Skip to content

Compliance

ScanNinja produces evidence aligned to four frameworks:

Framework What we cover Where the evidence lives
PCI DSS 4.0 Reqs 1, 2, 4, 6, 7, 8, 10, 11 Findings + scan history per asset
SOC 2 (TSC 2017) Security · Availability · Confidentiality categories Same
ISO/IEC 27001:2022 Annex A controls under A.5, A.8 Same
CMMC 2.0 Level 1 + Level 2 practice families Same; CMMC mapper is in beta

Not an attestation

ScanNinja produces evidence — not attestations. Use the findings + the mappings below to support your auditor's testing of controls. Do not substitute scan output for a SOC 2 Type II report or a PCI ROC. ScanNinja's separate compliance products handle the attestation packaging.

How findings carry compliance tags

Every finding emitted by the platform is tagged with one or more compliance references, for example:

pci_dss_4_0:6.3.3
soc2:CC7.1
iso27001:A.8.8

The mapping is data-driven, so a single finding can support controls across multiple frameworks and auditor exports can filter cleanly by reference.

Common cross-walk

The per-finding-category cross-walk to PCI / SOC 2 / ISO ships with the agent documentation and is published here once that section lands.

Worked auditor narratives

PCI DSS 4.0 — Req 11.3.1

Internal vulnerability scans of the CDE are performed quarterly using the ScanNinja pci scan template, executed against a defined asset group on a schedule. The scanner enumerates risky open ports and correlates discovered services with NVD CVE data via the on-platform CVE function. Scan records, findings, and remediation status are retained by the platform, and quarterly run evidence is exportable from the dashboard.

SOC 2 — CC7.1 (detection of vulnerabilities)

ScanNinja runs container and supply_chain scans on every CI build via the build pipeline, and production hosts are re-scanned daily on a schedule. Detected findings flow into the dashboard and the AI enrichment pipeline generates a remediation proposal per finding. Tracking SLAs are enforced via the finding lifecycle, which records when each finding was first seen, acknowledged, and resolved.

ISO 27001:2022 — A.8.8 (management of technical vulnerabilities)

Per-asset vulnerability lists with CVE IDs, severity (CVSS-based), age, and AI-generated remediation guidance are produced by every scan run. The compliance mapper tags each finding with iso27001:A.8.8 so auditor exports can filter cleanly. SLA tracking is built into the finding lifecycle.

Framework version policy

  • PCI DSS — we track the current version + the previous version's transition window. Adopt the new version's tagging within 90 days of release.
  • SOC 2 — TSC 2017 mappings are stable; we revisit when AICPA publishes a new TSC.
  • ISO 27001 — currently 2022 (Annex A 93 controls). Older 2013 mappings can be regenerated on request.
  • CMMC — tracking 2.0; the L2 mapping is in beta, contact your CSM for the readiness assessment.

What ScanNinja does NOT cover

  • No PCI ASV report. External scans are informational. PCI 11.3.2 requires an Approved Scanning Vendor; pair ScanNinja with an ASV.
  • No HIPAA Security Rule-specific reporting beyond general vulnerability scanning.
  • No FedRAMP-specific evidence packaging — the findings are usable but FedRAMP packaging is a separate product surface.
  • Mapping is descriptive, not prescriptive — we tell you a finding could support a control; your auditor decides if it does.