scan -provider aws -framework cis-aws

# NIST 800-53
auditkit scan -provider aws -framework 800-53

All Frameworks

# Scan all frameworks at once
auditkit scan -provider aws -framework all

Framework Crosswalks

AuditKit maps controls across frameworks. For example:

AWS IAM MFA enforcement maps to:

This means fixing one control improves compliance across multiple frameworks.

Compliance vs Security Hardening

Compliance Frameworks (SOC2, PCI, CMMC, NIST 800-53)

Security Hardening (CIS Benchmarks)

Best Practice: Use CIS Benchmarks alongside compliance frameworks. CIS provides technical depth that complements compliance requirements.

Choosing the Right Framework

Multiple Frameworks Required?

Many organizations need multiple frameworks:

Common combinations:

Good news: AuditKit scans once, reports on all frameworks

Framework Priorities

If you need multiple frameworks: 1. Start with broadest: SOC2 or NIST 800-53 2. Add security hardening: CIS Benchmarks 3. Add specific: PCI-DSS for payments, CMMC for DoW 4. Last: HIPAA (most organizational policies)

Security-first approach: 1. Start with CIS Benchmarks (security foundation) 2. Add compliance: SOC2, PCI, or CMMC as needed 3. Maintain both: CIS for ongoing hardening, compliance for audits

Getting Help

Framework-specific questions:

General support:

Next Steps