Skip to main content
All answers

How does compliance scanning work in air-gapped environments?

In air-gapped environments, compliance scanning works by deploying the entire scanning platform inside the isolated network: the server, benchmark content, scan engine, and reporting all operate with zero outbound connectivity. Benchmark definition updates are RSA-signed and verified by each agent; software updates arrive as offline media with published checksums through a controlled transfer process. CISGuard supports air-gapped deployment as a first-class configuration for classified government, defense, and critical-infrastructure networks where SaaS scanners cannot operate.

The longer answer.

The design constraints are strict: no license phone-home, no cloud-hosted console, no telemetry, and no dependency on internet-delivered content updates during operation. Tools designed as SaaS with an "offline mode" typically fail one or more of these constraints; air-gapped operation has to be an architectural decision, not a feature flag.

CISGuard's per-deployment licensing fits this model because entitlement lives with the installation rather than a cloud account. Benchmark definition updates are RSA-signed and verified by each agent, software updates ship as offline media with published checksums, and deployments are onboarded by CISGuard engineers who handle the transfer-process integration with the customer's security procedures.

More questions on Deployment?

Our compliance engineers can show you exactly how CISGuard handles Deployment in a briefing scoped to your environment.