NSAuditor AI Enterprise 0.40.3: Compliance Evidence an Auditor Can Verify Without the Vendor

Ask any auditor what separates useful compliance evidence from a nice-looking report, and the answer is the same: can they check it themselves, without trusting the vendor that produced it? NSAuditor AI Enterprise Edition 0.40.3, shipped this week by Nsasoft, is engineered around exactly that answer.

One scan, eight evidence packs, independently verifiable

NSAuditor AI Enterprise performs a single agentless, read-only scan of AWS, GCP, Azure and on-premises infrastructure, and produces eight framework-mapped evidence packs from it in parallel: SOC 2, HIPAA Security Rule §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32 as Security of Processing infrastructure substrate, and NIST SP 800-171 Rev 2 as evidence substrate for CMMC Level 2 preparation.

Nothing leaves the customer’s environment. Every pack carries SHA-256 chain-of-custody attestations, and organisations that want an independent third party in the chain can turn on RFC 3161 trusted timestamping by naming their own Time-Stamp Authority — the customer picks the authority, and the product contacts no other.

The 0.40.3 headline: timestamps bound to the file they attest

A trusted timestamp carries, inside it, a statement of which digest it is attesting. As of 0.40.3, NSAuditor AI Enterprise reads that statement back and matches it against the artifact the request was built from before the timestamp is allowed into the evidence pack.

What that buys the operator is a sentence they can say to an assessor without hedging: the timestamp file in this pack provably belongs to the artifact next to it. When the match cannot be established, nothing is written and the engine records precisely why — one of eight named outcomes, logged per artifact in the chain-of-custody envelope, alongside an explicit verification flag an auditor can read straight out of the JSON.

It is a small change in surface area and a large one in what the evidence is worth.

More authorities, less friction

The release also broadens compatibility with commercial Time-Stamp Authorities. Tokens in alternative valid encodings are now honoured wherever a reader can decode them, which — together with the policy-OID support added in the previous release — smooths integration with the authorities large enterprises already have contracts with.

Verification the customer never has to take on trust

Every report prints a verification command the assessor runs themselves:

openssl ts -verify -in <file>.tsr -data <file> -CAfile <ca-bundle>

Standard openssl, the authority the customer chose, no Nsasoft software involved at any point. For regulated buyers — healthcare, finance, government and defence suppliers, critical infrastructure — that independence is frequently the difference between evidence an assessor accepts and evidence they interrogate.

Operators upgrading from an earlier version can run the same one-liner across existing packs to bring them onto the current standard.

One hundred releases, shipped as a set

The plugin catalog is steady at 28 Enterprise auditors and 55 overall, and all eight coverage matrices are unchanged — this release deepens the assurance under existing reports rather than reshaping them.

It is also the hundredth consecutive paired trio: Enterprise Edition 0.40.3, Community Edition 0.2.47 and the agent skill 0.2.45, shipped together and version-locked, as they have been for one hundred releases running. For teams putting a compliance workflow into production, that cadence is itself a feature.

NSAuditor AI Enterprise starts at $2k/yr, with Community Edition free and MIT-licensed. Full coverage matrices and plugin catalog: nsauditor.com/ai/pricing.