Skip to main content

Know what your assessment covers.

Use this product coverage reference to scope a technical evaluation. Confirm the exact benchmark versions and control mappings against the release you plan to deploy.

Benchmarks
22
Total controls
3,933
Automated checks
3,283
Framework mappings
NIST SP 800-53 Rev. 5, ISO/IEC 27001:2022, SOC 2

Technical evidence has a defined scope

Technical configuration evidence supports an assessment; it does not by itself establish certification, authorization, or full regulatory compliance. Confirm exact control coverage for your product version and assessment scope.

  • The total control count includes checks that require manual review; it is not the number of automated checks.
  • A benchmark assessment reports configuration evidence. Organizational policies, training, physical controls and assessment decisions require separate work.
  • Cloud assessments need access to provider APIs. An isolated deployment does not make disconnected cloud accounts scannable.
  • Remediation availability and operational impact depend on the control and platform. Review a change before applying it.

Evidence to request during your evaluation

  1. A release-specific benchmark and control inventory.
  2. A representative report showing timestamps, observed and expected values, and manual-review items.
  3. The mapping rationale for your selected framework, including partial coverage.
  4. Deployment prerequisites, scan permissions and the approved remediation workflow.

This page describes evaluation criteria, not a customer case study or an independently validated test result. Consult the official CIS benchmark catalog for the underlying standards.

Review the evidence with an engineer.

Bring your platform and framework requirements. We will scope the demonstration around them.