Important

AuditKit automates technical control scanning. You still need auditors for certification.
CPA for SOC2: $15K-$30K • QSA for PCI-DSS: $15K-$50K • C3PAO for CMMC: $25K-$150K

Community Edition

$0

Free forever • Apache 2.0

View on GitHub
  • AWS, Azure, GCP (M365 via ScubaGear import)
  • SOC2, PCI-DSS v4.0.1, NIST 800-53
  • HIPAA (Technical Safeguards)
  • CIS Benchmarks (AWS, Azure, GCP)
  • FedRAMP, ISO 27001, GDPR, NIST CSF 2.0 (mappings)
  • CMMC: all 110 Level 1 + 2 practices reported, each gap with its fix and screenshot
  • Automated checks where your cloud config can prove it; evidence guidance elsewhere
  • Single account scanning
  • PDF, HTML, JSON, CSV output
  • Basic GKE checks (5, from the CIS GKE benchmark)
  • Multi-account scanning
  • Evidence package generator
  • Custom controls (YAML)
  • GCP Advanced (GKE deep security, Vertex AI)
  • Desktop GUI
  • Continuous monitoring
  • Drift detection
  • Community (GitHub Issues)

What AuditKit Actually Replaces

Not your auditor, and not the engineering hours to fix what is broken. What it displaces is the consultant you would otherwise hire to tell you what is broken in the first place, on every framework rather than one.

Framework Auditor or assessor
You still pay this
Consultant readiness
AuditKit replaces this
SOC 2 Type II CPA firm, $15K - $30K $20K - $80K
PCI-DSS v4.0.1 QSA, $15K - $50K $10K - $30K
CMMC Level 2 C3PAO, $25K - $150K
Phase 2 suspended; Phase 1 is self-assessed
$50K - $100K

AuditKit is $3,564/year and covers every framework in that table.

Ranges are industry estimates, not quotes; your scope drives the real number. AuditKit finds the gaps and hands you the commands to close them, but your engineers still do the closing.

Use Cases

Community Edition

  • Finding out where you stand, on one account
  • Closing gaps before you engage an auditor
  • Teams working from the CLI
  • Any of the ten frameworks, nothing gated

AuditKit

  • Handing an assessor a documented evidence package
  • Scanning a whole AWS Org, Azure MG or GCP Folder
  • Staying compliant between audits (drift detection, alerts)
  • Documenting a CMMC Level 2 self-assessment
  • GKE or Vertex AI environments