⚠️ CMMC NOW MANDATORY: All new DoD contracts require CMMC (effective Nov 10, 2025)

AuditKit Pro

Identify all 110 CMMC Level 2 gaps in 30 minutes. Know what to fix before paying a C3PAO.

110
CMMC Level 2 Practices
30 min
To Identify All Gaps
$297
Per Month
$50K+
Savings vs Consultants
Start 14-Day Free Trial

14-day free trial • $297/month after trial • Cancel anytime

Stop Paying Consultants to Run Scans

Hiring Consultants

$50,000+
  • Initial gap assessment: $15-30K
  • Remediation guidance: $20-40K
  • Documentation prep: $15-30K
  • Weeks of back-and-forth
  • Manual evidence collection
  • One-time assessment
  • Still need C3PAO ($25-75K)

AuditKit Pro (12 months)

$3,564
  • Gap analysis in 30 minutes
  • Specific remediation steps included
  • Evidence package generator
  • Unlimited re-scans
  • Automated evidence collection
  • Continuous monitoring
  • Still need C3PAO ($25-75K)

Save $46,000+ on prep work. Still budget for C3PAO certification.

What AuditKit Pro Actually Does

AuditKit Pro replaces expensive consultants, not C3PAO auditors. You still need a C3PAO for official certification ($25-75K), but you arrive at that assessment already knowing:

  • Exactly which of the 110 practices you're missing
  • Specific AWS/Azure/GCP configurations to fix
  • What evidence the C3PAO will ask for
  • That you'll pass before paying the assessment fee

Traditional approach: Pay consultants $50K to tell you what's wrong, then pay C3PAO $50K to verify you fixed it.
AuditKit approach: Pay $297/month to know what's wrong, fix it yourself, then pay C3PAO $50K knowing you'll pass.

Core Features

CMMC Level 2 Complete

All 110 CMMC Level 2 practices automated across AWS, Azure, GCP, and Microsoft 365. Real-time gap identification with specific remediation steps for each cloud provider.

./auditkit-pro scan -framework cmmc -verbose

Multi-Account Scanning

Scan entire AWS Organizations, Azure Management Groups, and GCP Folders with one command. Unified compliance reports across all accounts. Perfect for separate dev/staging/prod environments.

./auditkit-pro scan -framework cmmc --org-scan

GCP Advanced (NEW)

GKE Security: 10 checks for pod policies, network policies, RBAC, binary authorization.

Vertex AI Compliance: 10 checks for ML model governance, data access controls, audit logging.

./auditkit-pro scan -provider gcp --advanced

Professional Audit Workflow

Four features designed for C3PAO assessments. All work offline for air-gapped environments.

Evidence Package Generator

Generates auditor-ready ZIP files with screenshots, configuration dumps, logs, and documentation in the exact format C3PAOs expect. Saves 40+ hours of manual evidence collection per assessment.

./auditkit-pro evidence-package -framework cmmc -output ./audit

Exception & Waiver Management

Track approved exceptions with compensating controls, expiration dates, and risk acceptance documentation. Maintains audit trail for C3PAO review.

./auditkit-pro exception add -control AC.1.001

Continuous Monitoring Daemon

Scheduled scans with automated alerting via syslog, email, or webhook. Detects compliance drift in real-time. Air-gapped friendly for CMMC environments.

./auditkit-pro daemon start -schedule "0 2 * * *"

Multi-Environment Drift Detection

Compare dev/staging/prod environments to identify configuration drift. Ensures consistent security posture across all environments before C3PAO assessment.

./auditkit-pro drift-check -environments "dev,prod"

Desktop GUI

Maintenance Notice: The Desktop GUI is temporarily unavailable while we rebuild the interface. CLI features remain fully functional. Expected back soon.

Beautiful web-based dashboard that runs locally. No cloud dependencies. Air-gap compatible.

Dashboard

Dashboard

Real-time scores & trends

Findings

Findings Explorer

Search & filter by severity

Scan History

Scan History

Browse all past scans

Click any image to enlarge • Use arrow keys to navigate

Visual Dashboard

Real-time compliance scores, trends, and critical findings at a glance. Track progress across all your cloud accounts.

Scan History & Findings

Browse all past scans with search and filtering. Drill into findings by severity, framework, or provider. Export to PDF/HTML/CSV.

Everything in One Place

Evidence packages, exception management, drift detection, and scheduled scans - all accessible from your browser.

# Run the Desktop GUI
export AUDITKIT_PRO_LICENSE="your-license-key"
./auditkit-pro-desktop

# Browser opens to http://localhost:1337
# Change port if needed:
./auditkit-pro-desktop --port 8080

How It Works

# 1. Install AuditKit Pro (GitHub access provided after signup) git clone git@github.com:guardian-nexus/auditkit-pro.git cd auditkit-pro/scanner go build ./cmd/auditkit-pro
# 2. Run initial CMMC Level 2 assessment (30 minutes) ./auditkit-pro scan -provider aws -framework cmmc -verbose
# Output shows you exactly what's missing and how to fix it ✗ FAIL | AC.L2-3.1.3 | CUI access controls missing → Remediation: aws iam create-policy --policy-document file://cui-policy.json → Evidence needed: IAM policy JSON + console screenshot
# 3. Fix issues and re-scan (unlimited) ./auditkit-pro scan -provider aws -framework cmmc -verbose
# 4. Generate C3PAO-ready evidence package ./auditkit-pro evidence-package -framework cmmc -output ./cmmc-evidence
# 5. Schedule C3PAO knowing you'll pass ✓ All 110 practices passing - ready for C3PAO assessment

See It In Action

Real scan output and reports from actual customer environments

✓ What a PASS Looks Like

Controls that meet compliance requirements show specific evidence of what's configured correctly.

✓ PASS | CC6.6 - Authentication Controls Root account has MFA enabled → Meets SOC2 CC6.6, PCI DSS 8.3.1, HIPAA 164.312(a)(2)(i)
✓ PASS | CC6.3 - Encryption at Rest All 15 S3 buckets have encryption enabled → Meets SOC2 CC6.3, PCI DSS 3.4, HIPAA 164.312(a)(2)(iv)
✓ PASS | AC.L1-3.1.1 - Security Control IAM users have appropriate access restrictions

✗ What a FAIL Looks Like

Failed controls show exactly what's wrong, how to fix it, and what evidence you'll need for auditors.

✗ FAIL | CC6.1 - Access Controls Issue: 1 security groups have SSH open to 0.0.0.0/0 Security Group: sg-0ab56571076bcff37 (port 22) → Violates PCI DSS 1.2.1 (firewall config)
Fix: aws ec2 revoke-security-group-ingress \ --group-id sg-0ab56571076bcff37 \ --protocol tcp --port 22 --cidr 0.0.0.0/0
Evidence needed: 1. Go to EC2 → Security Groups 2. Screenshot 'Inbound rules' tab 3. Show NO rules with Source '0.0.0.0/0' for port 22

Interactive HTML Reports

Generate professional compliance reports with scores, failed controls, remediation steps, and direct console links.

HTML Report Score Dashboard

View examples: CMMC Level 2SOC2

Want to explore more examples?

Browse our full examples directory with scan outputs, PDF reports, terminal screenshots, and more evidence samples.

Browse All Examples →

Evidence Package Output

The evidence-package command generates C3PAO-ready ZIP files with organized evidence for every control.

# Generate evidence package for CMMC assessment ./auditkit-pro evidence-package -framework cmmc -output ./audit-evidence
✓ Evidence package generated: audit-evidence.zip
audit-evidence/ ├── 00-AUDIT-README.md # Instructions for auditors ├── 00-EXECUTIVE-SUMMARY.md # High-level summary ├── 01-compliance-report.pdf # PDF report ├── 01-compliance-report.html # HTML report (interactive) ├── 02-scan-results.json # Machine-readable results ├── 03-failed-controls/ # Evidence for failed controls │ ├── AC.1.001-access-control/ │ │ ├── README.md # Control details │ │ ├── evidence.txt # Scan evidence │ │ ├── screenshot-guide.md # Verification steps │ │ ├── console-urls.txt # Direct links │ │ └── remediation.sh # Fix script ├── 04-passed-controls/ # Evidence for passed controls ├── 05-manual-controls/ # Manual verification needed └── audit-evidence.zip # Complete ZIP archive

Real Customer Results

  • Defense contractor (50 employees): Found 23 CMMC gaps in 28 minutes. Fixed all issues in 3 weeks. Passed C3PAO assessment.
  • Aerospace company (200 employees): Evidence package saved 40+ hours of manual screenshot collection for SOC2 audit.
  • Engineering firm (15 employees): Identified critical SSH port exposure before C3PAO assessment. Would have failed without AuditKit Pro.

Frequently Asked Questions

Do I still need a C3PAO assessment?

Yes, for official CMMC Level 2 certification you need a C3PAO assessment ($25-75K). AuditKit Pro identifies gaps and generates evidence packages so you arrive at that assessment knowing you'll pass. This eliminates the risk of paying $50K for an assessment you fail.

How is this different from hiring consultants?

Consultants charge $15-30K just to run scans and tell you what's wrong, then another $20-40K for remediation guidance. AuditKit Pro runs the same scans for $297/month and gives you specific fix-it commands. You still may want consultants for complex architecture decisions, but you won't pay them $50K+ to run automated scans.

What's the difference between CMMC Level 1 and Level 2?

Level 1 (17 practices) protects Federal Contract Information (FCI). Level 2 (110 practices) protects Controlled Unclassified Information (CUI). If your DoD contracts involve CUI, you need Level 2. AuditKit Free includes Level 1, Pro includes both.

Does this work with government cloud?

Yes, AuditKit Pro supports both commercial cloud (AWS, Azure, GCP) and government cloud environments (AWS GovCloud, Azure Government). All 110 checks work identically across commercial and government regions.

How does multi-account scanning work?

AuditKit Pro scans entire AWS Organizations, Azure Management Groups, and GCP Folders with a single command. It aggregates results across all accounts and generates unified compliance reports. Perfect for organizations with separate dev/staging/prod accounts.

Can I re-scan after fixing issues?

Yes, unlimited re-scanning is included. Fix issues, re-scan immediately, and track compliance progress over time. No per-scan fees, no usage limits. Most customers scan daily during their prep period.

How does the 14-day trial work?

Click "Start 14-Day Free Trial" to begin. You'll receive GitHub access to the private auditkit-pro repository within 24 hours. Full access to CMMC Level 2 + all Pro features. Cancel anytime during trial - no questions asked.

Do the new features work in air-gapped environments?

Yes, all Pro features work offline including the daemon, evidence package generator, and drift detection. Designed specifically for defense contractors operating in classified/air-gapped networks.

What if I'm already working with consultants?

Perfect - use AuditKit Pro to validate their work. Run scans after they make changes to verify gaps are actually fixed. Many customers use this to reduce consultant hours by 50%+ since you're not paying them to manually check configurations.

Know What You're Missing in 30 Minutes

All 110 CMMC Level 2 practices scanned. Specific remediation steps. Evidence automation. $50K+ savings vs consultants.

Start 14-Day Free Trial

14-day free trial • $297/month after trial • Cancel anytime • No setup fees