CIS benchmark compliance you can see, fix and prove.
CISGuard scans your whole estate against 22 CIS Benchmarks, fixes what fails with signed, reversible remediations, and hands your auditors the evidence. Everything runs inside your network.
- See everything
One platform for your whole estate, from laptops to cloud to databases. One score you can defend.
- Fix it safely
Preview, approve, apply, verify and roll back, with every change under control and every fix signed.
- Prove it continuously
Always-current evidence and framework-ready reporting, not a once-a-year scramble.
- CIS benchmarks
- 22, spanning endpoints, servers, cloud, containers, databases and browsers
- Security controls
- 3,933 built in; 3,283 assessed automatically, the rest guided for manual review
- Built-in fixes
- 2,032 signed, reversible remediations with dry-run preview, approval and rollback
- Frameworks mapped
- ISO 27001, NIST 800-53 and SOC 2, on a CIS Controls v8 base
- Access
- One dashboard, three roles (administrator, compliance manager, auditor), MFA and SAML SSO
- Deployment
- Fully on-premises or air-gapped; from a single server to tens of thousands of endpoints
Coverage
Every layer of your estate, one standard.
Endpoints and servers
- Windows 11 Enterprise
- Windows Server 2022
- Ubuntu Linux 24.04 LTS
- Red Hat Enterprise Linux 9
- Intune-managed Windows 11
Cloud platforms
- Microsoft Azure Foundations
- Azure Compute Services
- Amazon Web Services Foundations
- Microsoft 365
Containers and orchestration
- Docker
- Kubernetes
- Azure Kubernetes Service (AKS)
- Amazon EKS
- Red Hat OpenShift
- AKS-optimized Azure Linux 2 and 3
Databases and web servers
- SQL Server 2022
- Microsoft IIS 10
Browsers
- Google Chrome
- Microsoft Edge
- Mozilla Firefox ESR
- Internet Explorer 11
Continuous scanning and assessment
Always current. Never a snapshot.
A once-a-year audit tells you where you stood months ago. CISGuard tells you where you stand right now, on every connected asset.
Scheduled, automated scans
Set the cadence per benchmark and let it run. Blackout windows respect your change freezes, so scanning never collides with a release.
Real-time posture
One overall score, live, across every connected asset, with the last-scanned time next to it. No more guessing what changed since the last audit.
Level 1 and Level 2 profiles
Hold each system to the right hardening bar: Level 1 for the practical baseline, Level 2 where classified networks, finance or healthcare demand more.
Drill down to the failing control
From estate score to benchmark to asset to the exact control that failed on a specific machine, with current versus expected values side by side.
Drift detection
Every scan is compared with the last. A regression is flagged the moment a Group Policy change, a firewall rule or an audit setting slips.
Automated and manual, together
Most controls are assessed automatically. The rest come with clear guidance for the checks that need human judgment, tracked in the same place.
Delta scanning
Only what changed since the last scan is stored and re-evaluated. Full compliance scoring at enterprise scale with minimal load on production systems.
Purpose-built check runners
Registry settings, security policies, service states, shell commands, database configuration and file permissions, each checked the way CIS specifies.
Safe, one-click remediation
Finding the problem is half the job. CISGuard fixes it, safely.
2,032 built-in fixes across Windows, Linux, IIS, SQL Server and cloud, each one under your control from preview to rollback. No scripts to write, no surprises in production.
- 01Preview
Dry run. See exactly what the fix would change.
- 02Approve
An authorized person signs off. Nothing runs before that.
- 03Execute
The signed fix applies, to one host or a chosen group.
- 04Verify
The control is re-checked, so you know it is compliant.
- 05Roll back
Undo cleanly if anything surprises you.
Preview before you change anything
Run any fix as a dry run first and see exactly what it would do before it touches a live system.
Approve, then execute
Nothing changes until an authorized person signs off. Finding an issue and acting on it stay separate, by design.
Verify automatically
After a fix runs, the control is re-checked, so you know the system is compliant, not just that a script finished.
Roll back with confidence
Every applied fix is reversible. If a change has side effects, undo it cleanly and move on.
Cryptographically signed
Each remediation is signed and integrity-checked. Only trusted, approved actions ever run in your environment.
Controlled rollout
Apply a fix to a small group first, watch the result, then expand across the estate on your schedule.
Compliance framework mapping
One scan. Every framework your auditor asks for.
CISGuard translates technical findings into ISO 27001, NIST 800-53 and SOC 2 language, so you stop cross-referencing spreadsheets the week before an audit.
- NIST SP 800-53 Rev. 550controls mapped
Coverage per control family, with drill-down to the CIS control behind each one.
- ISO/IEC 27001:202236Annex A controls
Satisfied, partially satisfied and not met, with a methodology note your auditor can read.
- SOC 226Trust Services Criteria
Evidence generated continuously, so the audit window is a report, not a project.
NIST SP 800-53 Rev. 5
50 controls mapped, with coverage per control family and drill-down to the CIS control behind each one.
ISO/IEC 27001:2022
36 Annex A controls mapped, with Satisfied, Partially Satisfied and Not Met status and a methodology note your auditor can read.
SOC 2
25 Trust Services Criteria mapped. Evidence is generated continuously, so the audit window is a report, not a project.
CIS Benchmarks
The base layer: 22 benchmarks and 3,933 controls with pass or fail determined per control, feeding every framework view above.
Executive and operational dashboard
One dashboard. Every stakeholder.
The CISO, the compliance manager and the auditor all need the numbers. Each gets the view their job requires, from the same live data.
CISO-level overview
Overall and risk-weighted compliance scores at a glance, with passing, failing, critical and high-severity counts on one strip.
Trends over time
Prove your posture is improving, not drifting, across 7, 30, 90, 180 and 365-day windows, per benchmark and overall.
Compliance timeline
How scores and fixes have changed across the estate, in order, so you can explain any number on the board slide.
Failures ranked by severity
Open issues sorted CRITICAL to LOW, with the affected host attached, so teams fix the most important thing first.
Asset and agent inventory
What is protected, what is online and what has gone stale, so a forgotten server never becomes an audit finding.
Benchmark and framework views
The technical perspective and the audit perspective, side by side, from the same scan data.
Evidence, audit and exceptions
Built for the moment the auditor arrives.
Evidence, audit trail and accepted risks are documented as you go, so audit week is a report you export, not a scramble you survive.
Evidence collection
The proof behind every passing and failing control is captured automatically, ready to hand over.
Full audit log
Who did what and when, across scans, approvals, exceptions and changes. Immutable, searchable, exportable.
Auditor access grants
Give an external or internal auditor a scoped, read-only view for the engagement, without handing over the keys.
Exception lifecycle
Request, approve, expire and revoke. Accepted risks are documented, time-boxed and recalculated into the score, never forgotten.
Policy management
Define the standards your organization commits to, assign them to asset groups, and track them from the same console.
Reporting
Reports that arrive before anyone asks.
Scheduled reports
Delivered automatically on the cadence each stakeholder needs: weekly to the security lead, monthly to the board.
Exportable reports
Executive summary, detailed compliance, gap analysis and framework coverage, ready to share with leadership, auditors and partners.
Point-in-time and trend
Show both where you stand today and how far you have come since the last audit.
Alerting and integrations
Alerts where your team already works.
Compliance events flow into email, signed webhooks and your SIEM, with every delivery tracked so nothing disappears silently.
Email notifications
New failures, completed scans and important changes, sent to the people who own them.
Webhook delivery
Post events to any HTTPS endpoint you run, signed with HMAC-SHA256, so the ticketing and chat tools you already use can receive them.
SIEM integration
Syslog (RFC 5424), CEF and JSON over HTTPS, so your security operations center sees compliance events alongside everything else it monitors.
Failed-delivery handling
Every notification is tracked and retried. An alert never disappears silently because a mail server was busy.
Enterprise security and access control
Enterprise access control, out of the box.
Three roles, MFA, single sign-on and separation of duties. People see and do only what their job requires.
Role-based access control
Three built-in roles: administrator, compliance manager and auditor. People see and do only what their job requires.
Multi-factor authentication
Authenticator-app codes with recovery codes, enforceable per role.
Single sign-on
SAML 2.0 and Microsoft Entra ID, so CISGuard fits your existing identity provider instead of adding another password.
Directory integration
LDAP and Active Directory with group-to-role mapping for centralized user management.
Separation of duties
Finding an issue, approving a fix and applying it are distinct permissions, so no single account can do all three.
Enterprise and region
Built for the enterprise. Built for your region.
Fully on-premises, so your configuration data never leaves your network. Suited to data-sovereignty and regulatory requirements in banking, energy, healthcare, telecom and government. Scales from a single server to tens of thousands of endpoints.
On-premises
A single installer on your server, agents on Windows, Linux and container hosts. Configuration data never leaves your data center.
- CISGuard server
- Windows agents
- Linux agents
- Cloud API scanner
- Your database
Air-gapped
Fully offline operation for classified networks. No internet connectivity required. Agent and definition updates arrive by secure file transfer.
- Isolated server
- Classified endpoints
- Offline updates
- Local report generation
Hybrid
One central server with agents across sites, cloud subscriptions and container clusters. One dashboard for all of it.
- Central server
- Site A agents
- Site B agents
- Azure and AWS APIs
- Kubernetes clusters
A 45-minute Executive Briefing: a live scan of a sample of your environment, one fix taken through preview, approval and rollback, and your security team in the room.