Compliance management software

Stay ready for the audit, not scared of it

Compliance management software is supposed to tell you where you stand before somebody asks. QS-WAN reads the evidence straight from your own network, continuously, and sorts it by the frameworks you answer to, such as NIS2 and ISO 27001. You see which technical controls hold up, which don’t, and which couldn’t be checked yet.

Helps verify certain technical controls associated with

  • NIS2
  • ISO/IEC 27001:2022
  • NIST SP 800-53 Rev. 5
  • CIS Controls v8.1
  • NIST CSF 2.0
  • GDPR Article 32
  • SOC 2
  • PCI DSS v4.0
  • HIPAA Security Rule
Three engines, one set of evidence
Risk score

How exposed you are now, from 0 to 100. Higher is worse.

RMF assessments

25 NIST SP 800-53 controls: pass, fail, partially satisfied or not tested.

Compliance crosswalk

How much of what could be assessed is satisfied. Higher is better.

Kept apart on purpose: a good compliance percentage and a bad week for risk can happen at the same time.

The situation

Somebody was made responsible for this, often by a law rather than by choice. A decree, a customer contract, an insurer, or a framework that now applies to organisations your size.

Usually it’s the person who already runs the network: not a security team, the same person with the same week and a new obligation on top. What they need isn’t more security. It’s being able to show what’s true on the day somebody asks, and knowing what to fix before then.

Why the usual answers don't fit

A spreadsheet

It’s where most people start, and it’s honest work. It’s also a snapshot of a moment that’s already gone, and nobody believes it, including the person keeping it.

Regulatory compliance management software built for large enterprises

It assumes you’ve got a team to feed it. Most of the cost is the process around it, not the licence.

Gathering evidence when asked

It’s the default, and it’s why the audit feels frightening. You aren’t proving a state. You’re rebuilding one, against the clock.

How QS-WAN solves it

What changes when the evidence comes from the network

QS-WAN doesn’t look at your network from the outside. It is the network: it runs remote access, issues every device certificate and signs the policy each endpoint follows. So most of the evidence comes from the system that enforces the controls.

See where you stand, framework by framework

The same evidence is read against each framework in the console, requirement by requirement. When the audit is announced, the question isn’t where to start. It’s which gap to close first.

A percentage that doesn't punish you for blanks

Anything without evidence leaves the calculation instead of counting as a failure, so the number describes what was actually assessed. Requirements that need a person to attest them, or whose source isn’t available, are shown apart.

25 NIST SP 800-53 controls, checked automatically

Each assessment returns pass, fail, partially satisfied or not tested, for gateways and for the control tower. Not tested means the automation couldn’t validate the control, and it’s never rounded up to a pass.

Every gap gets a plan and an owner

A plan of action and milestones (POA&M) tracks what’s open, how severe it is and who owns it. Nobody can prepare the authorisation to operate, the ATO, while a failed, partial or untested control has no plan.

A late fix shows up in the risk number

The risk score is built from 19 equally weighted indicators, and overdue plans are one of them. A fix that slips doesn’t hide in a to-do list. It moves the number your management sees.

Some fixes happen in the console itself

Mandate a signed company policy on every enrolled device, tighten the TLS groups and cipher across the fleet, or revoke a device’s certificate. Plenty of fixes still happen outside the platform, and the plan tracks those too.

The shape of it

The evidence is produced continuously, not assembled afterwards.

0

NIST SP 800-53 controls assessed automatically

0

equally weighted indicators in the risk score

Gateways and tunnels

Whether each gateway, its tunnel and its control channel are up, reported separately, because they fail separately.

Certificates, cryptography and MFA

Every device certificate and when it expires, the algorithms the fleet uses, and which VPN profiles have MFA.

Network scans from the inside

Scans run through a gateway, with five scan presets up to a vulnerability audit, once or on a daily, weekly or monthly schedule.

Web application scans

Alerts, discovered URLs and technical detail.

Endpoints

Configuration checks, vulnerabilities by installed package, inventory, and alerts mapped to MITRE ATT&CK.

Security events

A feed you can filter by severity and status.

Where the evidence comes from

The endpoint checks run on telemetry from the agent on each machine. Web application scans come from the QS-WAN Web Scanner. Network scans and MFA on VPN profiles need a gateway. When a source isn’t there, the requirements it would have evidenced sit outside the score as not evidenced, never as failures, so a missing agent never passes for a missing control.

Frameworks

Which frameworks it helps with, and where each one stops

Every framework below also asks for governance, policies and people, and no software does that part. Passing a check in the console isn’t passing an audit: that’s always your auditor’s call.

NIS2, including Portugal's Decree-Law 125/2025

Where QS-WAN helps

It helps verify certain technical controls associated with the NIS2 risk-management measures: incident tracking, vulnerability handling, cryptography, access control and MFA, network segmentation and basic cyber hygiene. It also supports the regular assessment of whether those measures work, which is Article 27(e) of Decree-Law 125/2025 in Portugal.

What stays with you

Governance approved by management, the documented risk analysis, training, supply chain security, business continuity and crisis management, and notifying incidents to the authority within the legal deadlines.

Where QS-WAN helps

It helps verify certain controls associated with Annex A, mostly the technological ones and access control: authentication, malware protection, vulnerability management, configuration management, network segregation and cryptography.

What stays with you

The management system itself, clauses 4 to 10: context, leadership, risk treatment, the Statement of Applicability, internal audit and management review. Certification is of your organisation, by an accredited body, never of a product.

Where QS-WAN helps

It helps verify certain controls associated with NIST SP 800-53 Rev. 5 by assessing 25 of them automatically, for gateways and for the control tower. It supports the authorisation cycle in the RMF format of NIST SP 800-37 Rev. 2 and records your organisation’s decision.

What stays with you

The rest of the catalogue, categorising your system, and the authorisation decision itself, which belongs to your authorising official.

Where QS-WAN helps

It helps verify certain safeguards associated with CIS Controls v8.1, mainly asset inventory, software inventory, secure configuration, account management, continuous vulnerability management and malware defences.

What stays with you

Data protection and recovery, security awareness training, service provider management, application security as a process, and penetration testing.

Where QS-WAN helps

It helps verify certain outcomes associated with the Identify, Protect and Detect functions, such as asset management, identity and access, platform security and continuous monitoring.

What stays with you

Govern almost entirely, Recover entirely, and the business side of risk: how critical each asset is, how much risk you accept and how you treat it.

Where QS-WAN helps

It helps verify certain technical measures associated with Article 32, especially encryption in transit and a process for regularly testing and evaluating whether the measures work.

What stays with you

Most of the GDPR, which isn’t technical: lawful basis, data minimisation, retention periods, data subjects’ rights, impact assessments, and notifying a breach to the supervisory authority.

Where QS-WAN helps

It helps verify certain controls associated with the common criteria for logical access and system operations, and its evidence can support your preparation for an examination.

What stays with you

The report itself, which an independent auditor issues, the control environment, and, for a Type II report, proof that the controls operated across the whole period.

Where QS-WAN helps

It helps verify certain controls associated with network security controls, secure configuration and malware protection, and supports the internal vulnerability scans in requirement 11.3.1.

What stays with you

Defining and validating the scope of your cardholder data environment, protecting stored card data, penetration testing, and the external scans in requirement 11.3.2, run by an Approved Scanning Vendor.

Where QS-WAN helps

It helps verify certain technical safeguards associated with the HIPAA Security Rule: access control, audit controls, person or entity authentication, transmission security and protection from malicious software.

What stays with you

The risk analysis, written policies and procedures, workforce training, business associate agreements, physical safeguards and the contingency plan.

When a control fails

When something fails, what you're told and what happens next

A failed control doesn’t just turn red. The assessment records what failed and how severe it is, and from there the work has an order.

It tells you what failed, how severe it is and where to look first.

It doesn’t write the fix for you. It keeps the plan honest until somebody on your side closes it.

01

You see what failed, and how bad it is

Each failed control carries a description of what failed and a severity. Not tested stays separate, because the automation couldn’t validate it and won’t pretend otherwise.

02

You see where to start

In the risk score, the indicators closest to their limit show which problem carries the number. On endpoints, the Posture view orders the work by host risk, known exploited vulnerabilities, MITRE ATT&CK breadth and internet exposure, with remediation context on each vulnerability.

03

The gap gets a plan

Every failed, partially satisfied or untested control needs a POA&M, with a severity and an owner, before an ATO can be prepared. The console enforces that, so the shortcut isn’t there to take.

04

Some fixes happen right there

A signed company policy, the fleet’s TLS groups and cipher, a revoked certificate. The rest, like patching a server or closing a port, is work your team does, and the plan keeps track of it.

05

Then it checks again

The next assessment and the next scheduled scan are where a fix shows up as fixed. Closing a plan is still a decision somebody on your side makes.

Regulation

When the rules change

Frameworks get revised while you’re in the job. Knowing what changed in the law, and what it means for your organisation, stays with your legal or compliance adviser.

What QS-WAN keeps current is the technical layer underneath, which barely moves between revisions, because every version keeps asking the same basic questions. When a new version lands, you’re rereading evidence you already hold, not starting a new spreadsheet.

What every version keeps asking
The audit

What the audit actually asks for

Three things, in this order, and they’re more boring than the frameworks suggest.

What's connected

An inventory of devices and sites that’s current rather than annual, because the first question is always whether you know what you have.

Who can reach what, and why

Access rules that map to a reason, not a pile of exceptions from four years ago that nobody can now explain.

Proof that both were true before today

The one that catches people. A correct configuration this morning says nothing about the day of the incident, and an audit trail put together afterwards isn’t one. In QS-WAN every assessment, scan and security event carries its date, and the risk score keeps its own timeline, so the record builds up while you work.

What to look for in any of these tools

People choosing the best compliance management software usually count frameworks. That’s the wrong axis. Ask where the evidence comes from: if most answers are typed in by hand, it’s a spreadsheet with a nicer interface. If most are derived from the state of the network, the tool is doing the work.

Then ask what the percentage does with the controls it couldn’t check. The same two questions apply to vendor compliance management software, the part everybody forgets until a customer asks about your suppliers.

What this is not

QuantumNova sells a product, not a managed service. Nobody here watches your network or signs off your compliance. The platform produces the evidence, the score and the plan, and your people, or your auditor, decide.

It doesn’t write your fixes or turn a percentage into an audit result. Healthcare compliance management software often comes bundled with an advisory service. This is software you run yourself.

Key features of this use case

The features this use case relies on

Risk scoring

Compliance crosswalk

Security asset management

See it running on your own network

Tell us which frameworks you answer to, and we’ll walk you through how the console reads them.

NEWSLETTER

Get weekly tips, product news and early access, straight to your inbox.

Scroll to Top