IT Audit Factory — evidence-first audit & compliance operations
Free • Professional • MSP

C31-R1 candidate: Professional and MSP retain C31 assessor-led preparation for 61 framework profiles. Free retains ISO 27001 scope. Complete automation is not claimed. C31 owner feedback confirmed frameworks installed and working; this consistency revision remains a candidate. See the current release guide.

Focused release · C31-R1 candidate

Follow a reviewable audit

Scope the program, collect relevant evidence, assess gaps and export reports for human review.

The workflow

1. Scope the program

Choose ISO 27001, CMMC Level 2, NIST SP 800-171 Rev. 2/3, NIST CSF 2.0 and NIST SP 800-53, HIPAA Security, ITAF ransomware readiness and PCI DSS preparation, select the client and document the assessment boundary.

2. Collect and assess

Use applicable collectors and manual evidence. Read missing-data warnings and record objective-specific decisions.

3. Explain the result

Review findings, assign remediation and export evidence-backed reports. Technical checks do not issue certification.

Focused assessment scope

ISO/IEC 27001

Assessment preparation using control identifiers, locally authored guidance, governance records and evidence review. Use your licensed standard for authoritative requirements.

CMMC Level 2

Practice and objective review, scope blockers, evidence requests, findings and POA&M. Technical results support assessor decisions; they do not establish a CMMC determination.

Evidence and reports

Collect applicable technical evidence, investigate missing results and export reviewer-ready material. Coverage varies by check, platform and edition.

In development

Additional framework assessments

CIS Controls, SOC 2 and additional ISO, privacy and regulatory packs are in development. They are not selectable for new assessments in the focused release. The full official PCI testing catalog also remains outside the bounded PCI preparation workflow.

Advanced collectors and integrations

Full AWS/GCP and broader Azure infrastructure coverage, Kubernetes, OT, database-security depth, dedicated SIEM/EDR/PAM integrations and integration SDKs remain in development. Existing scoped checks are not claims of complete platform coverage.

Automation and AI

Continuous compliance monitoring, automated regulatory submission, advanced AI analysis and the live Support Assistant are in development. No delivery date or regulatory outcome is promised.

Release status

C12: owner-confirmed passed and working. C31-R1 is the focused candidate being built and validated. Production acceptance, signing and clean-machine installation results will be published with the final release. This site does not offer an unvalidated C31-R1 installer.