How does compliance scanning work in air-gapped environments?
In air-gapped environments, compliance scanning works by deploying the entire scanning platform inside the isolated network: the server, benchmark content, scan engine, and reporting all operate with zero outbound connectivity. Benchmark definition updates are RSA-signed and verified by each agent; software updates arrive as offline media with published checksums through a controlled transfer process. CISGuard supports air-gapped deployment as a first-class configuration for classified government, defense, and critical-infrastructure networks where SaaS scanners cannot operate.
The longer answer.
The design constraints are strict: no license phone-home, no cloud-hosted console, no telemetry, and no dependency on internet-delivered content updates during operation. Tools designed as SaaS with an "offline mode" typically fail one or more of these constraints; air-gapped operation has to be an architectural decision, not a feature flag.
CISGuard's per-deployment licensing fits this model because entitlement lives with the installation rather than a cloud account. Benchmark definition updates are RSA-signed and verified by each agent, software updates ship as offline media with published checksums, and deployments are onboarded by CISGuard engineers who handle the transfer-process integration with the customer's security procedures.
More questions on Deployment?
Our compliance engineers can show you exactly how CISGuard handles Deployment in a briefing scoped to your environment.