NSAuditor AI Enterprise 1.2.0 Checks the Second Scan in Six More Cases Before Calling a Finding Fixed

Measured on a real router scan and a twin missing its 22 UDP rows: NSAuditor AI Enterprise 1.2.0 files all 22 not comparable, each with its reason.

nsauditor-ai-1-2-0-hero

Every scan diff has to decide what a missing finding means. If the second scan measured where the finding was and it is gone, something changed. NSAuditor AI builds its delta report on that rule. NSAuditor AI Enterprise 1.2.0, published by Nsasoft US LLC on 4 October 2026 with Community Edition 0.2.56 and the agent skill 0.2.54, extends that measured comparison to six more cases across the delta report, the mean-time-to-remediate (MTTR) figures and the compliance report.

The rule behind the delta

Cross-run delta reports for Pro and Enterprise were introduced in Enterprise 1.1.0, built on one rule: a finding that disappears between two scans has not been fixed unless the second scan measured where it was. 1.2.0 carries that rule into six more places, two of them backed by measurements from real scans.

Six more cases, now checked

  • UDP services that go quiet. A UDP finding that vanished reads NOT COMPARABLE unless the other scan recorded that port as closed or as answering. Measured by comparing a real router run with a twin of it that drops its 22 UDP rows: 1.2.0 reports all 22 not comparable, each with its reason.
  • CVE lookups that failed. When a service’s vulnerability lookup failed in one scan, the delta and MTTR do not count its earlier CVE rows as fixed, for TCP and UDP alike.
  • Analysis agents that did not run. An agent that failed, timed out or returned no finding list leaves a [COVERAGE GAP] AGENT NOT RUN record: the delta holds that agent’s rows out of the comparison, MTTR withholds them, and 78 generated routing rules route the gap to the controls that agent’s findings fail, in every framework that maps that agent.
  • Enterprise packages that did not load. Community Edition 0.2.56 names a failed Enterprise load on stderr ([EE] Enterprise is installed but FAILED TO LOAD) and records it on the scan’s conclusion, and the delta holds that host’s analysis-agent and CVE rows out of the comparison.
  • Controls tied to an unmeasured prior finding. With SLA tracking on (--compliance-history <dir> or --sla-policy <file>), the compliance report carries one evidence-gap record for each prior finding whose port or probe this scan did not measure, whose region it did not scan or whose producer it did not run, titled <prior title> — [COVERAGE GAP] PORT NOT MEASURED — … (or PROBE, SCOPE or PRODUCER). The record holds the control FAILED, leads the violation’s explanation with the gap, and is counted among “Evidence gaps (not findings)”; it is never presented as a current finding. It applies once the history holds a prior --compliance <fw> scan of the same host.
  • Vulnerability data that shifts. NVD stopped matching five CVEs to dnsmasq 2.78, the router’s DNS server, while the same dnsmasq 2.78 was still answering. A CVE is attributed on a service’s program and version alone, so when one identified program and version answer on the port in both scans, a vanished CVE row means the data changed, not the estate. 1.2.0 files it NOT COMPARABLE (vulnerability-data-changed), and the row’s own detail calls the absence “a change in the vulnerability data it was matched against, not a remediation”. MTTR, reading the program and version the prior row recorded, keeps it out of its closed findings.

The NOT-COMPARABLE list in 1.2.0

When the report can see that a finding was not measured the same way twice, it files it under NOT-COMPARABLE, with the reason on the row, instead of calling it resolved — among the reasons: a host that was not scanned; a finding that carries no producer identity; a plugin that did not run, errored or timed out; an analysis agent that did not run; an Enterprise package that failed to load; an evidence gap, including a CVE lookup that failed; a narrower scope; a port whose check could not complete; a TCP port the port scanner saw open that stopped answering between the two scans, or a UDP port the other scan did not record as closed or answering; a producer whose identity basis changed across an upgrade; and a CVE the vulnerability data stopped attributing while the same program and version still answer. A finding that could not be compared is not a finding that was fixed.

Some comparisons are declined outright rather than filed row by row, among them two runs at different licence tiers and two runs that straddle a release where a reported number changed meaning.

What it means for the reports you sign

  • Client reports built to be defended line by line. Every row filed under NOT-COMPARABLE carries its reason, so a question about “resolved” becomes a to-do list: scan the missing host, re-run the lookup, match the scope.
  • MTTR built to measure remediation, not data churn. The five dnsmasq CVEs above are filed as a data change, because the same dnsmasq 2.78 still answered.
  • Eight frameworks from one read-only scan. One Enterprise scan maps its evidence to all eight: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32 and NIST SP 800-171 Rev 2.

Also in 1.2.0

  • The right rationale for a coverage gap. Wherever an analysis agent’s or the CVE mapper’s own coverage-gap record routes, it is explained by a coverage-gap rule, in every framework.
  • Separate output directories for same-second scans. Two scans of one host whose plugin runs finish in the same second each get their own output directory; each directory is created exclusively.
  • Absolute run names. Every not-comparable reason names its run as “this run” or “the baseline run”, so each detail places an event in the scan where it happened.
  • A newly attributed CVE says what it is. A CVE row that appears on a service that did not change stays NEW, with a note that “the service is unchanged, the vulnerability data is not”: new knowledge about an existing service.

Upgrade notes

  • Upgrade both packages together. Enterprise 1.2.0 requires Community Edition 0.2.56 or newer, and the agent skill 0.2.54 requires the same floor: npm i -g nsauditor-ai@0.2.56 @nsasoft/nsauditor-ai-ee@1.2.0.
  • MCP setup. The docs print the installed nsauditor-ai-mcp command, or for Claude Desktop the configuration block that nsauditor-ai mcp install-key prints.
  • Additive. All eight coverage matrices and the plugin counts (29 Enterprise, 27 Community) carry over unchanged, and the release is minor under the 1.0 contract: new gap-record classes, routing rules and report wording.

Availability

Community Edition is MIT-licensed and free on npm. Pro (from $39 a month billed annually, $470 a year, or $49 month to month) is built for consultants and MSPs who hand a client a before-and-after report. Enterprise (from $2,000 a year for up to five seats, also on AWS Marketplace) is for teams that show an assessor movement between two points in time, across AWS, Azure and GCP and eight compliance frameworks. Cloud audits are read-only: they read configuration and metadata and never need write permissions. Under Zero Data Exfiltration your scan data never goes to Nsasoft, and the product has no telemetry.

Details: nsauditor.com/ai/pro/ · nsauditor.com/ai/enterprise/