Cyver Core transitions your team from spreadsheet-based compliance tracking to an integrated, framework-driven audit management platform. This workflow is suitable for CIS Benchmarks, enabling you to systematically evaluate system configurations against industry best practices, map specific controls, and track nonconformities seamlessly.
Follow this onboarding flow to set up your audit operations: Templates & Benchmarks > Client Enablement > Audit Execution & Tracking > Insights & Delivery > Audit Requests & Subsequent Cycles.
1. Preparing Your Templates
A. Configure Benchmarks & Compliance Norms
Benchmarks Setup: Build custom scoring and evaluation frameworks using a three-tier hierarchy (Benchmark > Groups > Tests) via Settings > Benchmarks. You can also bulk import them from files to save time. See our Benchmarks article for more information.
Compliance Norms: Ensure your specific compliance frameworks are properly configured and ready to be linked to your audits. See our Setting Up Compliance Norms article for more information.
B. Create Your Audit Report Template
Define the visual and structural output for your final audit documents.
Use Cyver Core’s pre-built template (IT Audit/Benchmark Report Template) or build your own audit-specific templates from scratch.
Use Benchmark Tokens: Ensure you insert specialized tokens like
{Benchmark_Summary}to automatically pull testing data and compliance scores directly into your document.
For a complete walkthrough on styling, Markdown, and using tokens, read our detailed guide on Customizing Report Templates.
C. Create Your Audit Project Template
Bundle your workflows and methodologies into a repeatable audit offering.
Workflows: Leverage out-of-the-box audit workflows to set up project stages designed specifically around the needs of audits and external auditors.
Report & Finding Defaults: Link your Audit Report Template, Checklists, Compliance Norms, Workflows, and Benchmarks. Set the default finding type to Non-conformity so the system correctly treats issues as audit deviations rather than standard security vulnerabilities. (Note: Advanced methodologies may require the "Advanced Methodologies & Compliance" Add-on).
To learn more about customizing audit templates, read our article on Customizing Pentest Templates.
2. Client Enablement
Audit management requires seamless communication with the client's internal compliance and IT teams.
Client Accounts: Navigate to Clients and add your client to create their dedicated workspace.
Client Users: Onboard internal client teams (e.g., IT, Compliance Officers) under the client's Users tab so they can track remediation and respond to nonconformities in real-time.
For more details, refer to our Onboarding Clients article.
3. Audit Execution & Nonconformity Tracking
A. Start the Audit Project
Create a new project by selecting the Client and the predefined Audit Template you prepared.
B. Manage Benchmarks (Execution & Results)
Assignments & Status Tracking: Use the project's dedicated Benchmarks tab to assign specific tests to team members and track their progress (e.g., To Do, In Progress, Completed, Skipped).
Registering Results: Log actual outcomes (Pass, Partial, Fail, Not Applicable) individually or in bulk. Use the comments section to leave notes.
C. Manage Findings (Nonconformities-as-Tickets)
Import & Auto-Fill: Automatically add data from your finding library, merge findings across instances, and auto-fill CVSS and compliance framework data to save time on every import.
Live Ticketing: Deliver these nonconformity findings as actionable tickets immediately to the client dashboard. This allows client teams to start remediating critical issues without waiting weeks for the final audit report.
Remediation & Retesting: Help clients track their time-to-fix. They can request retests and verify fixes in real-time directly on the ticket, ensuring they are fully prepared to pass the final compliance check.
4. Insights & Audit Delivery
A. Monitor the Live Insights Dashboard
Instruct your clients to open their Insights tab within the active project. Here, they can view real-time compliance tracking, nonconformity status charts, and assess their overall audit readiness at a glance.
B. Reporting & Delivery
When the audit cycle concludes, navigate to the Report tab and generate your document. The system will automatically compile all passed/failed benchmark tests, attached evidence, and resolved nonconformities into an audit-ready PDF, ready for secure digital delivery to external authorities or stakeholders.
For advanced reporting features and token management, explore our article on Generating, Changing, and Duplicating Report Templates.
5. Audit Requests & Subsequent Cycles
When a client is ready for their next compliance check or needs a full re-evaluation to verify major remediated nonconformities, they can request a brand-new audit engagement or a full project retest directly from their portal. Your team will receive a notification to review and approve the request, automatically initiating the new audit scope. (Note: Both the "Request Pentest" and "Project Retest" workflows require the Professional plan, or the "Advanced Client Portal" Add-on for Starter plans).
To learn how to configure intake forms for new client audit requests, read our guide on Request Forms.
For a complete walkthrough on setting up entire projects for a subsequent evaluation, check out Retest Project setup.