Compliance & evidence

Walk into the assessment with the evidence already assembled.

Skans is the enclave's technical control plane and evidence generator. It satisfies the hard technical controls of NIST 800-171 / CMMC Level 2, crosswalks the same live measurements to ISO/IEC 27001:2022, and exports a signed, air-gap-friendly evidence pack on one command. It supports and evidences your program — it never certifies it, and your organizational controls stay yours.

Skans console · Compliance
The Skans compliance view — a NIST security-posture ring with per-control-family status cards for AC, AU, CM, CP, IA, RA and SC

NIST 800-171 / CMMC

Live posture, read by control family.

The Compliance hub maps Skans capabilities onto the NIST 800-171 / CMMC Level 2 control families and shows where each one stands — computed from the appliance's live state, not a questionnaire. Of the 110 requirements in 800-171, roughly a third are organizational and stay with you; Skans owns the system and technical controls a product can actually measure.

  • Posture by family — AC (802.1X admission, RBAC), AU (central logging, synchronized time), CM (baseline + update rings), IA (per-device X.509, MFA), RA (CVE + ATT&CK matching), SC (TLS, PKI, FIPS approved-mode), CP, SI — with PE / PS / PL / PM shown as out of scope for an appliance.
  • A live, agent-measured scorecard — BitLocker, host firewall, audit policy, FIPS mode, and patch / Defender / certificate posture roll up on each device's detail page.
  • Not Verified, never wishful — a control Skans hasn't actually read stays Not Verified; it is never turned green just because a policy should have applied it. Only the on-box reading counts.
  • The boundary, shrunk to the enclave — a responsibility matrix names the organizational third that remains yours, so the assessor looks at less.
Skans console · Compliance
NIST posture ring with per-control-family cards — AC, AU, CM, CP, IA, RA, SC

ISO/IEC 27001:2022

One set of measurements, crosswalked to all 93 Annex A controls.

The same live checks feed an ISO 27001 tab — a different crosswalk over the same evidence machinery. It reports against every Annex A control, grounded in a published mapping rather than an in-house judgment call, and it is deliberate about what it will and won't claim.

  • All 93 Annex A controls — a fixed denominator that never shrinks to flatter the numbers, and deliberately no single "readiness %" over a standard that is mostly organizational.
  • Grounded in NIST OLIR #155 — every check-to-control link traces back to the published SP 800-53 Rev 5 → ISO/IEC 27001:2022 mapping, not a guess.
  • Four honest buckets — supporting evidence available · gaps identified · mapped-not-yet-measured · customer responsibility.
  • 15 controls get partial technical evidence — 5.9, 5.16–5.18 and clause-8 controls such as 8.15 Logging; the remaining 78 are your ISMS's. A passing check is evidence toward a control, never the whole control.
Skans console · Compliance · ISO 27001
The ISO 27001 crosswalk tab in the Skans Compliance hub, showing Annex A controls bucketed by evidence status

Honest by construction

The boundaries are the feature.

Being straight about what a product can and can't do is the point. These four lines are drawn into the tab, the export, and the language itself.

Supports, never certifies

No product can make a network "NIST compliant" or be "ISO 27001 certified." Skans evidences the technical controls; your ISMS is certified by an accredited body, and CMMC Level 2 standing by a C3PAO.

Tamper-evident, not WORM

An append-only, hash-linked, signed audit chain: each entry carries the previous hash, so any after-the-fact edit breaks every hash and signature after it. Cryptographically tamper-evident — never described as immutable.

Your controls stay yours

A responsibility matrix spells out Skans-technical vs customer-organizational per control, and a live POA&M carries the gaps. Physical, personnel, planning and program controls remain the customer's.

Only measured state counts

Agentless devices read N/A, not pass; unmeasured controls stay grey. Fleet evidence reads like "4 of 4 measured devices pass" — a real count over real readings, not wishful green.

Ask-the-box & evidence pack

Ask the box in plain language. Hand over the pack in one command.

The console is command-bar-driven — type where a family stands or what needs you, then export the whole thing. One command produces a timestamped folder and .zip, assembled entirely from live state with no hand-collation, built to move to an air-gapped site.

  • Ask the appliance — the command-bar console resolves "compliance", "AC" or "what needs me" straight to the surface, and Compliance sits in the bounded triage worklist, not a firehose.
  • Everything an assessor opens — ssp-control-status.csv (every control → NIST ID → Implemented / Planned), poam.csv (the live gaps), responsibility-matrix.csv, inventory.csv with per-device cert posture, audit-log.csv, and a README cover sheet.
  • Signed and verifiable — a manifest.sha256 plus a detached release-key signature; any post-export edit breaks verification.
  • Point-in-time by design — each pack is a live snapshot; persisted evidence history and in-console SoA management are named as Phase 2, not claimed today.
Skans console · Home
The Skans console home — a command bar over a correlated worklist with a Compliance lane

Audit & change control

Every change approved. Every action on the record.

Compliance is as much about how the enclave is run as what it measures. Skans gates the changes that matter behind an approval, attributes every action to a real person, and gives the auditor a read-only lens of their own.

  • Change approvals — patch-ring promotion, maintenance windows and firmware push gate on a Manager's patch.approve capability; the approval is recorded, not implicit.
  • Real-actor attribution — an AuditContext stamps the signed-in person on AD and RBAC writes; login is audited on both success and failure with the source IP, and rate-limiting, a 15-minute idle lock and explicit sign-out back NIST AC-7 / AC-11 / AC-12 and AU-2.
  • A read-only Auditor role — one of six least-privilege roles: review, attest and export signed evidence with no mutating capability, keeping the reviewer separate from the operator (NIST AC-6).
  • Reports straight from live state — control-status, POA&M and inventory export as the same CSVs you hand the assessor, with a default 365-day audit retention.
Skans console · Updates
The Skans updates view — patch rings with per-ring approval and a fleet patch-compliance chart

Talk to us

See Skans on your network.

Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.