Show auditors evidence from your real security data
UTMStack works out on its own whether you meet each security control, because it already reads your logs: it sees whether sign-ins use multi-factor authentication, whether disks and connections are encrypted, whether audit logging is on and who holds privileged access. It scores nine compliance frameworks from one shared control library, and you download PDF reports for auditors with every reviewer sign-off listed.
Nine frameworks
Banking Audit, CMMC 2.0, GDPR, HIPAA, ISO/IEC 27001:2022, NIST SP 800-171 Rev 3, NIST CSF 2.0, PCI DSS 4.0 and SOC 2.
One control library
All nine frameworks map to one library of controls based on NIST SP 800-53, so a piece of evidence counts everywhere it applies.
Pass or fail, worked out for you
More than 600 controls are checked automatically against your logs, including multi-factor sign-ins, disk and connection encryption, audit logging, privileged access and antivirus changes. Each gets a clear status, such as compliant, at risk or not covered.
Run an evaluation any time
Check your current score on demand, before an audit or right after a change.
Reviewer sign-off
Record a verdict and a reason on any control. The PDF report lists what a person signed off on and what could not be measured.
Schedules and history
Schedule evaluations and follow your score over time to show that controls kept working, not only on audit day.
The 9 frameworks UTMStack scores
Controls are defined once in a library based on NIST SP 800-53, so evidence collected for one framework counts toward the others.
| Framework | Who it applies to | Controls | Edition |
|---|---|---|---|
| Banking Audit | For banks, credit unions and other financial institutions that must prove they log, watch and act on security events. | 80 | Enterprise |
| CMMC 2.0 | For companies in the US defense supply chain that handle federal contract or controlled unclassified information. | 339 | Community and Enterprise |
| GDPR (EU 2016/679) | For any organization that collects or processes personal data of people in the European Union. | 12 | Community and Enterprise |
| HIPAA | For US healthcare providers, health plans and their partners that store or handle patient health information. | 69 | Enterprise |
| ISO/IEC 27001:2022 | For organizations of any size or sector that run, or want to certify, an information security management system. | 29 | Enterprise |
| NIST SP 800-171 Rev 3 | For contractors and other non-federal organizations that store or process US controlled unclassified information. | 113 | Enterprise |
| NIST Cybersecurity Framework 2.0 | For any organization that wants a common, widely used way to manage and measure cybersecurity risk. | 76 | Enterprise |
| PCI DSS 4.0 | For any business that stores, processes or transmits payment card data. | 155 | Enterprise |
| SOC 2 | For service providers, such as software and cloud companies, that hold customer data and need an independent audit report. | 34 | Enterprise |
Questions buyers ask
Does UTMStack make us compliant?
No tool can do that on its own. UTMStack helps you meet framework requirements by monitoring controls continuously and producing the evidence auditors ask for. Policies, people and the audit itself are still part of the work.
Which frameworks are included?
UTMStack scores nine: Banking Audit, CMMC 2.0, GDPR, HIPAA, ISO/IEC 27001:2022, NIST SP 800-171 Rev 3, NIST CSF 2.0, PCI DSS 4.0 and SOC 2. Which ones you can use depends on your edition.
Can I schedule reports?
Yes. Set evaluations to run on a schedule and keep a score history. You can download any report as a PDF and sign it before sharing.
Can we track compliance for several companies or business units?
Yes. In multi-tenant installs, each tenant gets its own scores and reports, so service providers and groups of companies can report on each one separately.
Related capabilities
- Log managementCollect logs from any source, correlate them in real time before storage, and keep hot and cold data searchable for up to 5 years.
- Vulnerability managementScan networks, web apps and servers for known vulnerabilities, rank findings by CVSS and EPSS scores, track every fix and export audit-ready reports.
- Identity auditingAudit Active Directory and Linux user accounts, find stale and disabled users, and detect identity attacks such as Kerberoasting and Golden Ticket.
- Multi-tenancyNative multi-tenancy in UTMStack 12: separate tenants on one server, your own branding, federation across servers, SSO and custom roles.
Protect your organization this week, not next quarter
Talk to an engineer today, or start using UTMStack in minutes.
Need to extend your SOC team?
Our analysts work as an extension of your security team: they cover nights and weekends, take alert overflow and back you up on hard incidents. Book a 30-minute call to plan the coverage you need.
Want to try UTMStack?
Click through the live demo in your browser with no sign-up, start a free cloud instance, or install the open source edition on your own server in about 30 minutes.