Skip to main content

CIS benchmark compliance you can see, fix and prove.

CISGuard scans your whole estate against 22 CIS Benchmarks, fixes what fails with signed, reversible remediations, and hands your auditors the evidence. Everything runs inside your network.

  • See everything

    One platform for your whole estate, from laptops to cloud to databases. One score you can defend.

  • Fix it safely

    Preview, approve, apply, verify and roll back, with every change under control and every fix signed.

  • Prove it continuously

    Always-current evidence and framework-ready reporting, not a once-a-year scramble.

CIS benchmarks
22, spanning endpoints, servers, cloud, containers, databases and browsers
Security controls
3,933 built in; 3,283 assessed automatically, the rest guided for manual review
Built-in fixes
2,032 signed, reversible remediations with dry-run preview, approval and rollback
Frameworks mapped
ISO 27001, NIST 800-53 and SOC 2, on a CIS Controls v8 base
Access
One dashboard, three roles (administrator, compliance manager, auditor), MFA and SAML SSO
Deployment
Fully on-premises or air-gapped; from a single server to tens of thousands of endpoints

Coverage

Every layer of your estate, one standard.

All 22 benchmarks
  • Endpoints and servers

    • Windows 11 Enterprise
    • Windows Server 2022
    • Ubuntu Linux 24.04 LTS
    • Red Hat Enterprise Linux 9
    • Intune-managed Windows 11
  • Cloud platforms

    • Microsoft Azure Foundations
    • Azure Compute Services
    • Amazon Web Services Foundations
    • Microsoft 365
  • Containers and orchestration

    • Docker
    • Kubernetes
    • Azure Kubernetes Service (AKS)
    • Amazon EKS
    • Red Hat OpenShift
    • AKS-optimized Azure Linux 2 and 3
  • Databases and web servers

    • SQL Server 2022
    • Microsoft IIS 10
  • Browsers

    • Google Chrome
    • Microsoft Edge
    • Mozilla Firefox ESR
    • Internet Explorer 11

Continuous scanning and assessment

Always current. Never a snapshot.

A once-a-year audit tells you where you stood months ago. CISGuard tells you where you stand right now, on every connected asset.

  • Scheduled, automated scans

    Set the cadence per benchmark and let it run. Blackout windows respect your change freezes, so scanning never collides with a release.

  • Real-time posture

    One overall score, live, across every connected asset, with the last-scanned time next to it. No more guessing what changed since the last audit.

  • Level 1 and Level 2 profiles

    Hold each system to the right hardening bar: Level 1 for the practical baseline, Level 2 where classified networks, finance or healthcare demand more.

  • Drill down to the failing control

    From estate score to benchmark to asset to the exact control that failed on a specific machine, with current versus expected values side by side.

  • Drift detection

    Every scan is compared with the last. A regression is flagged the moment a Group Policy change, a firewall rule or an audit setting slips.

  • Automated and manual, together

    Most controls are assessed automatically. The rest come with clear guidance for the checks that need human judgment, tracked in the same place.

  • Delta scanning

    Only what changed since the last scan is stored and re-evaluated. Full compliance scoring at enterprise scale with minimal load on production systems.

  • Purpose-built check runners

    Registry settings, security policies, service states, shell commands, database configuration and file permissions, each checked the way CIS specifies.

Safe, one-click remediation

Finding the problem is half the job. CISGuard fixes it, safely.

2,032 built-in fixes across Windows, Linux, IIS, SQL Server and cloud, each one under your control from preview to rollback. No scripts to write, no surprises in production.

  1. 01Preview

    Dry run. See exactly what the fix would change.

  2. 02Approve

    An authorized person signs off. Nothing runs before that.

  3. 03Execute

    The signed fix applies, to one host or a chosen group.

  4. 04Verify

    The control is re-checked, so you know it is compliant.

  5. 05Roll back

    Undo cleanly if anything surprises you.

  • Preview before you change anything

    Run any fix as a dry run first and see exactly what it would do before it touches a live system.

  • Approve, then execute

    Nothing changes until an authorized person signs off. Finding an issue and acting on it stay separate, by design.

  • Verify automatically

    After a fix runs, the control is re-checked, so you know the system is compliant, not just that a script finished.

  • Roll back with confidence

    Every applied fix is reversible. If a change has side effects, undo it cleanly and move on.

  • Cryptographically signed

    Each remediation is signed and integrity-checked. Only trusted, approved actions ever run in your environment.

  • Controlled rollout

    Apply a fix to a small group first, watch the result, then expand across the estate on your schedule.

Compliance framework mapping

One scan. Every framework your auditor asks for.

CISGuard translates technical findings into ISO 27001, NIST 800-53 and SOC 2 language, so you stop cross-referencing spreadsheets the week before an audit.

  • NIST SP 800-53 Rev. 550controls mapped

    Coverage per control family, with drill-down to the CIS control behind each one.

  • ISO/IEC 27001:202236Annex A controls

    Satisfied, partially satisfied and not met, with a methodology note your auditor can read.

  • SOC 226Trust Services Criteria

    Evidence generated continuously, so the audit window is a report, not a project.

  • NIST SP 800-53 Rev. 5

    50 controls mapped, with coverage per control family and drill-down to the CIS control behind each one.

  • ISO/IEC 27001:2022

    36 Annex A controls mapped, with Satisfied, Partially Satisfied and Not Met status and a methodology note your auditor can read.

  • SOC 2

    25 Trust Services Criteria mapped. Evidence is generated continuously, so the audit window is a report, not a project.

  • CIS Benchmarks

    The base layer: 22 benchmarks and 3,933 controls with pass or fail determined per control, feeding every framework view above.

Executive and operational dashboard

One dashboard. Every stakeholder.

The CISO, the compliance manager and the auditor all need the numbers. Each gets the view their job requires, from the same live data.

  • CISO-level overview

    Overall and risk-weighted compliance scores at a glance, with passing, failing, critical and high-severity counts on one strip.

  • Trends over time

    Prove your posture is improving, not drifting, across 7, 30, 90, 180 and 365-day windows, per benchmark and overall.

  • Compliance timeline

    How scores and fixes have changed across the estate, in order, so you can explain any number on the board slide.

  • Failures ranked by severity

    Open issues sorted CRITICAL to LOW, with the affected host attached, so teams fix the most important thing first.

  • Asset and agent inventory

    What is protected, what is online and what has gone stale, so a forgotten server never becomes an audit finding.

  • Benchmark and framework views

    The technical perspective and the audit perspective, side by side, from the same scan data.

Evidence, audit and exceptions

Built for the moment the auditor arrives.

Evidence, audit trail and accepted risks are documented as you go, so audit week is a report you export, not a scramble you survive.

  • Evidence collection

    The proof behind every passing and failing control is captured automatically, ready to hand over.

  • Full audit log

    Who did what and when, across scans, approvals, exceptions and changes. Immutable, searchable, exportable.

  • Auditor access grants

    Give an external or internal auditor a scoped, read-only view for the engagement, without handing over the keys.

  • Exception lifecycle

    Request, approve, expire and revoke. Accepted risks are documented, time-boxed and recalculated into the score, never forgotten.

  • Policy management

    Define the standards your organization commits to, assign them to asset groups, and track them from the same console.

Reporting

Reports that arrive before anyone asks.

  • Scheduled reports

    Delivered automatically on the cadence each stakeholder needs: weekly to the security lead, monthly to the board.

  • Exportable reports

    Executive summary, detailed compliance, gap analysis and framework coverage, ready to share with leadership, auditors and partners.

  • Point-in-time and trend

    Show both where you stand today and how far you have come since the last audit.

Alerting and integrations

Alerts where your team already works.

Compliance events flow into email, signed webhooks and your SIEM, with every delivery tracked so nothing disappears silently.

  • Email notifications

    New failures, completed scans and important changes, sent to the people who own them.

  • Webhook delivery

    Post events to any HTTPS endpoint you run, signed with HMAC-SHA256, so the ticketing and chat tools you already use can receive them.

  • SIEM integration

    Syslog (RFC 5424), CEF and JSON over HTTPS, so your security operations center sees compliance events alongside everything else it monitors.

  • Failed-delivery handling

    Every notification is tracked and retried. An alert never disappears silently because a mail server was busy.

Enterprise security and access control

Enterprise access control, out of the box.

Three roles, MFA, single sign-on and separation of duties. People see and do only what their job requires.

  • Role-based access control

    Three built-in roles: administrator, compliance manager and auditor. People see and do only what their job requires.

  • Multi-factor authentication

    Authenticator-app codes with recovery codes, enforceable per role.

  • Single sign-on

    SAML 2.0 and Microsoft Entra ID, so CISGuard fits your existing identity provider instead of adding another password.

  • Directory integration

    LDAP and Active Directory with group-to-role mapping for centralized user management.

  • Separation of duties

    Finding an issue, approving a fix and applying it are distinct permissions, so no single account can do all three.

Enterprise and region

Built for the enterprise. Built for your region.

Fully on-premises, so your configuration data never leaves your network. Suited to data-sovereignty and regulatory requirements in banking, energy, healthcare, telecom and government. Scales from a single server to tens of thousands of endpoints.

  • On-premises

    A single installer on your server, agents on Windows, Linux and container hosts. Configuration data never leaves your data center.

    • CISGuard server
    • Windows agents
    • Linux agents
    • Cloud API scanner
    • Your database
  • Air-gapped

    Fully offline operation for classified networks. No internet connectivity required. Agent and definition updates arrive by secure file transfer.

    • Isolated server
    • Classified endpoints
    • Offline updates
    • Local report generation
  • Hybrid

    One central server with agents across sites, cloud subscriptions and container clusters. One dashboard for all of it.

    • Central server
    • Site A agents
    • Site B agents
    • Azure and AWS APIs
    • Kubernetes clusters

A 45-minute Executive Briefing: a live scan of a sample of your environment, one fix taken through preview, approval and rollback, and your security team in the room.

Request a briefing Compare with alternatives