Stronger, more secure IT infrastructure: Rudder launches automated CIS Benchmarks™ compliance solution

Paris, France – 18 November 2025

System hardening has become a top priority, given the resurgence of cyberattacks and tighter regulations, including NIS2, DORA and ISO 27001:2022. With its new add-on, Policy and benchmark compliance, Rudder is revolutionizing the way we apply CIS Benchmarks™. The solution, from France’s leading IT infrastructure security automation provider, implements the recommendations published by the Center for Internet Security® (CIS), so Ops and SecOps teams can harden their systems without affecting Operations. While traditional tools simply scan and report, the new module makes compliance up to 5 times faster and automatically remediates gaps.

System hardening: turning an operational nightmare into a strategic advantage

With the EU’s Network and Information Security Directive 2 (NIS2) now in force and enhanced configuration management requirements under ISO 27001:2022 taking effect, system hardening is no longer optional for organizations managing critical infrastructures.

Until now, applying hundreds of security rules like CIS Benchmarks™ to heterogeneous server environments has been risky and time-consuming, relying on code-based infrastructure tools like Ansible or Puppet. DevSecOps teams often had to choose between maximum security or operational agility, juggling various compliance analysis and deployment tools.

“The market is overrun with tools that just run scans and generate reports, leaving Ops teams facing never-ending lists of non-compliance that all have to be corrected by hand. With Rudder’s new solution, we are breaking free from this outdated model. It doesn’t just diagnose… it remediates automatically, giving teams full control over what they apply.” – Alexandre Brianceau, Rudder CEO.

Game-changing expertise in automated operations

Unlike other solutions such as OpenSCAP, Ansible and Chef InSpec, Rudder Policy and benchmark compliance isn’t limited to auditing. The platform offers:

  • Built-in CIS benchmarks: No need to manually convert PDF recommendations into scripts or code. Rudder natively integrates benchmarks, making them ready to deploy.
  • Gradual, secure deployment: The standout feature of the solution. Admins can adjust the level of intervention, either by policy or by machine group. Both auditing and remediation are automated, making it easy to manage exceptions and customization.
  • Clear, intuitive visibility: Real-time dashboards are organized by benchmark sections, plus compliance scores and integrated documentation for each control. It’s easy to continuously track the compliance status and demonstrate your security posture to auditors.

Measurable gains for Ops and SecOps

Previously, teams had to manually correct hundreds of configurations. Early user feedback shows that benchmark compliance is on average 5 times faster with Rudder Policy and benchmark compliance, thanks to the completely automated Audit-Remediate-Verify cycle.

“We’re shaking up traditional hardening by finally addressing the operational realities of putting it into practice. Rudder has been growing intensely for the past four years, and this new solution marks a major milestone in our vision of making continuous compliance a practical, manageable reality.” – Alexandre Brianceau, Rudder CEO.

Policy and benchmark compliance now available

Policy and benchmark compliance is available now with the Rudder Corporate Security Suite. It is aimed at critical infrastructure requiring an advanced level of compliance and control. Several security benchmarks are natively integrated for major Linux distributions, including CIS Benchmarks™ version 2.0 for Red Hat Enterprise Linux 9. Benchmarks for Microsoft Windows Server systems will become available in the coming months.

Customer case: Nexus-WAN achieves compliance in just 3 days

Nexus-WAN needed to implement CIS Benchmarks™ on its fleet of machines. The managed services provider, which specializes in critical and secure infrastructures, was looking for a way to meet the tougher compliance requirements under DORA, SecNumCloud and NIS2. Without Rudder Policy and benchmark compliance, implementation would have required developing a custom solution or compiling several open-source tools and integrating them manually.

With Rudder Policy and benchmark compliance, Nexus-WAN brought its entire fleet into compliance in just 3 days – including selecting CIS requirements to be applied and correcting drifts.

“Our main fear with hardening was the impact it might have on operations. The granular control that Rudder offers meant we could move steadily from auditing to active remediation, saving us weeks of work while providing peace of mind for our Ops teams.” – Pierre Forest, Nexus-WAN CEO.

Beyond the time it saved, Nexus-WAN now enjoys real-time compliance visibility, comprehensive audit traceability and the ability to instantly detect and correct configuration drift, without causing a headache for Operations.

Contact

For any information, please contact :
Lisa Saadé
Scroll to Top
Rudder robot named Ruddy makes an announcement.

Rudder 9.1: less noise, more control. Compliance without friction.

Security management module details

This module targets maximum security and compliance for managing your infrastructure, with enterprise-class features such as:
Learn more about this module on the Security management page

Configuration & patch management module details

This module targets maximum performance and reliability for managing your infrastructure and patches, with enterprise-class features such as:

Learn more about this module on the Configuration & patch management page