NSAuditor AI Enterprise 1.3.0 Keeps the SLA Clock Running on Findings That Never Went Away

NSAuditor AI Enterprise 1.3.0 keeps SLA age and MTTR counting on findings that never went away, in every compliance pack, with no pack regenerated.

nsauditor-ai-1-3-0-hero

An SLA report is a claim about time: how long a finding has been open, and how long it took to close. That claim is only as good as the scan history underneath it. NSAuditor AI Enterprise 1.3.0, published by Nsasoft US LLC on 7 October 2026 with Community Edition 0.2.57 and the agent skill 0.2.55, strengthens that history in both directions: a finding that stays open stays on the clock, and a scan that looked at less does not turn into a fix.

SLA age that accrues in every compliance pack

An open finding has to be recognised as the same finding on every scan, or its age restarts. 1.3.0 keys each finding on its prose with every framework’s control ids removed, on both sides of the comparison. In the HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS, GDPR and NIST SP 800-171 packs, a cloud finding that stays open is now tracked as one finding scan after scan, so its age reaches the SLA threshold you set and MTTR counts real remediation. A history written by an earlier release reads correctly with no pack regenerated, so the benefit applies to the evidence you already hold.

Three more cases where “gone” now has to be measured

  • A plugin left out of the scan. Each analysis agent reads what named plugins write. Leave one of those plugins out of --plugins on a scan made with 1.3.0, and the scan records an input gap ([COVERAGE GAP] INPUT GAP): the delta refuses the rows that agent would have re-checked, MTTR withholds them, and with SLA tracking on their controls stay FAILED.
  • A TCP port that answered without its service being identified. With the SSH probe left out, port 22 answers as an unidentified service. The CVE mapper and the service agent attribute on a service’s program and version, so their earlier rows there now read NOT COMPARABLE in the delta and stay out of MTTR’s closed count. An identified version change, or an upgrade past end-of-life, still closes.
  • A CVE lookup that failed. With SLA tracking on, the compliance report holds the controls behind those earlier CVE rows FAILED with a [COVERAGE GAP] LOOKUP NOT MEASURED record, and the CVE mapper’s own failed-lookup record fails the controls its CVE rows map to: 14 controls across seven frameworks.

Stable titles, readable rows

  • Titles that name the port. The exposure agent’s titles now name the port, and the service agent’s end-of-life titles name the port and the program, with the service and the version in their own fields. A probe that identifies a service differently no longer makes one unchanged port read as both resolved and new.
  • A Basis cell on every row that moved. In the Pro delta report, each new, resolved and changed row says what was checked for that row, so the reader of a client report sees the evidence behind every change.
  • An accurate “withheld from closure” count. The report’s count now includes a CVE row that a failed lookup or an unidentified TCP port holds back.

Also in 1.3.0

  • One severity table for every service-check finding. --fail-on, SARIF, the CSV, the Markdown report, the scan history and the --watch webhook all read it. From its second cycle on, the webhook alerts on a host whose scan changed and that carries a finding at or above --alert-severity.
  • Sharper checks. The DNS-posture audit declines an IP-address target and records why; the Missing-HSTS check fires on port 443 where the HTTPS response was received; the offline NVD matcher reads only the product queried; and a GuardDuty listing that could not be read is recorded as an evidence gap rather than as a disabled service.
  • Less sensitive data in artifacts. A non-default SNMP community string and the cookie values the HTTP probe records no longer reach the scan’s artifacts, and the AI redactor masks cookie values.
  • NIST SP 800-171. Requirement 3.5.3 carries the four determination statements SP 800-171A (June 2018) gives it, for 69 of 171 objectives evidenced across the 51 mapped requirements, and every objective list is held to a census derived from the NIST publication.
  • A documented egress register of 18 outbound paths, now including a redirect the scanned web server returns (at most five hops, each checked against the host guard’s address rules) and a UPnP device’s own description URL.

What it means for the reports you sign

  • SLA ageing and MTTR you can defend in all eight frameworks: SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32 and NIST SP 800-171 Rev 2, from one read-only scan.
  • Client reports built to be defended line by line, with the reason on every not-comparable row and the basis on every row that moved.
  • Compliance controls held FAILED, with SLA tracking on, when the evidence behind them was not re-measured.

Upgrade notes

  • Upgrade both packages together. Enterprise 1.3.0 requires Community Edition 0.2.57 or newer, and the agent skill 0.2.55 requires the same floor: npm i -g nsauditor-ai@0.2.57 @nsasoft/nsauditor-ai-ee@1.3.0.
  • Start a fresh baseline. Run one scan after upgrading before you compare: the exposure agent’s, the service agent’s and plugin 1160’s rows changed what identifies them, so a comparison across the upgrade reads them identity-basis-changed.
  • Pipelines. --fail-on now reads every graded service-check finding, and nsauditor-ai mcp verify-call <id> expects --response; review both in CI.
  • Carried over. The plugin counts (29 Enterprise, 27 Community) and all eight coverage matrices are unchanged, and the release is minor under the 1.0 contract. The Enterprise suite runs 13,084 regression tests.

Availability

Community Edition is MIT-licensed and free on npm. Pro (from $39 a month billed annually, $470 a year, or $49 month to month) is built for consultants and MSPs who hand a client a before-and-after report. Enterprise (from $2,000 a year for up to five seats, also on AWS Marketplace) is for teams that show an assessor movement between two points in time, across AWS, Azure and GCP and eight compliance frameworks. Cloud audits are read-only: they read configuration and metadata and never need write permissions. Under Zero Data Exfiltration your scan data never goes to Nsasoft, and the product has no telemetry.

Details: nsauditor.com/ai/pro/ · nsauditor.com/ai/enterprise/