For an MSP or a security consultant, trust is won in the second meeting, when the client asks what their money bought and the report shows what got better since the last scan. NSAuditor AI Enterprise 1.2.0 and Community Edition 0.2.56, published on 4 October 2026, extend the Pro and Enterprise delta report’s measured comparison to five more cases, each filed NOT COMPARABLE with its reason instead of resolved, and add a sixth for Enterprise compliance reports: a control held FAILED when this scan did not re-measure the prior finding behind it.
The second meeting, won
A delta report earns its keep when every line holds up to a follow-up question. 1.2.0 checks six more ways a finding can go missing: an SNMP service on the router that did not answer the second scan, a CVE lookup that failed, vulnerability data that changed under unchanged software. Where the report sees one of them, the row says so and gives the reason.
What 1.2.0 adds to the client delta
The delta report compares two scan runs with nsauditor-ai report --from <dir> --format executive --since <runId|prior> and renders what is new, resolved or changed into the client-ready HTML report. Point --from at the folder your scans write to with --out; prior picks the run before the one you report on. In 1.2.0:
- UDP services that went quiet. A UDP finding that vanished reads NOT COMPARABLE unless the other scan recorded that port as closed or as answering. Measured on a real router run against a twin without its 22 UDP rows: 1.2.0 reports all 22 not comparable, each with its reason.
- Vulnerability data that changed. NVD stopped matching five CVEs to dnsmasq 2.78 while the router still ran dnsmasq 2.78. 1.2.0 files them NOT COMPARABLE as
vulnerability-data-changed, and the row says the absence is “a change in the vulnerability data it was matched against, not a remediation”. - CVE lookups that failed. When a service’s vulnerability lookup failed in one scan, the delta and MTTR do not count its earlier CVE rows as fixed.
- Analysis agents that did not run. An agent that failed, timed out or returned no finding list leaves a
[COVERAGE GAP] AGENT NOT RUNrecord. The delta holds that agent’s rows out of the comparison, MTTR withholds them, and 78 generated routing rules route the gap to the controls that agent’s findings fail, in every framework that maps that agent. - An Enterprise package that did not load. Community Edition 0.2.56 names the failure on stderr and records it on the scan’s conclusion, and the delta holds that host’s analysis-agent and CVE rows out of the comparison.
When the report can see that a finding was not measured the same way twice, it files it under NOT-COMPARABLE with the reason on the row. That turns a client question into a to-do list: scan the missing host, re-run the lookup, match the scope.
For compliance clients (Enterprise): the control hold
With SLA tracking on (--compliance-history <dir> or --sla-policy <file>), a control that failed on a prior finding stays FAILED, backed by an evidence-gap record, when this scan did not re-measure that finding’s port, region or producer. The report counts the record among “Evidence gaps (not findings)” and never presents it as a current finding. It applies once the history holds a prior --compliance <fw> scan of the same host.
Three habits for your next client delta
- Read the reason on every not-comparable row. It tells you what to run next before the meeting.
- Keep the compliance history. The control hold reads it, so point every compliance scan at the same
--compliance-historyfolder. - Upgrade both packages together. Enterprise 1.2.0 requires Community Edition 0.2.56 or newer:
npm i -g nsauditor-ai@0.2.56 @nsasoft/nsauditor-ai-ee@1.2.0.
A report that shows its reasons is a report you can walk a client through, row by row.
Built for the way a practice works
- Client-ready HTML, with the reason on every not-comparable row.
- Read-only cloud audits. They read configuration and metadata only and never need write permissions on a client’s account.
- Zero Data Exfiltration. Client scan data never goes to Nsasoft, and the product has no telemetry.
- Pricing that fits a practice. Pro is from $39 a month billed annually ($49 month to month). Enterprise, for AWS, Azure and GCP estates and eight compliance frameworks from one read-only scan, is from $2,000 a year and is also on AWS Marketplace. Community Edition is free and MIT-licensed.
Show the client the movement
Any tool can diff two scans. The value is in what the report does when the second scan never looked, and 1.2.0 handles six more of those cases.
See what changed since the last scan with Pro, for consultants and MSPs, at nsauditor.com/ai/pro/, and Enterprise at nsauditor.com/ai/enterprise/.




