NSAuditor AI Enterprise 0.45.0: Your Evidence Pack’s Timestamps Now Come From an Authority You Choose

If you are the person who has to hand an evidence pack to an assessor, NSAuditor AI Enterprise 0.45.0 changes one thing you will care about: the time on the evidence now comes from an authority you pick, and the pack itself tells the reviewer what the scanner did and did not measure. Nsasoft US LLC published the release on 7 September 2026 with Community Edition 0.2.52 and the agent skill 0.2.50.

The five-minute setup that changes how your pack is read

Set one environment variable — NSAUDITOR_TSA_URL — to the RFC 3161 Time-Stamp Authority your auditor already accepts, and the opt-in timestamping path does the rest: every compliance artifact gets a .tsr sidecar whose time is signed by that authority, not read from the laptop or container the scan ran on. A reviewer verifies it with stock openssl ts -verify. If the scanning host’s clock was wrong, the token is not, and the gap between the two is itself a signed fact the assessor can read.

Leave the variable unset and nothing breaks: the pack says plainly that no authority was configured. That is the point of the release — the artifact never implies a guarantee it did not obtain.

What the cover block now says

Every pack opens with a scope attestation: CIDR list, exclusions, scanner version, framework. In 0.45.0 its ntp block is a fixed set of six constants and one prose note — this scanner does not measure its own clock; use the timestamping path for an independent time anchor. Because the nsauditor.scope-attestation/v1 schema is unchanged and every existing pack already carried those six keys with those values, nothing in your downstream tooling needs to change, and no pack you have already delivered is invalidated. Consistent with that standard, the NTP clock-attestation probe is WITHDRAWN as of EE 0.45.0 — it attested the scanner’s own host clock, never your estate — and the wording that described it is guarded against reappearing on any published surface.

Why the version number moved

Nsasoft shipped this as a minor version, not a patch, on the principle that a change to what the product claims should be findable in the version series an auditor reads. Community Edition 0.2.52 carries no scanner behaviour change, and the agent skill 0.2.50 teaches AI assistants the same line: asked about clock drift, an assistant running the skill says the scanner does not measure it and points at the timestamping path.

Everything else stays where you left it

29 Enterprise auditors (28 cloud auditors plus one Zero Trust posture check), 56 plugins overall, and all eight coverage matrices unchanged — SOC 2, HIPAA §164.312, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32 (Security of Processing infrastructure substrate only, not GDPR compliance) and NIST SP 800-171 Rev 2 as evidence substrate for CMMC Level 2 preparation. Enterprise 0.45.0 requires Community Edition 0.2.49 or newer, the same floor as before. The report command that arrived in 0.44.0 — one self-contained HTML file a consultant can send, with coverage stated on the cover — is unchanged and pairs naturally with authority-anchored time: a report you can send, over evidence you can date.

Get it

NSAuditor AI Community Edition is free; Pro and Enterprise add the report renderer and the cloud auditors. Documentation, the plugin catalogue and the timestamping how-to are at nsauditor.com/ai/enterprise/.