Addigy provides a set of pre-built compliance benchmarks you can deploy in seconds to test and enforce CIS, DISA STIG, CMMC, NIST, and AI Governance compliance across your fleet — no need to build a benchmark from scratch.
Overview
Pre-built benchmarks are offered as part of the Addigy Security Suite, alongside Addigy's broader Device Compliance features. You'll find them ready to deploy in the Compliance tab of the Catalog.
macOS Benchmarks
macOS benchmarks are audited on-device by the Compliance Agent. Every prebuilt macOS benchmark supports macOS 27.
- CIS, at Level 1 and Level 2. CIS Level 1 includes over 80 rules and provides a comprehensive security foundation for most environments.
- NIST, based on the 800-53 baselines, for organizations that require more rigid controls.
- CMMC, at Level 1 and Level 2, for Department of Defense contractors and subcontractors handling federal contract information or controlled unclassified information.
- DISA STIG, for government and defense environments that must comply with federal security requirements.
- Cyber Essentials (beta), for organizations working toward the UK government-backed Cyber Essentials scheme. This benchmark runs in Monitor & Enforce mode.
These benchmarks follow the macOS Security Compliance Project, the open-source effort maintained under NIST (Apple acknowledges the project on its Platform Certifications page). Because the rules are open source, regularly tested, and monitored by Addigy for changes, the rules you assign stay current as standards evolve. Addigy revises the benchmarks alongside each macOS release — Sonoma, Sequoia, Tahoe (macOS 26), and macOS 27 (Golden Gate) — so your fleet stays covered from the day a new OS ships.
iOS and iPadOS Benchmarks
iOS and iPadOS benchmarks align with CIS Level 1 Enterprise and DISA STIG guidelines, delivered as a configuration profile pushed to the device. There's no on-device audit on these platforms — monitoring is based on the successful deployment of that profile.
The CIS Level 1 Enterprise set for iOS 17 comprises 30 rules — 25 Apple MDM restrictions plus 5 passcode payloads — covering controls such as disabling iCloud Backup and Keychain sync, forcing encrypted backups, restricting configuration profile installation, requiring a minimum 6-character passcode, and capping auto-lock at two minutes or less. Some rules require device supervision to enforce, and several restrictions are supervised-only on current or future OS versions.
AI Compliance Benchmark
The AI Compliance Benchmark is a prebuilt AI Governance benchmark for macOS, audited on-device by the Compliance Agent using the same engine as CIS, NIST, CMMC, DISA STIG, and Cyber Essentials. It gives you a policy-based way to contain AI usage across managed Macs, for organizations that want controls in place before deciding which AI tools to adopt.
It provides 30 or more controls at the app and network level, targeting the AI tools that drive the most usage across a typical fleet. You can block unapproved AI tools, monitor whether they're actually blocked, and report on that status for yourself, a client, or an auditor.
Note: The benchmark measures whether an AI tool is blocked. It targets the highest-usage AI tools and doesn't cover AI embedded inside other software.
Rule Impact and Risk Management
Security hardening changes how people use their devices — sometimes considerably. A rule that caps failed passcode attempts, removes a user from FileVault, or disables a familiar feature can generate support tickets the next morning. Addigy shows the end-user impact of every rule in a prebuilt benchmark, for macOS and iOS alike, so you can weigh security value against user disruption before anything reaches a device.
Note: Impact ratings are published for benchmarks targeting the two most recent OS versions. Benchmarks scoped to older releases may show ratings partially or not at all.
Open any prebuilt benchmark in Benchmark Settings (Select... > View Details), and each rule carries a color-coded tag with an impact rating of High, Medium, or Low, plus the kind of change it makes (Restriction, Notification, Lockout). An impact legend at the top of the rule list explains the ratings, and a search field helps you find a specific rule quickly.
Expanding a rule shows four things in one place:
- The requirement — the setting the benchmark expects.
- The security rationale — the threat the rule addresses.
- End-user impact — a plain-language description of what users will experience once the rule is enforced. For example, the iOS rule limiting consecutive failed login attempts is rated High and tagged Lockout, with a note explaining that a user who mistypes their passcode several times is locked out until the lockout window passes.
- The fix — how Addigy brings the device into compliance, such as the configuration profile it installs.
From Benchmark Settings, you can download the benchmark specification, clone the benchmark to keep only the rules suited to your environment, and assign it to policies — reviewing High-impact rules and removing the rest from a clone before any device is affected.
Monitor & Enforce vs. Monitor-Only
When you browse prebuilt benchmarks in the Catalog, each one is offered in two modes:
- Monitor & Enforce — audits devices against the benchmark's rules and automatically remediates any that fail, bringing devices into compliance.
- Monitor-Only — audits devices and reports pass/fail status without changing anything on the device.
Both modes list the same benchmarks, organized by OS version. For example, CIS - Level 1 is available separately for macOS 27 (beta), macOS 26, and macOS 15, and CIS - Level 1 - Enterprise is available for iOS 26 and iOS 18. Each card shows the rule count and the date it was last updated; select Older versions to see benchmarks built for earlier OS releases.
How to Apply a Prebuilt Benchmark to a Policy
- In the Catalog, find the mode (Monitor & Enforce or Monitor-Only) and OS version of the benchmark you want.
- Click Select... on that benchmark's card.
- Choose one of three actions:
- Clone... — copy the benchmark so you can customize which rules it includes before assigning it.
- View Details... — review the benchmark's rules and impact ratings without assigning it yet.
- Assign Directly... — assign the benchmark as-is to one or more policies.
- If you choose Assign Directly, the Assigned Policies window opens. Check the policies you want the benchmark deployed to, then click Save. The benchmark deploys to supported devices in each selected policy and its child policies.
Note: Assigning a benchmark directly applies every rule it contains, including any rated High impact. Addigy warns that some rules in a benchmark may cause devices to become inaccessible or disrupt the end-user experience — clone the benchmark first if you want to review or remove specific rules before assigning it.
Frequently Asked Questions
Which benchmark should I use?
That depends on your organization's security requirements. The CIS Level 1 set includes over 80 rules and provides comprehensive security; NIST options are even more rigid. Many customers find the full set stricter than they need, so they clone the original benchmark and keep only the rules that apply to them.
Where are the pre-built benchmarks generated from?
They're based on guidelines from the Center for Internet Security (CIS) and the National Institute of Standards and Technology (NIST), and leverage open-source resources such as the macOS Security Compliance Project.
Is there a risk to using a pre-built benchmark?
The rules from CIS and NIST are open source and regularly tested, and we're confident they provide the best option for industry-recommended security. Addigy also constantly monitors the specification for changes, so the rules you assign stay updated as needed.
What's the difference between a Benchmark and a Baseline?
A Benchmark is meant to be applied in totality, with every rule accounted for. A Baseline is more of a catalog of rules that's never meant to be applied in full — in some cases, a Baseline can even contain conflicting rules.
I have compliance rules that aren't covered by either spec. What do I do?
A common example is requiring anti-virus software on all devices. Creating custom rules and benchmarks is straightforward, and custom benchmarks can be assigned to the same policies as pre-built ones. We recommend using the official rules where possible, since they're updated from time to time.
Should I select Monitor and Remediate or Monitor-Only?
Monitor and Remediate enforces compliance by running scripts or installing profiles as needed so each device passes the benchmark — most customers prefer this to reduce the need for a human admin to step in. Monitor-Only runs the same tests but doesn't attempt to fix anything; reports are still available showing which rules passed or failed on each device.
How do I know how disruptive a rule will be before I assign it?
Open the benchmark in Benchmark Settings and expand a rule to see its High/Medium/Low impact rating, the kind of change it makes, and a plain-language description of the end-user impact.