Stay ready for the audit, not scared of it
Compliance management software is supposed to tell you where you stand before somebody asks. QS-WAN reads the evidence straight from your own network, continuously, and sorts it by the frameworks you answer to, such as NIS2 and ISO 27001. You see which technical controls hold up, which don’t, and which couldn’t be checked yet.
Helps verify certain technical controls associated with
- NIS2
- ISO/IEC 27001:2022
- NIST SP 800-53 Rev. 5
- CIS Controls v8.1
- NIST CSF 2.0
- GDPR Article 32
- SOC 2
- PCI DSS v4.0
- HIPAA Security Rule
How exposed you are now, from 0 to 100. Higher is worse.
25 NIST SP 800-53 controls: pass, fail, partially satisfied or not tested.
How much of what could be assessed is satisfied. Higher is better.
Kept apart on purpose: a good compliance percentage and a bad week for risk can happen at the same time.
The situation
Somebody was made responsible for this, often by a law rather than by choice. A decree, a customer contract, an insurer, or a framework that now applies to organisations your size.
Usually it’s the person who already runs the network: not a security team, the same person with the same week and a new obligation on top. What they need isn’t more security. It’s being able to show what’s true on the day somebody asks, and knowing what to fix before then.
Why the usual answers don't fit
A spreadsheet
It’s where most people start, and it’s honest work. It’s also a snapshot of a moment that’s already gone, and nobody believes it, including the person keeping it.
Regulatory compliance management software built for large enterprises
It assumes you’ve got a team to feed it. Most of the cost is the process around it, not the licence.
Gathering evidence when asked
It’s the default, and it’s why the audit feels frightening. You aren’t proving a state. You’re rebuilding one, against the clock.
What changes when the evidence comes from the network
QS-WAN doesn’t look at your network from the outside. It is the network: it runs remote access, issues every device certificate and signs the policy each endpoint follows. So most of the evidence comes from the system that enforces the controls.
See where you stand, framework by framework
The same evidence is read against each framework in the console, requirement by requirement. When the audit is announced, the question isn’t where to start. It’s which gap to close first.
A percentage that doesn't punish you for blanks
Anything without evidence leaves the calculation instead of counting as a failure, so the number describes what was actually assessed. Requirements that need a person to attest them, or whose source isn’t available, are shown apart.
25 NIST SP 800-53 controls, checked automatically
Each assessment returns pass, fail, partially satisfied or not tested, for gateways and for the control tower. Not tested means the automation couldn’t validate the control, and it’s never rounded up to a pass.
Every gap gets a plan and an owner
A plan of action and milestones (POA&M) tracks what’s open, how severe it is and who owns it. Nobody can prepare the authorisation to operate, the ATO, while a failed, partial or untested control has no plan.
A late fix shows up in the risk number
The risk score is built from 19 equally weighted indicators, and overdue plans are one of them. A fix that slips doesn’t hide in a to-do list. It moves the number your management sees.
Some fixes happen in the console itself
Mandate a signed company policy on every enrolled device, tighten the TLS groups and cipher across the fleet, or revoke a device’s certificate. Plenty of fixes still happen outside the platform, and the plan tracks those too.
The evidence is produced continuously, not assembled afterwards.
NIST SP 800-53 controls assessed automatically
equally weighted indicators in the risk score
Gateways and tunnels
Whether each gateway, its tunnel and its control channel are up, reported separately, because they fail separately.
Certificates, cryptography and MFA
Every device certificate and when it expires, the algorithms the fleet uses, and which VPN profiles have MFA.
Network scans from the inside
Scans run through a gateway, with five scan presets up to a vulnerability audit, once or on a daily, weekly or monthly schedule.
Web application scans
Alerts, discovered URLs and technical detail.
Endpoints
Configuration checks, vulnerabilities by installed package, inventory, and alerts mapped to MITRE ATT&CK.
Security events
A feed you can filter by severity and status.
Where the evidence comes from
The endpoint checks run on telemetry from the agent on each machine. Web application scans come from the QS-WAN Web Scanner. Network scans and MFA on VPN profiles need a gateway. When a source isn’t there, the requirements it would have evidenced sit outside the score as not evidenced, never as failures, so a missing agent never passes for a missing control.
Which frameworks it helps with, and where each one stops
Every framework below also asks for governance, policies and people, and no software does that part. Passing a check in the console isn’t passing an audit: that’s always your auditor’s call.
NIS2, including Portugal's Decree-Law 125/2025
It helps verify certain technical controls associated with the NIS2 risk-management measures: incident tracking, vulnerability handling, cryptography, access control and MFA, network segmentation and basic cyber hygiene. It also supports the regular assessment of whether those measures work, which is Article 27(e) of Decree-Law 125/2025 in Portugal.
Governance approved by management, the documented risk analysis, training, supply chain security, business continuity and crisis management, and notifying incidents to the authority within the legal deadlines.
ISO/IEC 27001:2022
It helps verify certain controls associated with Annex A, mostly the technological ones and access control: authentication, malware protection, vulnerability management, configuration management, network segregation and cryptography.
The management system itself, clauses 4 to 10: context, leadership, risk treatment, the Statement of Applicability, internal audit and management review. Certification is of your organisation, by an accredited body, never of a product.
NIST SP 800-53 Rev. 5 and the Risk Management Framework
It helps verify certain controls associated with NIST SP 800-53 Rev. 5 by assessing 25 of them automatically, for gateways and for the control tower. It supports the authorisation cycle in the RMF format of NIST SP 800-37 Rev. 2 and records your organisation’s decision.
The rest of the catalogue, categorising your system, and the authorisation decision itself, which belongs to your authorising official.
CIS Controls v8.1
It helps verify certain safeguards associated with CIS Controls v8.1, mainly asset inventory, software inventory, secure configuration, account management, continuous vulnerability management and malware defences.
Data protection and recovery, security awareness training, service provider management, application security as a process, and penetration testing.
NIST Cybersecurity Framework 2.0
It helps verify certain outcomes associated with the Identify, Protect and Detect functions, such as asset management, identity and access, platform security and continuous monitoring.
Govern almost entirely, Recover entirely, and the business side of risk: how critical each asset is, how much risk you accept and how you treat it.
GDPR, Article 32
It helps verify certain technical measures associated with Article 32, especially encryption in transit and a process for regularly testing and evaluating whether the measures work.
Most of the GDPR, which isn’t technical: lawful basis, data minimisation, retention periods, data subjects’ rights, impact assessments, and notifying a breach to the supervisory authority.
SOC 2 (Trust Services Criteria)
It helps verify certain controls associated with the common criteria for logical access and system operations, and its evidence can support your preparation for an examination.
The report itself, which an independent auditor issues, the control environment, and, for a Type II report, proof that the controls operated across the whole period.
PCI DSS v4.0
It helps verify certain controls associated with network security controls, secure configuration and malware protection, and supports the internal vulnerability scans in requirement 11.3.1.
Defining and validating the scope of your cardholder data environment, protecting stored card data, penetration testing, and the external scans in requirement 11.3.2, run by an Approved Scanning Vendor.
HIPAA Security Rule
It helps verify certain technical safeguards associated with the HIPAA Security Rule: access control, audit controls, person or entity authentication, transmission security and protection from malicious software.
The risk analysis, written policies and procedures, workforce training, business associate agreements, physical safeguards and the contingency plan.
When something fails, what you're told and what happens next
A failed control doesn’t just turn red. The assessment records what failed and how severe it is, and from there the work has an order.
It tells you what failed, how severe it is and where to look first.
It doesn’t write the fix for you. It keeps the plan honest until somebody on your side closes it.
You see what failed, and how bad it is
Each failed control carries a description of what failed and a severity. Not tested stays separate, because the automation couldn’t validate it and won’t pretend otherwise.
You see where to start
In the risk score, the indicators closest to their limit show which problem carries the number. On endpoints, the Posture view orders the work by host risk, known exploited vulnerabilities, MITRE ATT&CK breadth and internet exposure, with remediation context on each vulnerability.
The gap gets a plan
Every failed, partially satisfied or untested control needs a POA&M, with a severity and an owner, before an ATO can be prepared. The console enforces that, so the shortcut isn’t there to take.
Some fixes happen right there
A signed company policy, the fleet’s TLS groups and cipher, a revoked certificate. The rest, like patching a server or closing a port, is work your team does, and the plan keeps track of it.
Then it checks again
The next assessment and the next scheduled scan are where a fix shows up as fixed. Closing a plan is still a decision somebody on your side makes.
When the rules change
Frameworks get revised while you’re in the job. Knowing what changed in the law, and what it means for your organisation, stays with your legal or compliance adviser.
What QS-WAN keeps current is the technical layer underneath, which barely moves between revisions, because every version keeps asking the same basic questions. When a new version lands, you’re rereading evidence you already hold, not starting a new spreadsheet.
- What's connected
- Who can reach what
- Whether MFA is on
- Which cryptography is in use
- How long a known vulnerability has been open
What the audit actually asks for
Three things, in this order, and they’re more boring than the frameworks suggest.
What's connected
An inventory of devices and sites that’s current rather than annual, because the first question is always whether you know what you have.
Who can reach what, and why
Access rules that map to a reason, not a pile of exceptions from four years ago that nobody can now explain.
Proof that both were true before today
The one that catches people. A correct configuration this morning says nothing about the day of the incident, and an audit trail put together afterwards isn’t one. In QS-WAN every assessment, scan and security event carries its date, and the risk score keeps its own timeline, so the record builds up while you work.
What to look for in any of these tools
People choosing the best compliance management software usually count frameworks. That’s the wrong axis. Ask where the evidence comes from: if most answers are typed in by hand, it’s a spreadsheet with a nicer interface. If most are derived from the state of the network, the tool is doing the work.
Then ask what the percentage does with the controls it couldn’t check. The same two questions apply to vendor compliance management software, the part everybody forgets until a customer asks about your suppliers.
What this is not
QuantumNova sells a product, not a managed service. Nobody here watches your network or signs off your compliance. The platform produces the evidence, the score and the plan, and your people, or your auditor, decide.
It doesn’t write your fixes or turn a percentage into an audit result. Healthcare compliance management software often comes bundled with an advisory service. This is software you run yourself.
The features this use case relies on
See it running on your own network
Tell us which frameworks you answer to, and we’ll walk you through how the console reads them.
NEWSLETTER
Get weekly tips, product news and early access, straight to your inbox.