WardBee by ScanComb
Coverage you can count.
These counts come from the bundled catalogs and compiled check mappings in this release. A mapping means a check can supply evidence for part of a control; it does not mean the whole control passes automatically.
| Framework / edition | Catalog controls | Native checks cover | Any scanner covers | No scanner mapping |
|---|---|---|---|---|
| ISO/IEC 270012022 | 93 | 12 | 57 | 36 |
| SOC 2 Trust Services Criteria (2017, 2022 points of focus)2017 | 61 | 6 | 28 | 33 |
| NIST Cybersecurity Framework2.0 (OSCAL 1.2.0) | 106 | 9 | 37 | 69 |
| NIST SP 800-53Rev. 5.2.0 MODERATE baseline | 287 | 11 | 96 | 191 |
| CIS Critical Security Controls8.1 · limited bundled starter | 3 | 3 | 3 | 0 |
| TISAX ISA (VDA ISA)6.0.3 | 67 | 7 | 25 | 42 |
| NIS2 Directive (EU) 2022/25552022/2555 | 24 | 9 | 17 | 7 |
| OWASP Application Security Verification Standard5.0.0 Level 1 | 70 | 0 | 3 | 67 |
| EU Cyber Resilience ActRegulation (EU) 2024/2847 | 35 | 0 | 4 | 31 |
What these numbers leave open
Mapped controls can still require process evidence, scope confirmation, or human approval. Unmapped controls need evidence outside the registered scanners. A partial catalog is not a complete framework assessment; the full CIS catalog requires a licensed import.
What runs in your workspace
AWS, GitHub, and GitLab integrations are available. Azure preview requires activation and covers storage encryption and activity log export configuration only. It does not provide all Azure mappings; GCP collection remains unavailable. Repository, image, and product scanners need their corresponding inputs. Your configured scope and fresh evidence determine which checks can run.
Cloud posture is not product compliance. CRA and OWASP ASVS require product or application evidence. Read the CRA scope · Review connection access