Get your first compliance scan running in 5 minutes.

Prerequisites

Installation

Option 1: Download Binary (Fastest)

  1. Go to Releases
  2. Download binary for your OS (Linux, macOS, Windows)
  3. Make it executable: chmod +x auditkit
  4. Run: ./auditkit scan

Option 2: Build from Source

git clone https://github.com/guardian-nexus/AuditKit-Community-Edition
cd AuditKit-Community-Edition/scanner
go build ./cmd/auditkit
./auditkit scan

Your First Scan

AWS

# 1. Configure AWS credentials
aws configure

# 2. Run scan
./auditkit scan -provider aws -framework soc2

# 3. Generate PDF report
./auditkit scan -provider aws -framework soc2 -format pdf -output report.pdf

Setup details: AWS Authentication →

Azure

# 1. Login to Azure
az login
export AZURE_SUBSCRIPTION_ID="your-subscription-id"

# 2. Run scan
./auditkit scan -provider azure -framework soc2

# 3. Generate PDF report
./auditkit scan -provider azure -framework soc2 -format pdf -output report.pdf

Setup details: Azure Authentication →

GCP

# 1. Login to GCP
gcloud auth application-default login
export GOOGLE_CLOUD_PROJECT=your-project-id

# 2. Run scan
./auditkit scan -provider gcp -framework soc2

# 3. Generate PDF report
./auditkit scan -provider gcp -framework soc2 -format pdf -output report.pdf

Setup details: GCP Authentication →

Understanding Your Results

Terminal Output

AuditKit SOC2 Compliance Scan Results
=====================================
AWS Account: 123456789012
Scan Time: 2025-10-19 14:30:00

Compliance Score: 72.5%
Controls Passed: 46/64

Critical Issues: 3 (FIX IMMEDIATELY)
High Priority: 6
Medium Priority: 4

CRITICAL - Fix These NOW:
[FAIL] CC6.6 - User MFA Enforcement
[FAIL] CC6.2 - S3 Bucket Public Access
[FAIL] CC6.1 - IAM Key Rotation

What this means: - Compliance Score: Of the controls that could be automatically checked, the percentage that passed. Controls needing manual evidence, and controls the scanner could not evaluate, are excluded rather than counted as failures. A resource type you do not use is also excluded, not counted as a pass. - Critical Issues: Security gaps requiring immediate attention - Each failed control shows: What's wrong and how to fix it

Report Types

PDF Report - For auditors and management

./auditkit scan -format pdf -output report.pdf

HTML Report - Interactive, great for teams

./auditkit scan -format html -output report.html

JSON Report - For automation/CI/CD

./auditkit scan -format json -output results.json

Next Steps

1. Fix Critical Issues

AuditKit shows exact commands to fix each issue:

# Generate fix script
./auditkit fix -output fixes.sh

# Review the script
cat fixes.sh

# Run fixes (review first!)
bash fixes.sh

2. Track Your Progress

# Show improvement over time
./auditkit progress

# Compare last two scans
./auditkit compare

3. Scan Other Frameworks

# PCI-DSS
./auditkit scan -framework pci

# CMMC Level 1 + 2 (all 110 practices reported; 5 of the 17 Level 1 practices reach a verdict on AWS)
./auditkit scan -framework cmmc

# NIST 800-53
./auditkit scan -framework 800-53

# All frameworks
./auditkit scan -framework all

Framework details: Frameworks →

Common Use Cases

For Startups: SOC2 Preparation

Goal: Pass SOC2 Type II audit without hiring consultants

Steps: 1. Run initial scan: ./auditkit scan -framework soc2 2. Fix critical issues (usually takes 1-2 days) 3. Re-scan weekly to track progress 4. Generate final report for auditor 5. Collect evidence using evidence tracker

Timeline: Most startups fix 80%+ of issues in 2-4 weeks

For DoW Contractors: CMMC Compliance

Goal: Complete a CMMC Level 1 self-assessment, and see where you stand against Level 2

Steps: 1. Run CMMC scan: ./auditkit scan -framework cmmc 2. Fix automated controls (AC.L1-3.1.1, AC.L1-3.1.2, etc.) 3. Document manual controls (physical security, training) 4. Generate assessment report 5. Schedule C3PAO review with confidence

Note: Need automated checks for the 110 CMMC Level 2 practices? Try Pro free for 14 days →

For Multi-Cloud: Unified Compliance

Goal: Single compliance view across AWS + Azure + GCP

Steps:

# Scan all providers
./auditkit scan -provider aws -framework soc2 -format json -output aws-results.json
./auditkit scan -provider azure -framework soc2 -format json -output azure-results.json
./auditkit scan -provider gcp -framework soc2 -format json -output gcp-results.json

# Compare results
# Unified multi-cloud reporting is an AuditKit Pro feature

Troubleshooting

"Error: AWS credentials not configured"

Solution:

aws configure
# Enter your AWS Access Key ID and Secret Access Key

Details: AWS Setup →

"Error: Azure subscription not found"

Solution:

az login
az account list  # Find your subscription ID
export AZURE_SUBSCRIPTION_ID="your-sub-id"

Details: Azure Setup →

"Error: GCP project not found"

Solution:

gcloud auth application-default login
gcloud projects list  # Find your project ID
export GOOGLE_CLOUD_PROJECT=your-project-id

Details: GCP Setup →

"Compliance score is very low (< 30%)"

Common cause: Security services not enabled

Solution: Enable these first: - AWS: GuardDuty, Config, CloudTrail, Security Hub - Azure: Defender for Cloud, Azure Policy, Activity Logs - GCP: Security Command Center, Cloud Logging, Cloud KMS

Then re-scan.

Getting Help

What's Next?

Ready for CMMC Level 2 or advanced GCP features? Try Pro free for 14 days →

Ready for CMMC Level 2 or advanced GCP features?

Start Free Trial →