Show Clients the Real Age of Their Open Findings: NSAuditor AI Enterprise 1.3.0 for MSPs and Consultants

The question every client asks is simple: are we getting better? The answer lives in two numbers, how long findings stay open and how fast they close. NSAuditor AI Enterprise 1.3.0 and Community Edition 0.2.57, published on 7 October 2026, make both numbers sturdier: a finding that stays open keeps its age, and a scan that looked at less no longer shows up in a client report as progress.

Open findings keep their age

Your SLA commitments are measured in days open. In 1.3.0 a cloud finding that stays open is tracked as the same finding on every scan in the HIPAA, NIST CSF 2.0, PCI DSS, ISO 27001, CIS, GDPR and NIST SP 800-171 packs, so its age climbs toward the threshold you agreed with the client, and mean time to remediate (MTTR) reflects work that was actually done. The scan history you have already collected reads correctly with no pack regenerated, so you can rerun this quarter’s report on the evidence you already hold.

Progress your client can trust

Pro and Enterprise compare two scans and tell the client what changed:

nsauditor-ai report --from <dir> --format executive --since <runId|prior>

1.3.0 makes that comparison harder to fool in three more cases:

  • A narrower scan. When a scan made with 1.3.0 leaves out a plugin an analysis agent reads, the scan records an input gap ([COVERAGE GAP] INPUT GAP). The delta refuses those rows, MTTR withholds them, and with SLA tracking on their controls stay FAILED.
  • A service the scan could not identify. With the SSH probe left out, port 22 answers as an unidentified service. The earlier CVE and service-agent rows there now read NOT COMPARABLE and stay out of MTTR’s closed count, while a real version change or an upgrade past end-of-life still closes.
  • A CVE lookup that failed. The CVE mapper’s failed-lookup record now fails the controls its CVE rows map to, 14 controls across seven frameworks, so a failed lookup is shown as an evidence gap.

A Basis cell on every row that moved

Every new, resolved and changed row in the Pro delta report now carries a Basis cell that says what was checked for that row. When a client asks “how do you know this is fixed?”, the answer is already on the page. That turns a review meeting into a walk through the evidence, row by row.

Alerts that follow the change

One severity table now grades every service-check finding, and --fail-on, SARIF, the CSV and Markdown reports and the --watch webhook all read it. From its second cycle on, the webhook alerts on a host whose scan changed and that carries a finding at or above --alert-severity, so a managed client’s new exposure reaches you without waiting for the monthly report.

Eight frameworks from one read-only scan

One Enterprise scan maps its evidence to SOC 2, HIPAA, NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8, GDPR Article 32 and NIST SP 800-171 Rev 2. Cloud audits across AWS, Azure and GCP are read-only, and under Zero Data Exfiltration your clients’ scan data never goes to Nsasoft.

Upgrade in one line

Enterprise 1.3.0 requires Community Edition 0.2.57 or newer, so upgrade both together:

npm i -g nsauditor-ai@0.2.57 @nsasoft/nsauditor-ai-ee@1.3.0

Run one fresh scan of each client after upgrading to start the new baseline before you compare.

Pricing

Pro, with client delta reports, starts at $39 a month billed annually ($470 a year) or $49 month to month. Enterprise starts at $2,000 a year for up to five seats and is also on AWS Marketplace. Community Edition is free and MIT-licensed on npm.

A report that shows its basis is a report you can walk a client through, row by row. Details: nsauditor.com/ai/pro/ · nsauditor.com/ai/enterprise/