Get your first compliance scan running in 5 minutes
Get your first compliance scan running in 5 minutes.
chmod +x auditkit./auditkit scangit clone https://github.com/guardian-nexus/AuditKit-Community-Edition
cd AuditKit-Community-Edition/scanner
go build ./cmd/auditkit
./auditkit scan
# 1. Configure AWS credentials
aws configure
# 2. Run scan
./auditkit scan -provider aws -framework soc2
# 3. Generate PDF report
./auditkit scan -provider aws -framework soc2 -format pdf -output report.pdf
Setup details: AWS Authentication →
# 1. Login to Azure
az login
export AZURE_SUBSCRIPTION_ID="your-subscription-id"
# 2. Run scan
./auditkit scan -provider azure -framework soc2
# 3. Generate PDF report
./auditkit scan -provider azure -framework soc2 -format pdf -output report.pdf
Setup details: Azure Authentication →
# 1. Login to GCP
gcloud auth application-default login
export GOOGLE_CLOUD_PROJECT=your-project-id
# 2. Run scan
./auditkit scan -provider gcp -framework soc2
# 3. Generate PDF report
./auditkit scan -provider gcp -framework soc2 -format pdf -output report.pdf
Setup details: GCP Authentication →
AuditKit SOC2 Compliance Scan Results
=====================================
AWS Account: 123456789012
Scan Time: 2025-10-19 14:30:00
Compliance Score: 72.5%
Controls Passed: 46/64
Critical Issues: 3 (FIX IMMEDIATELY)
High Priority: 6
Medium Priority: 4
CRITICAL - Fix These NOW:
[FAIL] CC6.6 - User MFA Enforcement
[FAIL] CC6.2 - S3 Bucket Public Access
[FAIL] CC6.1 - IAM Key Rotation
What this means: - Compliance Score: Of the controls that could be automatically checked, the percentage that passed. Controls needing manual evidence, and controls the scanner could not evaluate, are excluded rather than counted as failures. A resource type you do not use is also excluded, not counted as a pass. - Critical Issues: Security gaps requiring immediate attention - Each failed control shows: What's wrong and how to fix it
PDF Report - For auditors and management
./auditkit scan -format pdf -output report.pdf
HTML Report - Interactive, great for teams
./auditkit scan -format html -output report.html
JSON Report - For automation/CI/CD
./auditkit scan -format json -output results.json
AuditKit shows exact commands to fix each issue:
# Generate fix script
./auditkit fix -output fixes.sh
# Review the script
cat fixes.sh
# Run fixes (review first!)
bash fixes.sh
# Show improvement over time
./auditkit progress
# Compare last two scans
./auditkit compare
# PCI-DSS
./auditkit scan -framework pci
# CMMC Level 1 + 2 (all 110 practices reported; 5 of the 17 Level 1 practices reach a verdict on AWS)
./auditkit scan -framework cmmc
# NIST 800-53
./auditkit scan -framework 800-53
# All frameworks
./auditkit scan -framework all
Framework details: Frameworks →
Goal: Pass SOC2 Type II audit without hiring consultants
Steps:
1. Run initial scan: ./auditkit scan -framework soc2
2. Fix critical issues (usually takes 1-2 days)
3. Re-scan weekly to track progress
4. Generate final report for auditor
5. Collect evidence using evidence tracker
Timeline: Most startups fix 80%+ of issues in 2-4 weeks
Goal: Complete a CMMC Level 1 self-assessment, and see where you stand against Level 2
Steps:
1. Run CMMC scan: ./auditkit scan -framework cmmc
2. Fix automated controls (AC.L1-3.1.1, AC.L1-3.1.2, etc.)
3. Document manual controls (physical security, training)
4. Generate assessment report
5. Schedule C3PAO review with confidence
Note: Need automated checks for the 110 CMMC Level 2 practices? Try Pro free for 14 days →
Goal: Single compliance view across AWS + Azure + GCP
Steps:
# Scan all providers
./auditkit scan -provider aws -framework soc2 -format json -output aws-results.json
./auditkit scan -provider azure -framework soc2 -format json -output azure-results.json
./auditkit scan -provider gcp -framework soc2 -format json -output gcp-results.json
# Compare results
# Unified multi-cloud reporting is an AuditKit Pro feature
Solution:
aws configure
# Enter your AWS Access Key ID and Secret Access Key
Details: AWS Setup →
Solution:
az login
az account list # Find your subscription ID
export AZURE_SUBSCRIPTION_ID="your-sub-id"
Details: Azure Setup →
Solution:
gcloud auth application-default login
gcloud projects list # Find your project ID
export GOOGLE_CLOUD_PROJECT=your-project-id
Details: GCP Setup →
Common cause: Security services not enabled
Solution: Enable these first: - AWS: GuardDuty, Config, CloudTrail, Security Hub - Azure: Defender for Cloud, Azure Policy, Activity Logs - GCP: Security Command Center, Cloud Logging, Cloud KMS
Then re-scan.
Ready for CMMC Level 2 or advanced GCP features? Try Pro free for 14 days →