Compliance
Vulnerability scanning that satisfies your auditors.
SOC 2, PCI DSS, ISO 27001, HIPAA, CMMC, CIS, NIST — every major compliance framework expects continuous or quarterly vulnerability scanning. VulnScanners runs hosted Nmap, Nuclei, and OWASP ZAP assessments against your scope, from $10 per assessment, with an audit-ready PDF report every time.
Why compliance-grade scanning matters
Frameworks don't prescribe a specific scanner — they require evidence that you identify, assess, and remediate vulnerabilities on a regular cadence. A hosted assessment with a dated report satisfies that control element without standing up, patching, and documenting your own scanning infrastructure.
- Cover the frameworks that matter
- SOC 2 CCV (v1.1, CC6, CC7), PCI DSS v4.0 Requirement 11.2, ISO 27001 A.12.6.1, HIPAA Security Rule §164.308(a)(1)(ii), CMMC 2.0 / NIST SP 800-171 RA-5, and CIS Controls 4 (IG1–IG3) — all expect continuous or quarterly vulnerability scanning. One platform satisfies them all.
- Audit-ready evidence
- Every assessment produces a dated, severity-ranked PDF report you can hand to an auditor or include in your SOC 2 evidence package. Reports include the scanner output, finding details, and remediation guidance — no reformatting.
- Hosted — nothing to deploy
- No agents, no appliances, no patching obligations. Scans originate from a stable source IP your team can document in the control description. Onboard in minutes, not weeks.
- Continuous or on-demand
- Schedule recurring assessments for continuous monitoring coverage, or run ad-hoc scans when your attack surface changes. The Agency plan delivers 200 assessments every month so coverage never lapses.
- Credits never expire
- Pre-buy assessments at $10 each and use them across quarters and clients without losing value. No annual subscription lock-in — only the scans you actually run.
Framework-by-framework coverage
Each framework maps to the same core activity — run scans, collect findings, produce evidence. Here is how VulnScanners fits each one.
- SOC 2CC6, CC7, CCV v1.1
- Continuous vulnerability monitoring and remediation are expected across all Trust Services Criteria. Our assessment reports serve as third-party-evidenced scan output for your SOC 2 evidence binder.
- PCI DSS v4.0Requirement 11.2
- Quarterly internal and external vulnerability scans are mandatory for any entity handling cardholder data. Run your quarterly pass — Nmap for network, Nuclei for CVE coverage, ZAP for web apps — and download the report as your scan evidence.
- ISO 27001A.12.6.1
- The standard requires timely identification of technical vulnerabilities and remediation tracking. Our assessments map directly to Annex A control A.12.6.1, with a dated report that demonstrates due diligence in your ISMS.
- HIPAA Security Rule§164.308(a)(1)(ii)
- Covered entities and business associates must conduct accurate and thorough assessments of the potential risks and vulnerabilities. Our full three-engine assessment provides the vulnerability-scanning component of your risk analysis.
- CMMC 2.0 / NIST SP 800-171RA-5
- Vulnerability scanning is required at three CMMC levels. Our hosted assessments produce the scan evidence needed for RA-5 compliance without standing up your own scanning infrastructure.
- CIS Critical Security ControlsControl 4 (IG1–IG3)
- Continuously acquire, assess, and act on vulnerability information. VulnScanners covers the assessment and reporting workflow for CIS Control 4 across all implementation groups.
What the frameworks require
“Continuously acquire, assess, and take action on new information in order to identify vulnerabilities, remediate, and minimize the window of opportunity for attackers.”
“Run internal and external network vulnerability scans at least quarterly and after any significant change in the network.”
“Monitor and scan for vulnerabilities in the system and hosted applications, and when new vulnerabilities potentially affecting the system are identified and reported.”
“Organizations that do not scan for vulnerabilities and address discovered flaws pro-actively face a significant likelihood of having their computer systems compromised.”
Compliance FAQ
- Does VulnScanners meet PCI DSS quarterly scan requirements?
- Yes. PCI DSS v4.0 Requirement 11.2 requires internal and external vulnerability scans at least every quarter and after significant network changes. Run a full Nmap + Nuclei + ZAP assessment quarterly against your CDE scope and export the PDF report as scan evidence. Your QSA or ASV can review the report directly.
- Can I use VulnScanners for SOC 2 evidence?
- Yes. SOC 2 examinations (CC6, CC7) expect the service organization to monitor for and remediate vulnerabilities. Each dated assessment report serves as evidence of ongoing monitoring. Pair it with your remediation tracking and the report satisfies the scanning component of the control.
- Which ISO 27001 control does vulnerability scanning satisfy?
- Annex A control A.12.6.1 — Management of technical vulnerabilities. The standard requires timely identification of technical vulnerabilities and remediation. Our assessments produce a dated, severity-ranked report you can include in your ISMS evidence.
- Do you offer ASV-approved PCI scanning?
- No. VulnScanners is not an Approved Scanning Vendor (ASV). For formal PCI DSS attestation you need a QSA or ASV. Our reports are suitable for internal evidence, gap analysis, and preparation scans before your official ASV assessment — at a fraction of the cost per scan.
- Can I schedule recurring compliance scans?
- Yes. You can schedule weekly, biweekly, or monthly scans against your compliance scope targets from the Scheduled Scans page. The Agency plan adds 200 assessments per month, making continuous compliance coverage straightforward.
- Is there a white-label option for auditor reports?
- Yes. Agency subscribers get white-label PDF reports with their own logo and organization name — no VulnScanners branding. This is useful when submitting scan evidence under your company name to auditors or clients.
Start your compliance assessment
Run a full Nmap + Nuclei + ZAP assessment against your compliance scope. Audit-ready PDF report included. From $10.