What AuditKit assesses, and how much of each
AuditKit supports multiple compliance frameworks for automated technical control scanning.
| Framework | Status | Automated Controls | Cloud Providers |
|---|---|---|---|
| SOC2 Type II | Production | 38 of 43 criteria | AWS, Azure, GCP |
| PCI-DSS v4.0.1 | Production | 71 requirements across all 12 groups | AWS, Azure, GCP |
| CMMC Level 1 | Production | 5 of 17 practices | AWS, Azure, GCP |
| CMMC Level 2 | Reported; automated in Pro | 110 practices | AWS, Azure, GCP |
| CIS Benchmarks | Production | AWS: 70, Azure: 127, GCP: 93 | AWS, Azure, GCP |
| NIST 800-53 Rev 5 | Production | 149 technical controls (covers FedRAMP), derived, of 1,196 in the catalog | AWS, Azure, GCP |
| FedRAMP | Production | Low 81 of 149, Moderate 131 of 287, High 133 of 370 on AWS | AWS, Azure, GCP |
| ISO 27001:2022 | Production | 53 controls, derived (53 on every provider, of 93 in Annex A) | AWS, Azure, GCP |
| NIST CSF 2.0 | Production | 67 subcategories, derived (67 AWS, 65 Azure and GCP, of 106) | AWS, Azure, GCP |
| GDPR | Production | 16 articles, derived | AWS, Azure, GCP |
| HIPAA Security Rule | Production | 30 safeguards, derived | AWS, Azure, GCP |
Fully tested, comprehensive coverage, used in production environments:
Community reports all 110 CMMC Level 1 and Level 2 practices - every failing check with its fix and the screen to photograph (5 of the 17 Level 1 practices reach a verdict on AWS, 4 on Azure and GCP). An AuditKit subscription turns those findings into the assessor's evidence package and adds deeper automated coverage:
SaaS/Startups: SOC2 Type II
E-commerce/Payment Processing: PCI-DSS v4.0.1
DoW Contractors (FCI): CMMC Level 1
DoW Contractors (CUI): CMMC Level 2 (reported free, automated in Pro)
Federal Contractors: NIST 800-53 Rev 5
Healthcare: HIPAA (18 safeguards, derived via crosswalk)
Security Hardening: CIS Benchmarks
Customer demands compliance: SOC2
Processing credit cards: PCI-DSS
DoW contract requires it: CMMC
Federal agency requires it: NIST 800-53
Handling PHI: HIPAA
Security best practices: CIS Benchmarks
2-4 weeks: CMMC Level 1, Basic SOC2 prep, CIS hardening
2-3 months: SOC2 Type II certification
3-6 months: CMMC Level 2, PCI-DSS
6-12 months: NIST 800-53, HIPAA
Purpose: Trust Services Criteria for service organizations
Certification: Requires CPA firm audit
Cost: $15,000 - $30,000 for audit
Timeline: 3-6 months preparation + 3-12 month observation period
Purpose: Payment Card Industry Data Security Standard
Certification: Requires QSA assessment
Cost: $15,000 - $50,000 for assessment
Timeline: 3-6 months preparation
Purpose: Cybersecurity Maturity Model Certification for DoW
Certification:
Timeline:
Purpose: Security configuration best practices
Certification: Not a certification - industry-recognized hardening standards
Cost: Free to implement
Timeline: 2-4 weeks for basic hardening (IG1)
Current Coverage:
Purpose: Security controls for federal information systems
Certification: Not a certification (used by FedRAMP, FISMA)
Coverage: 149 automated technical controls
Timeline: 6-12 months for full implementation
Purpose: Healthcare data protection
Status: Production - 30 of the 75 Security Rule safeguards are reached on AWS
Note: Covers all 12 Technical Safeguards (164.312) and 18 of the 31 Administrative Safeguards (164.308). Does not cover Physical Safeguards (164.310), Organizational Requirements (164.314) or Policies and Documentation (164.316)
# SOC2
auditkit scan -provider aws -framework soc2
# PCI-DSS
auditkit scan -provider aws -framework pci
# CMMC Level 1
auditkit scan -provider aws -framework cmmc
# CMMC Level 1 + 2 - all 110 practices (Community reports all 110; Pro adds the evidence package and deeper automation)
auditkit-pro scan -provider aws -framework cmmc
# CIS Benchmarks
auditkit scan -provider aws -framework cis-aws
# NIST 800-53
auditkit scan -provider aws -framework 800-53
# Scan all frameworks at once
auditkit scan -provider aws -framework all
AuditKit maps controls across frameworks. For example:
AWS IAM MFA enforcement maps to:
This means fixing one control improves compliance across multiple frameworks.
Best Practice: Use CIS Benchmarks alongside compliance frameworks. CIS provides technical depth that complements compliance requirements.
Many organizations need multiple frameworks:
Common combinations:
Good news: AuditKit scans once, reports on all frameworks
If you need multiple frameworks: 1. Start with broadest: SOC2 or NIST 800-53 2. Add security hardening: CIS Benchmarks 3. Add specific: PCI-DSS for payments, CMMC for DoW 4. Last: HIPAA (most organizational policies)
Security-first approach: 1. Start with CIS Benchmarks (security foundation) 2. Add compliance: SOC2, PCI, or CMMC as needed 3. Maintain both: CIS for ongoing hardening, compliance for audits
Framework-specific questions:
General support: