Addigy Compliance Benchmarks let you deploy, enforce, and prove security compliance across every Mac, iPhone, and iPad you manage. Deploy CIS, NIST, CMMC, DISA STIG, or Cyber Essentials benchmarks in seconds, layer in your own rules for frameworks like HIPAA, SOC 2, ISO, or FedRAMP, and let Addigy monitor for drift and remediate it automatically — so your fleet stays audit-ready between assessments, not just during them.
Looking for official CIS, DISA, or NIST compliance for iOS or macOS? Read about Addigy's pre-built benchmarks, which we keep in sync with the official spec.
Overview
Compliance benchmarks are selected from the Catalog, the same place you manage every other asset in your Addigy environment. A Benchmark is a bundle of Rules you assign across all or part of your fleet; each Rule sets up real-time monitoring on a device fact, with optional automated remediation.
Compliance is assigned the same way on every platform, but evaluated differently depending on the device:
| macOS | iOS and iPadOS | |
|---|---|---|
| What evaluates compliance | The Compliance Agent, a dedicated binary on the device | The MDM configuration profile delivered to the device |
| How it's delivered | Rules assigned to a policy, audited on device | A configuration profile pushed to the device |
| What's measured | Each rule is tested and returns pass or fail | Successful deployment of the profile carrying the restrictions |
| When status updates | On each device check-in, including offline audits | When the profile installs or its status changes |
| Remediation | Automatic in Monitor & Enforce mode | Enforced by the profile itself; no on-device audit or script remediation |
Throughout this article, audit refers to the on-device check the Compliance Agent performs on a Mac. For iOS and iPadOS, the equivalent concept is profile deployment status, since those devices don't run the Compliance Agent.
Note: Addigy Compliance can also be accessed via the Addigy API v2.
Prebuilt Compliance Frameworks
Addigy makes a set of prebuilt benchmarks available as part of the Security Suite, ready to deploy in seconds from the Compliance tab of the Catalog — covering CIS, NIST, CMMC, DISA STIG, and Cyber Essentials for macOS, an AI Compliance Benchmark for macOS, and CIS/DISA STIG-aligned benchmarks for iOS and iPadOS. See Addigy Pre-built Compliance Benchmarks for the full list of available benchmarks, each rule's end-user impact rating, and how to browse, clone, or assign one directly to a policy.
How to Create a Custom Rule
Rules are similar to Alerts — they set up real-time monitoring on a specific device fact along with automated remediation. For example, a Rule can check whether FileVault is enabled. Rules are then included in one or more Benchmarks.
- Navigate to Catalog > Compliance > Rules to create a New Rule.
How to Create a Custom Benchmark
Benchmarks consist of any number of Rules and are also created from the Catalog page.
- Navigate to Catalog > Compliance > Benchmarks > New Custom Benchmark.
- Add Rules to meet your organization's security needs.
Note: Each benchmark has a target OS with minimum and maximum versions. Addigy only runs compliance tests on devices that meet that criteria.
How to Apply Your Benchmark
Assign your benchmark to one or more Policies to start tracking device compliance. Benchmarks can be added to Flex Policies or your standard Policy Hierarchy.
- On the policy view, select Compliance in the left navigation bar.
- Select your benchmark in the table, then click Add/Remove > Add to policy.
Continuous Monitoring and Remediation on macOS
On Macs, compliance runs continuously through the Compliance Agent — a dedicated binary, separated from the main Addigy agent, that runs audits and remediation independently for better performance and reliability. It deploys automatically as part of the agent update, with no manual installation required, and supports offline compliance monitoring, so a device can run audits and generate results even while temporarily disconnected from the network.
Two modes determine what happens after an audit:
- Monitor-Only runs the tests and reports which rules passed or failed, leaving the device unchanged — useful for gaining visibility before enforcing anything.
- Monitor & Enforce enforces compliance by running scripts or installing profiles as needed so each device passes the benchmark. Most customers prefer this mode since it reduces the need for an admin to step in when drift occurs.
These modes apply to macOS only. On iOS and iPadOS, there's no on-device audit and no script-based remediation — the configuration profile enforces the controls, and compliance status simply reflects whether that profile deployed successfully.
How to View Compliance Results
You can view compliance at a high level from the Devices page by adding the Compliant device fact as a Column.
Click the red or green icons in the Compliant column for details on which benchmark is out of compliance and which specific rules are failing.
You can also see individual device status in GoLive.
Compliance Performance Report
For a fleet-wide view of compliance over time, the Compliance Performance report collects several charts about your fleet's compliance into a single prebuilt report. Find it under Reports > Compliance Performance, alongside other prebuilt reports; you can also build your own reports from the Reports section.
Addigy gathers historical data each night at approximately 12 a.m. EST, so the report shows how compliance changes over a date range rather than just a single snapshot. Charts render as doughnut charts, line charts, bar charts, or single-value scorecards; the three-dot menu on any chart opens Show Data to inspect underlying records, search for a device, and open its GoLive page. Viewing this report requires the View Reports and Export Reports Data permissions.
Exporting Compliance Reports
For evidence and analysis, Addigy also exports Compliance Reports (Overview, Benchmark Breakdown, Failed Rules, and Full Report) from the Devices page or any Policy view, delivered as a CSV to your email. See Compliance Reports for details on each report type.
Custom Rules and Benchmarks for Other Frameworks
Prebuilt frameworks cover common standards, and custom rules cover everything specific to your organization. This lets you align a fleet with frameworks Addigy doesn't ship as a prebuilt benchmark — including HIPAA, SOC 2, ISO, and FedRAMP — by expressing their requirements as rules you control.
You can also clone any prebuilt benchmark and customize it. Many organizations find the full CIS or NIST set stricter than they need, so they clone the original and keep only the rules that apply to them. A cloned benchmark continues to receive Addigy's automatic rule updates, so you retain current, maintained rules while tailoring the set to your environment. See Cloning and Customizing Pre-built Benchmarks.