Skip to main content
All answers

What is a compliance exception?

A compliance exception is a documented deviation from a required control, with a formally approved compensating control documenting equivalent risk reduction. Exceptions exist because no control set perfectly fits every environment: legacy systems, vendor constraints, and operational realities sometimes require deviation. Auditors expect exception registers with approval chains, supporting evidence, and auto-expiry to prevent stale waivers.

The longer answer.

A good exception records which control is not met, on which assets, why, what compensates for it, who approved it and when it expires. Without the expiry, exceptions become permanent and the register stops reflecting real risk.

In CISGuard, approved exceptions are applied to scan results, so excepted controls are reported as exceptions rather than failures, and each one keeps its approval trail for the auditor. The exception lifecycle is included in every license tier.

More questions on Fundamentals?

Our compliance engineers can show you exactly how CISGuard handles Fundamentals in a briefing scoped to your environment.