NSAuditor AI Enterprise now maps NIST SP 800-171 Rev 2 as evidence substrate for CMMC Level 2 preparation — eight frameworks from a single read-only scan.
NSAuditor AI Enterprise 0.39.0 Makes Every Cloud Scanner Say What It Did Not Check
Azure and GCP plugins now declare their coverage boundaries in the report itself — even over an empty account. All seven compliance matrices stay unchanged.
NSAuditor AI Enterprise 0.38.0 Adds Signed Evidence Packs — Verifiable Offline With openssl Alone
Enterprise 0.38.0 signs one framework’s chain-of-custody envelope with an operator-held Ed25519 key, and the verifier re-hashes every artifact that envelope names.
NSAuditor AI Enterprise 0.37.0: Carrying Vulnerability Data Across the Air Gap
NSAuditor AI Enterprise 0.37.0 ships an air-gap feed pipeline: feed bundle merges the NVD feed files you downloaded on a connected host into one portable archive, feed import loads it into the offline CVE store on the isolated side, and your own CISA KEV and FIRST EPSS files ride along inside it.
NSAuditor AI Enterprise 0.36.0 checks the approval signatures in your compliance report
NSAuditor AI Enterprise 0.36.0 verifies each approval signature against the approver’s own key material, reports two verdicts side by side, and treats a missing verdict as “not checked” rather than “failed”.





