Regulatory compliance
Three frameworks from every scan.CIS hardening for the rest.
Every CIS control CISGuard evaluates carries its NIST 800-53, ISO 27001 and SOC 2 references, so one scan produces three framework coverage reports. The same hardening is the technical baseline that HIPAA, PCI-DSS, DORA, NIS2 and regional regulators expect.
- Frameworks mapped
- NIST SP 800-53 Rev. 5, ISO/IEC 27001:2022, SOC 2
- Evidence base
- 22 CIS Benchmarks, 3,933 controls, 3,283 automated
- Coverage report formats
- JSON, CSV and SARIF, alongside PDF and HTML reports
- Status per control
- Satisfied, partially satisfied or not met, with scan timestamps
- Evidence cadence
- Continuous: every scheduled scan updates every report
- Deployment
- On-premises, private cloud or air-gapped
Mapped from every scan
Three frameworks, one scan.
Each CIS control is tagged with its framework references. The coverage report lists every mapped control, its status, the CIS controls behind it and the most recent scan timestamps.
- NIST 800-5350controls
NIST SP 800-53 Rev. 5 controls across 13 control families, each tied to the CIS benchmark checks that evidence it.
Read the deep dive - ISO 2700136Annex A controls
ISO/IEC 27001:2022 Annex A controls across the A.5, A.7 and A.8 themes, with Clause 9.1 monitoring evidenced continuously.
Read the deep dive - SOC 225criteria
SOC 2 Trust Services Criteria across CC1 to CC8, A1, C1 and P1, with the period evidence Type II demands.
Read the deep dive
Supported by the same hardening
Regulations the same controls support.
These regulations do not get a separate mapping. They get the CIS Benchmark evidence they ask for, with per-control history, drift detection and the exception register, from the same scans.
- United States
HIPAA
CISGuard automates the technical safeguards required by the HIPAA Security Rule (45 CFR Part 164 Subpart C) and generates the audit trail OCR investigations demand.
Read the deep dive - United States
FedRAMP
CISGuard maps 50 NIST 800-53 controls supporting FedRAMP Moderate and High baselines, with air-gapped deployment for High and IL4/IL5 environments and automated Continuous Monitoring satisfying CA-7.
Read the deep dive - Global
PCI-DSS
CISGuard automates the PCI-DSS technical configuration requirements that QSAs spend the most assessment hours validating: secure configurations, change detection, and audit logging.
Read the deep dive - Germany / European Automotive
TISAX
CISGuard automates the technical Annex A controls that TISAX assessors validate, generating the continuous evidence VDA ISA requires for AL2 and AL3 certification.
Read the deep dive - European Union
DORA
CISGuard automates the ICT risk management technical controls DORA mandates for EU financial entities: system hardening, continuous monitoring, drift detection, and third-party risk reviews.
Read the deep dive - European Union
NIS2
CISGuard automates the cybersecurity risk-management measures NIS2 Article 21 requires of EU Essential and Important Entities, with continuous evidence the national supervisory authorities expect.
Read the deep dive - United States
CMMC
CISGuard automates approximately 80% of CMMC Level 2 practice requirements through NIST 800-171 mapping, supporting defense contractors handling Controlled Unclassified Information (CUI).
Read the deep dive - United States
NIST 800-171
CISGuard automates the 110 security requirements of NIST 800-171 Rev. 3 (the technical baseline behind CMMC Level 2), with continuous evidence for DFARS 7012 contracting officers and C3PAO assessors.
Read the deep dive - California, United States
CCPA / CPRA
CISGuard automates the reasonable security expectations of the CCPA / CPRA Civil Code Section 1798.150 with continuous CIS benchmark scanning, drift detection, and the audit trail California Privacy Protection Agency examiners walk through.
Read the deep dive - New York, United States
NYDFS 23 NYCRR 500
CISGuard automates the technical controls of the New York Department of Financial Services cybersecurity regulation, with continuous evidence for the November 2023 Class A Covered Entity amendments and the bundled 24-hour incident reporting workflow.
Read the deep dive - United States
GLBA Safeguards Rule
CISGuard automates the technical safeguards required by the Gramm-Leach-Bliley Act Safeguards Rule, with continuous evidence aligned to the December 2021 amendments and the broader FFIEC Cybersecurity Assessment Tool.
Read the deep dive - United States
SOX
CISGuard automates the IT General Controls underlying Sarbanes-Oxley Section 404 ICFR evidence, with continuous configuration, access, and change-management evidence the external auditor walks through.
Read the deep dive - United States (with global adoption)
HITRUST CSF
CISGuard automates the technical control objectives of the HITRUST Common Security Framework (CSF v11) with continuous CIS benchmark evidence for the e1, i1, and r2 certification cycles.
Read the deep dive - New York, United States
SHIELD Act
CISGuard automates the reasonable security expectations of the New York SHIELD Act with continuous CIS benchmark scanning, drift detection, and the audit trail New York Attorney General enforcement looks for.
Read the deep dive - Massachusetts, United States
Mass 201 CMR 17
CISGuard automates the technical security controls of the strictest US state data security regulation, with continuous evidence the Massachusetts Office of Consumer Affairs and the Attorney General both walk through.
Read the deep dive - European Union
GDPR
CISGuard automates the "appropriate technical and organisational measures" GDPR Article 32 requires, with continuous evidence Data Protection Authorities (DPAs) expect during investigations.
Read the deep dive - United States / Global
NIST CSF
CISGuard turns continuous CIS benchmark scanning into technical evidence for the NIST Cybersecurity Framework 2.0, with strongest coverage of the Protect and Detect functions through configuration hardening and drift detection.
Read the deep dive - United States (State & Local Government)
StateRAMP
CISGuard maps 50 NIST 800-53 controls underpinning StateRAMP security requirements, giving cloud providers serving state and local government continuous configuration evidence for snapshots, authorization, and ongoing monitoring.
Read the deep dive - United States (Texas)
TX-RAMP
CISGuard maps 50 NIST 800-53 controls underlying TX-RAMP Level 1 and Level 2 requirements, giving cloud vendors serving Texas state agencies continuous configuration evidence instead of questionnaire snapshots.
Read the deep dive - United States
CJIS
CISGuard automates the technical CJIS Security Policy areas that audits hinge on: access control, auditing and accountability, and configuration management, with air-gapped deployment for criminal justice networks.
Read the deep dive - United States (Federal)
FISMA
CISGuard maps 50 NIST 800-53 controls across the baselines FISMA systems inherit, automating the configuration evidence behind ATO packages and the continuous monitoring FISMA reporting demands.
Read the deep dive - United States
FFIEC
CISGuard gives banks and credit unions continuous configuration evidence for FFIEC IT examinations: hardening baselines, change monitoring, and audit trails in the form examiners ask to see.
Read the deep dive - North America
NERC CIP
CISGuard automates the configuration baseline and change monitoring evidence at the heart of NERC CIP-010 and CIP-007, with air-gapped deployment built for control centers and Electronic Security Perimeters.
Read the deep dive - Global
SOC 1
SOC 1 examinations stand or fall on IT general controls: access, change management, and operations. CISGuard turns continuous CIS benchmark scans into the configuration evidence your service auditor requests.
Read the deep dive - Global
ISO 27002
ISO/IEC 27002:2022 tells you how to implement the 93 controls behind ISO 27001 Annex A. CISGuard proves the technological ones are actually in place, with continuous CIS benchmark scans as the implementation evidence.
Read the deep dive - Global
SWIFT CSP
Every SWIFT user must attest annually against the Customer Security Controls Framework. CISGuard continuously hardens and verifies the secure zone systems those controls target, producing the technical evidence your assessment needs.
Read the deep dive - United Kingdom
Cyber Essentials
Cyber Essentials rests on five technical control themes, and secure configuration is the hardest to prove. CISGuard verifies it continuously across every device with CIS benchmark scans, keeping you audit-ready for Plus.
Read the deep dive - United States
IRS 1075
Agencies and contractors that receive federal tax information must meet IRS Publication 1075's NIST 800-53 based safeguards. CISGuard automates the technical configuration evidence Safeguard reviews examine.
Read the deep dive - Germany
BSI IT-Grundschutz
Germany's BSI IT-Grundschutz methodology specifies concrete hardening requirements in its Kompendium building blocks. CISGuard evidences the system, operations, and network blocks through continuous CIS benchmark scans.
Read the deep dive - Spain
ENS
Spain's Esquema Nacional de Seguridad binds public sector bodies and their technology suppliers to graded security measures. CISGuard automates the configuration evidence behind the operational measures at BASICA, MEDIA, and ALTA.
Read the deep dive
Frequently asked
Compliance mapping questions, answered directly.
How does CISGuard map a single CIS benchmark scan to multiple regulatory frameworks?
Each CIS control in CISGuard is tagged with its NIST 800-53 control IDs, ISO 27001:2022 Annex A clauses and SOC 2 Trust Services Criteria. A single scan generates three framework coverage reports showing satisfied, partially satisfied and not-met status per control. Regulations such as HIPAA, HITRUST, PCI-DSS, NYDFS and CMMC are supported through the same CIS hardening evidence, history and exception register rather than a separate mapping.
How does CIS benchmark compliance help with DORA?
DORA (Digital Operational Resilience Act) requires EU financial entities to implement ICT risk management controls under Articles 5 to 16. CIS benchmarks provide system hardening for Article 9, continuous monitoring for detection under Article 10, drift detection for change management under Article 11, and audit-ready evidence for third-party ICT risk reviews under Article 15.
Can CISGuard help achieve FedRAMP authorization?
Yes. CISGuard maps 50 NIST 800-53 Rev. 5 controls across 13 control families, directly supporting FedRAMP Moderate and High baselines. Air-gapped deployment is available for FedRAMP High and IL4 and IL5 environments. Continuous monitoring supports FedRAMP ConMon requirements (CA-7), and automated evidence replaces manual POA&M documentation.
What is the difference between CMMC and NIST 800-53?
CMMC (Cybersecurity Maturity Model Certification) is required for US defense contractors and aligns with NIST SP 800-171, which derives from NIST 800-53. CISGuard automates the NIST 800-53 technical controls that underpin both frameworks, covering the configuration-based practice requirements of CMMC Level 2 through CIS benchmark scanning.
What evidence does CISGuard generate to satisfy ISO 27001 Annex A audit requirements?
CISGuard maps 36 CIS controls directly to ISO/IEC 27001:2022 Annex A, primarily the A.5 (organizational), A.7 (physical) and A.8 (technological) themes. Auditors receive a framework coverage report listing each Annex A control, its satisfaction status, the underlying CIS controls and scan timestamps. Continuous scanning satisfies Clause 9.1 (monitoring, measurement, analysis and evaluation).
Facing a compliance deadline?
Our compliance engineers have helped organizations achieve regulatory readiness through a seamless, fully managed deployment.