Pricing
Community Edition free forever. AuditKit $297/month with a 14-day free trial.
Important
AuditKit automates technical control scanning. You still need auditors for certification.
CPA for SOC2: $15K-$30K • QSA for PCI-DSS: $15K-$50K • C3PAO for CMMC: $25K-$150K
Community Edition
Free forever • Apache 2.0
- Cloud Providers
- AWS, Azure, GCP (M365 via ScubaGear import)
- Frameworks
- SOC2, PCI-DSS v4.0.1, NIST 800-53
- HIPAA (Technical Safeguards)
- CIS Benchmarks (AWS, Azure, GCP)
- FedRAMP, ISO 27001, GDPR, NIST CSF 2.0 (mappings)
- CMMC: all 110 Level 1 + 2 practices reported, each gap with its fix and screenshot
- Automated checks where your cloud config can prove it; evidence guidance elsewhere
- Features
- Single account scanning
- PDF, HTML, JSON, CSV output
- Basic GKE checks (5, from the CIS GKE benchmark)
- Multi-account scanning
- Evidence package generator
- Custom controls (YAML)
- GCP Advanced (GKE deep security, Vertex AI)
- Desktop GUI
- Continuous monitoring
- Drift detection
- Support
- Community (GitHub Issues)
AuditKit
14-day free trial • Cancel anytime
- Cloud Providers
- AWS, Azure, GCP (M365 via ScubaGear import)
- Frameworks
- SOC2, PCI-DSS v4.0.1, NIST 800-53
- HIPAA (Technical Safeguards)
- CIS Benchmarks (AWS, Azure, GCP)
- FedRAMP, ISO 27001, GDPR, NIST CSF 2.0 (mappings)
- CMMC Level 1 (17 practices)
- CMMC Level 2 assessed (all 110 L1 + L2 practices; automated checks where the cloud can prove it, evidence guidance elsewhere)
- Features
- Multi-account scanning (AWS Orgs, Azure MGs, GCP Folders)
- PDF, HTML, JSON, CSV output
- Evidence package generator (auditor-ready)
- Custom controls (YAML-defined)
- GCP Advanced (GKE deep security + Vertex AI, 20 checks)
- Desktop GUI
- Continuous monitoring (scheduled scans, alerts to Slack, Teams, email or webhook)
- Drift detection
- Support
- Priority email
What AuditKit Actually Replaces
Not your auditor, and not the engineering hours to fix what is broken. What it displaces is the consultant you would otherwise hire to tell you what is broken in the first place, on every framework rather than one.
| Framework | Auditor or assessor You still pay this |
Consultant readiness AuditKit replaces this |
|---|---|---|
| SOC 2 Type II | CPA firm, $15K - $30K | $20K - $80K |
| PCI-DSS v4.0.1 | QSA, $15K - $50K | $10K - $30K |
| CMMC Level 2 | C3PAO, $25K - $150K Phase 2 suspended; Phase 1 is self-assessed |
$50K - $100K |
AuditKit is $3,564/year and covers every framework in that table.
Ranges are industry estimates, not quotes; your scope drives the real number. AuditKit finds the gaps and hands you the commands to close them, but your engineers still do the closing.
Use Cases
Community Edition
- Finding out where you stand, on one account
- Closing gaps before you engage an auditor
- Teams working from the CLI
- Any of the ten frameworks, nothing gated
AuditKit
- Handing an assessor a documented evidence package
- Scanning a whole AWS Org, Azure MG or GCP Folder
- Staying compliant between audits (drift detection, alerts)
- Documenting a CMMC Level 2 self-assessment
- GKE or Vertex AI environments