Compliance
Hashiro maps cloud misconfigurations to industry-standard compliance benchmarks, giving you visibility into how your cloud infrastructure aligns with established security frameworks.
CIS Benchmarks
The primary compliance framework used by Hashiro is the CIS (Center for Internet Security) Benchmarks: widely recognized best-practice guidelines for securing cloud environments.
Each cloud provider has its own CIS benchmark:
| Provider | Benchmark |
|---|---|
| AWS | CIS Amazon Web Services Foundations Benchmark |
| Azure | CIS Microsoft Azure Foundations Benchmark |
| GCP | CIS Google Cloud Platform Foundations Benchmark |
Compliance Score
Each connected provider account displays a compliance score: the percentage of applicable CIS controls that are passing.
Compliance Score = (Passing Controls / Total Applicable Controls) x 100The score updates automatically after each scan as misconfigurations are detected or resolved.

Screenshots use fictional demonstration data.
Benchmark Progress
Compliance benchmarks are displayed as progress bars showing:
- Passing: controls where no misconfigurations were found
- Failing: controls with one or more active misconfigurations
- Not Applicable: controls that don't apply to your environment (e.g., a control about a service you don't use)
Control Mapping
Every misconfiguration in Hashiro is mapped to its corresponding CIS benchmark control. This means you can:
- Drill down from a benchmark control to see all related misconfigurations
- Drill up from a misconfiguration to see which compliance controls it affects
- Track remediation progress at the control level (a control passes only when all related misconfigurations are resolved)
Using Compliance Data
Audit Preparation
Export compliance reports to demonstrate your organization's security posture to auditors. The compliance view shows which controls are met and which have gaps, along with the specific resources involved.
Prioritization
Use compliance alignment to prioritize remediation. Misconfigurations that affect multiple compliance controls or that are required for your regulatory obligations should be addressed first.
Trend Tracking
Monitor your compliance score over time to ensure your cloud security posture is improving and that new deployments don't introduce regressions.
TIP
Compliance scores are a useful directional indicator, but they don't replace a thorough security assessment. A high compliance score means you're following established best practices. It doesn't guarantee the absence of all security risks.