UTMStack

Show auditors evidence from your real security data

UTMStack works out on its own whether you meet each security control, because it already reads your logs: it sees whether sign-ins use multi-factor authentication, whether disks and connections are encrypted, whether audit logging is on and who holds privileged access. It scores nine compliance frameworks from one shared control library, and you download PDF reports for auditors with every reviewer sign-off listed.

UTMStack · Compliance
The compliance frameworks with their current scores. Open one, such as HIPAA, to see its score over time, the counts of compliant, non-compliant and at-risk requirements, and each control with its evidence.
  • Nine frameworks

    Banking Audit, CMMC 2.0, GDPR, HIPAA, ISO/IEC 27001:2022, NIST SP 800-171 Rev 3, NIST CSF 2.0, PCI DSS 4.0 and SOC 2.

  • One control library

    All nine frameworks map to one library of controls based on NIST SP 800-53, so a piece of evidence counts everywhere it applies.

  • Pass or fail, worked out for you

    More than 600 controls are checked automatically against your logs, including multi-factor sign-ins, disk and connection encryption, audit logging, privileged access and antivirus changes. Each gets a clear status, such as compliant, at risk or not covered.

  • Run an evaluation any time

    Check your current score on demand, before an audit or right after a change.

  • Reviewer sign-off

    Record a verdict and a reason on any control. The PDF report lists what a person signed off on and what could not be measured.

  • Schedules and history

    Schedule evaluations and follow your score over time to show that controls kept working, not only on audit day.

How scoring works

Each framework requirement points to controls in the shared library, and each control is checked against your events. A control can be compliant, non-compliant, at risk, not covered, not evaluated, pending or out of scope. Multi-tenant installs score each tenant separately.

HIPAA

UTMStack helps healthcare organizations meet the security requirements of the Health Insurance Portability and Accountability Act (HIPAA). It monitors the systems that hold patient data and keeps the records auditors ask for.

  • Keep an inventory of connected systems, including operating system details
  • Find vulnerabilities such as outdated software and insecure configurations
  • Correlate security events automatically with 600+ detection rules
  • Detect threats already inside your network, such as botnet traffic and malware reported by your antivirus or endpoint tools
  • Understand what each attack is after, with every alert mapped to MITRE ATT&CK
  • Speed up response with recommended steps and incident management
  • Monitor and report on the security controls HIPAA requires

GDPR

For the EU General Data Protection Regulation (GDPR), UTMStack supplies the monitoring and records behind its security requirements. It covers these areas.

  • Risk-based assessment
  • Security management
  • Perimeter security
  • Remote access
  • Incident response and investigation
  • Configuration change management
  • Vulnerability assessment
  • Information protection

GLBA

The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to protect customer information. UTMStack does not score GLBA as its own framework, but it collects the evidence its safeguards depend on, such as sign-ins, file access, Active Directory policy changes and new or re-enabled accounts. Banks can pair this with the Banking Audit framework.

  • Ensure the security and confidentiality of customer information
  • Protect against expected threats or hazards to the security or integrity of that information
  • Protect against unauthorized access to or use of customer information that could cause substantial harm or inconvenience to a customer

SOC 2

UTMStack scores the SOC 2 Trust Services Criteria from your events, which supports each stage of a SOC 2 audit. The audit itself is still carried out by an independent auditor.

  • Readiness (gap) assessment before the audit
  • Type 1: evidence that controls are designed properly at a point in time
  • Type 2: score history showing that controls worked throughout the audit period

The 9 frameworks UTMStack scores

Controls are defined once in a library based on NIST SP 800-53, so evidence collected for one framework counts toward the others.

Compliance frameworks in UTMStack
FrameworkWho it applies toControlsEdition
Banking AuditFor banks, credit unions and other financial institutions that must prove they log, watch and act on security events.80Enterprise
CMMC 2.0For companies in the US defense supply chain that handle federal contract or controlled unclassified information.339Community and Enterprise
GDPR (EU 2016/679)For any organization that collects or processes personal data of people in the European Union.12Community and Enterprise
HIPAAFor US healthcare providers, health plans and their partners that store or handle patient health information.69Enterprise
ISO/IEC 27001:2022For organizations of any size or sector that run, or want to certify, an information security management system.29Enterprise
NIST SP 800-171 Rev 3For contractors and other non-federal organizations that store or process US controlled unclassified information.113Enterprise
NIST Cybersecurity Framework 2.0For any organization that wants a common, widely used way to manage and measure cybersecurity risk.76Enterprise
PCI DSS 4.0For any business that stores, processes or transmits payment card data.155Enterprise
SOC 2For service providers, such as software and cloud companies, that hold customer data and need an independent audit report.34Enterprise

Questions buyers ask

Does UTMStack make us compliant?

No tool can do that on its own. UTMStack helps you meet framework requirements by monitoring controls continuously and producing the evidence auditors ask for. Policies, people and the audit itself are still part of the work.

Which frameworks are included?

UTMStack scores nine: Banking Audit, CMMC 2.0, GDPR, HIPAA, ISO/IEC 27001:2022, NIST SP 800-171 Rev 3, NIST CSF 2.0, PCI DSS 4.0 and SOC 2. Which ones you can use depends on your edition.

Can I schedule reports?

Yes. Set evaluations to run on a schedule and keep a score history. You can download any report as a PDF and sign it before sharing.

Can we track compliance for several companies or business units?

Yes. In multi-tenant installs, each tenant gets its own scores and reports, so service providers and groups of companies can report on each one separately.

Protect your organization this week, not next quarter

Talk to an engineer today, or start using UTMStack in minutes.

Need to extend your SOC team?

Our analysts work as an extension of your security team: they cover nights and weekends, take alert overflow and back you up on hard incidents. Book a 30-minute call to plan the coverage you need.

Want to try UTMStack?

Click through the live demo in your browser with no sign-up, start a free cloud instance, or install the open source edition on your own server in about 30 minutes.