QS-WAN · Compliance

Compliance automation that excludes what it could not measure

Compliance automation in QS-WAN scores nine frameworks from evidence your own network already produces. One control answers several frameworks at once. Controls with nothing behind them leave the calculation instead of counting as failures, and three of the seven states that do that cannot be set by hand.

What it is

What compliance automation means here

Two engines and the reporting on top, and it helps to keep them apart.

Two engines

The crosswalk maps one control onto many frameworks

One control usually answers the same question under more than one regime, so evidence gathered once lands everywhere it is asked for. Nine frameworks each carry a score: the HIPAA Security Rule, ISO/IEC 27001:2022, CIS Controls v8.1, PCI DSS v4.0, GDPR, the SOC 2 Trust Services Criteria, NIST RMF (SP 800-53 Rev. 5), NIS2 as transposed in Portugal, and NIST CSF 2.0. Alongside them sits QNova Cert, our own quantum-safe scorecard, which is not one of the nine.

The Security Dashboard carries the average across them and the ones you stand best against.

The configuration assessment produces the evidence

It runs published CIS benchmarks against each machine and scores it per host: CIS Microsoft Windows 11 Enterprise v3.0.0, plus CIS Apple macOS 26.0 Tahoe v1.0.0 and macOS 15.0 Sequoia v1.0.0.

The checks are concrete: password history, minimum password length, account lockout duration, BitLocker recovery, NTLM hardening.

The promise this page proves lives in the compliance management software use case. This one is where it gets measured.

The mechanism

What was never measured stays out of the sum

Press the panel and watch the denominator move. Counting a control nobody measured as a failure is the other way to do this, and the two numbers are not the same number.

Evidence Crosswalk Nine frameworks Configuration assessment CIS benchmarks, scored per host Windows 11 Enterprise v3.0.0macOS 26.0 Tahoe v1.0.0macOS 15.0 Sequoia v1.0.0 Passed · Failed · Not applicable One control answers every framework that asks the same question HIPAA Security RuleISO/IEC 27001:2022CIS Controls v8.1PCI DSS v4.0GDPRSOC 2NIST RMF (SP 800-53 Rev. 5)NIS2, PortugalNIST CSF 2.0 Each of the nine carries its own score The sum 5 satisfied · 2 partially satisfied · 1 gap 2 not evidenced, outside the sum 2 not evidenced, counted as failures satisfied, plus half of the partials, over what was assessed 5 + half of 2, over 8 assessed

Two of these ten controls have nothing behind them. There are two ways to count that.

Eight controls were assessed and the score says so. The two nobody measured are not a pass and not a failure.

The diagram reads left to right. On the left, the configuration assessment scores each machine against the CIS benchmark for its own operating system, marking every check passed, failed or not applicable. That evidence feeds the crosswalk in the middle, where a single control answers the same question under several of the nine frameworks at once, so the lit lines run to more than one framework from the same control. On the right, the nine frameworks each carry their own score. Along the bottom, ten controls make up a sum: five satisfied, two partially satisfied and worth half a point each, one gap worth zero and still counted, and two with no evidence behind them, which sit outside the calculation. The two buttons compare the two ways of counting those last two, and leaving them out is what QS-WAN does. The states that take a control out of the denominator cannot be set by hand in the console; they follow the evidence.

The arithmetic is one line. Satisfied, plus half of the partials, over what was assessed. The configuration assessment runs the same rule on the evidence side, scoring passed over passed plus failed and leaving not applicable out of both halves.

Why this exists

Four weeks out from an audit

Nothing physical moves. What changes is who assembles the answer.

A folder of screenshots

Dated whenever somebody took them, which is the date the picture was taken and not the date the control was true.

One spreadsheet per framework

Ten regimes, ten files, and nothing in one of them knows what the others have already answered.

The same control, answered three times

Once for ISO 27001, once for NIS2, and once for a customer questionnaire, all three from the same evidence.

In your evenings

The collecting happens after hours, because during the day the job is the network. That is the part this takes off you.

What you gain

One score, two people reading it

If you run the network

You stop being the collection mechanism

The screenshot of a policy, the export of who has disk encryption, the email asking three site managers to confirm what you could check yourself: none of that was ever the control. It was proof the control existed.

The assessment produces that proof per host, against the benchmark for the operating system each machine is actually running.

If you sign for it

The number survives being questioned

Nothing unmeasured sits in the denominator, and the size of what was assessed sits beside it. There is no second sentence to add when somebody asks what the percentage covers.

A gap moves a named driver in the risk score rather than a document opened twice a year.

How it works

How a number gets made

The evidence comes from what is already running

Nothing new goes into the rack. The endpoints already report and the policy is already applied; the assessment reads both and scores each host against the benchmark for its own operating system.

The crosswalk maps it, then scores only what it holds

Each control lands in one of seven states. Four count: satisfied is a full point, partially satisfied is half, gap is zero, and in progress is zero too, because work underway is not evidence. Manual required, not evidenced and not applicable leave the sum.

The report leaves without you assembling it

The report composer builds a PDF from the sections you pick, inheriting scope and window from the dashboard you were on, so document and screen cannot disagree. The Management Report is the periodic one, emailed to people without console access.

In detail

The detail worth checking before you commit

States

The three states that remove a control cannot be set by hand

A state that takes something out of the denominator is exactly what a person under audit pressure would reach for at eleven at night. It is not there to reach for.

Three of the seven leave the calculation, and none of the three is a setting:

  1. Manual required
  2. Not evidenced
  3. Not applicable

The other four stay in the sum, including gap, which is worth zero and is still counted. Nothing leaves because somebody decided it should.

Denominator

Read the score next to the size of what was assessed

A high percentage on a small assessed set is still a small assessed set. The score declares its own denominator so that you can read the two together, which is the only way either of them means anything.

A gap also has a price you can point at. Compliance is one of the eight findings drivers in the risk score, where all 19 drivers weigh the same, about 5.26 points each.

Where this earns its place

Four moments this changes

The customer questionnaire

One control answers every framework that asks, so what you gathered for ISO 27001 is already the answer to the question a customer sends you in a spreadsheet.

Four weeks out from an audit

Evidence read per host against a named benchmark, one control answering every framework that asks, and a score that declares its own denominator.

The report somebody needs by Friday

You pick the sections, and the scope and the window come from the dashboard you were already on, so the document cannot disagree with the screen.

The people who never open the console

The Management Report is the periodic one. It goes by email, carrying aggregates only: no named employee, no individual device, no IP address.

Works better together

Where this sits in the rest of the console

These are not a related links box. Each one owns a piece of the same number, and the order is the order the evidence travels.

01

Runs the per host checks this score reads, and shows the passed, failed and not applicable counts sitting behind every benchmark.

02

Changes what is actually enforced on a machine. This page scores and names; that one is where the change gets made, and it stays your call.

03

Turns a compliance gap into a number that moves. Compliance is one of the eight findings drivers, and every driver weighs the same.

04

Holds the Security Dashboard the average is read from, and the report composer that inherits its scope and its window.

Every feature is listed in one place.

What this does not do

The limits, because they are what make the number believable

It is not a certification

A meter in your console reads your own evidence. It is not an assessor signature, and no percentage here becomes one.

Nobody here reviews it for you

There is no QuantumNova analyst looking at your controls. You run the product, and the output is yours.

It does not fix what it finds

It scores and it names. Changing what is enforced on a machine is security policy management, and that stays your call.

The benchmarks named here are Windows 11 and two macOS releases

That is what runs today. If your estate is mostly something else, ask on the call rather than assume the coverage.

Questions people ask

The ones that come up first

What is compliance automation?

Compliance automation means the evidence for security controls is read from the systems themselves and scored against the frameworks you answer to, instead of gathered by hand before an audit. Here it is a crosswalk over nine frameworks, fed by per host configuration assessments.

What happens to a control with no evidence behind it?

It leaves the calculation. It is not a failure and it is not a pass, so the percentage describes what was measured. Read it next to how much was assessed.

Can somebody mark controls not applicable to lift the score?

No. The three states that take a control out of the denominator, manual required, not evidenced and not applicable, cannot be set by hand.

Who gets the periodic report, and what is in it?

It goes by email to people without console access, carrying aggregates only: no named employee, no individual device, no IP address.

Bring us the framework you answer to. We will read the score live.

An engineer, a console shaped like yours, and as long as you need. You watch one control land in several frameworks at once, then watch one with nothing behind it leave the sum. It is free and there is nothing to sign.

Scroll to Top