Skip to content

WardBee by ScanComb

Coverage you can count.

These counts come from the bundled catalogs and compiled check mappings in this release. A mapping means a check can supply evidence for part of a control; it does not mean the whole control passes automatically.

Bundled catalog coverage. Scanner mappings include native checks and registered external scanners.
Framework / editionCatalog controlsNative checks coverAny scanner coversNo scanner mapping
ISO/IEC 27001202293125736
SOC 2 Trust Services Criteria (2017, 2022 points of focus)20176162833
NIST Cybersecurity Framework2.0 (OSCAL 1.2.0)10693769
NIST SP 800-53Rev. 5.2.0 MODERATE baseline2871196191
CIS Critical Security Controls8.1 · limited bundled starter3330
TISAX ISA (VDA ISA)6.0.36772542
NIS2 Directive (EU) 2022/25552022/2555249177
OWASP Application Security Verification Standard5.0.0 Level 1700367
EU Cyber Resilience ActRegulation (EU) 2024/2847350431

What these numbers leave open

Mapped controls can still require process evidence, scope confirmation, or human approval. Unmapped controls need evidence outside the registered scanners. A partial catalog is not a complete framework assessment; the full CIS catalog requires a licensed import.

What runs in your workspace

AWS, GitHub, and GitLab integrations are available. Azure preview requires activation and covers storage encryption and activity log export configuration only. It does not provide all Azure mappings; GCP collection remains unavailable. Repository, image, and product scanners need their corresponding inputs. Your configured scope and fresh evidence determine which checks can run.

Cloud posture is not product compliance. CRA and OWASP ASVS require product or application evidence. Read the CRA scope · Review connection access