Scanner Compliance Comparison Integrity Pricing Request License

Every misconfig.
Surfaced.
Before the breach.

NatMesh is an offline-first, multi-vendor network configuration auditor for defense, finance, and DevSecOps teams. Drop a config in. Get back a CVSS-scored, compliance-mapped, auditor-ready finding report — without a single packet hitting your network.

0
Security rules
0
Vendor parsers
0
Frameworks
0
Phone-home calls
CLR·CSC FILE: edge-fw-01.cfg FOUND 0 LIVE
28 PARSERS · CERTIFIED
CISCO IOS OK IOS-XE OK NX-OS OK CISCO ASA OK JUNIPER JUNOS OK PALO ALTO PAN-OS OK FORTINET FORTIOS OK CHECK POINT OK HUAWEI VRP OK H3C COMWARE OK F5 BIG-IP OK HPE ARUBA OK EXTREME OK SANGFOR OK FORCEPOINT OK TRELLIX OK TREND MICRO OK NETSKOPE OK PROOFPOINT OK BEYONDTRUST OK IBM OK ERICSSON OK CISCO IOS OK IOS-XE OK NX-OS OK CISCO ASA OK JUNIPER JUNOS OK PALO ALTO PAN-OS OK FORTINET FORTIOS OK CHECK POINT OK HUAWEI VRP OK H3C COMWARE OK F5 BIG-IP OK HPE ARUBA OK EXTREME OK SANGFOR OK FORCEPOINT OK TRELLIX OK TREND MICRO OK NETSKOPE OK PROOFPOINT OK BEYONDTRUST OK IBM OK ERICSSON OK
§ 01 · ENGINESECTION-A

Watch a real config
get torn apart.

No agents. No SNMP polling. No credentials. Drop the exported config and the engine identifies vendor, walks every rule pack, and writes a finding with CVE, CVSS, STIG, and remediation in seconds.

edge-fw-01.cfg VENDOR · CISCO IOS-XE
SHA · 0xa3f4
FINDINGS · STREAM 0 findings
SCAN 0%
LINES 0 · FINDINGS 0 · CRIT 0
§ 02 · SCORINGFOUR SYSTEMS · ONE FINDING

Risk you can defend
in front of an auditor.

Every finding lands with four independent scores. CVSS for severity, STIG CAT for DOD posture, Cisco SIR for vendor alignment, and a 0–100 composite weighted by device role — because the same misconfig on a border firewall is not the same risk as on an access switch.

SCORE · 01 / 04 · CVSS v3.1
0.0 10.0 9.8 CRITICAL

CVSS v3.1

Per-finding base, temporal, and environmental scores. Standard, defensible, and machine-parseable for SIEM ingestion.

SCORE · 02 / 04 · STIG · CAT
III I CAT I DISA · RMF

DISA STIG · CAT

Maps every finding to Category I/II/III against the relevant DISA STIG. Drops directly into your RMF package.

SCORE · 03 / 04 · CISCO SIR
LOW CRIT HIGH CISCO · SIR

Cisco SIR

Cisco Security Impact Rating for Cisco platforms — speaks the vendor's own language so PSIRT advisories line up cleanly.

SCORE · 04 / 04 · NatMesh · 0–100
0 100 87 ROLE-WEIGHTED

Composite · Role-Weighted

Our 0–100. Same misconfig scores higher on a border firewall than an access switch, because exposure context is the whole point.

§ 03 · COMPLIANCESIX FRAMEWORKS · ONE PASS

Audit evidence,
pre-mapped.

Per-control pass/fail with evidence generated automatically. Hand the PDF to a QSA, an Authorizing Official, or a CMMC C3PAO and they read it the way they already think about your network.

CAT-I / II / III

DISA STIG

12-rule dedicated pack · NIST 800-53 r5

Every finding maps to a STIG Vul-ID with severity and CCI references. RMF-ready evidence package out of the box.

CAT ICAT IICAT III
PCI-DSS · v4.0

PCI-DSS 4.0

Requirements 1 · 2 · 6 · 8 · 10

Dedicated 10-rule pack written against the v4.0 final standard. QSA-grade prose evidence with control numbers.

REQ 1REQ 2REQ 6REQ 8REQ 10
CMMC · LEVEL 2 / 3

CMMC 2.0

NIST 800-171 + 800-172

14 dedicated CMMC rules tied to the assessment objectives every DIB contractor will see during a C3PAO walkthrough.

ACSCIAAUSI
NIST · 800-53 r5

NIST 800-53

AC · SC · IA · AU · CM · SI · SA

Control families tagged on every rule. Direct evidence into FedRAMP, FISMA, and StateRAMP assessment packages.

AC-3SC-7IA-2AU-2
CIS · BENCHMARKS

CIS Controls

CSC v8 · cross-tagged

Center for Internet Security control numbers attached to every rule for cross-walk with audit programs.

CSC 4CSC 5CSC 6CSC 12
NIST · 800-63B

800-63B Auth

Password & identity assurance

Detects every Cisco password type (0, 5, 7, 8, 9) and grades against the 800-63B memorized-secret guidance.

TYPE 0TYPE 5TYPE 7TYPE 8TYPE 9
§ 04 · DEPTHWHAT A SCANNER WILL NEVER SEE

Three things
nothing else does.

A port scanner reads what's open. NatMesh reads what's written — and what's been written for the last twelve months. Segmentation posture, drift over time, and a tamper-evident chain of every scan you ever ran.

Zero Trust scoring

Segmentation, graded.

Every firewall, ACL, and zone policy is scored on a Zero Trust scale — implicit any-any, over-permissive egress, missing micro-segmentation all surface as ranked findings.

Drift detection

Every scan, queryable.

Local DuckDB keeps every scan. Compare any two runs and NatMesh shows you which findings were fixed, which regressed, and what's new since the golden baseline.

12scan · 2026-05-18T14:22Z
sha256=a3f4…8c2b · prev=7b21…0e91
11scan · 2026-05-17T09:04Z
sha256=7b21…0e91 · prev=fe12…d3b4
10scan · 2026-05-15T18:31Z
sha256=MISMATCH · CHAIN BROKEN
09scan · 2026-05-14T11:17Z
sha256=4c98…a712 · prev=2e1f…b8a3
Tamper-evident audit

If it was edited, you'll know.

Every scan event is hash-chained to the previous. verify_audit_integrity() walks the chain and flags any break — even one altered byte.

§ 05 · COMPARISONDECLASSIFIED · FOR DISTRIBUTION

Other online solutions
vs NatMesh.

Most online config auditors haven't meaningfully advanced in years. Here is the same feature list, side by side. Black bars are where the typical online solution has nothing to say.

FILE · COMPETITIVE-MATRIX-2026Q2.PDF13 ROWS
CAPABILITY
ONLINE SOLUTIONS
NatMesh
Vendor parserscisco · juniper · forti · palo · …
~15
28
Security ruleschecked patterns
~70
202
Offline-only, air-gap compatibleno telemetry, no license server
Yes
Yes
Contextual risk by device roleborder vs edge vs access
 
Role-weighted
Zero Trust segmentation scoringpolicy graph + grade
 
Built-in
CVE correlation, offlinestatic KB + NVD cache
 
22 + NVD
Dedicated CMMC 2.0 rule packL2 + L3
 
14 rules
Dedicated DISA STIG rule packCAT I/II/III
 
12 rules
SARIF output for CI/CDGitHub Actions · Azure DevOps
 
First-class
Drift detection scan-over-scanDuckDB · golden baseline
 
90-day window
Tamper-evident audit chainhash-linked events
 
SHA-256
Extensible rules — no codedeclarative YAML packs
 
YAML
White-label reportscompany / logo / footer
Paid add-on
Included
License modelhow you pay
Per-device subscription
One-time, per-machine
DECLASSIFIED05·18·2026

On every modern capability — Zero Trust scoring, role-weighted risk, offline CVE correlation, SARIF/CI-CD output, drift detection, and a tamper-evident audit trail — the typical online solution has nothing to put in the column. We just shipped the next decade of the category.

§ 06 · OPERATORSFOUR PROFILES · ONE LICENSE

Who runs NatMesh.

The buyer doesn't change the engine. The engine changes the buyer's mandate. Defense contractors, payment-card teams, MSSPs, and DevSecOps all ship the same binary.

CMMC · L3
FOR USE BY · 01

Defense & Federal

  • Air-gap requirement eliminates every SaaS competitor on the list.
  • DISA STIG + CMMC 2.0 packs ship pre-built — no consultant engagement.
  • RMF-ready evidence drops straight into the AO's package.
PCI · QSA
FOR USE BY · 02

Financial · PCI

  • Tamper-evident audit log — exactly what a QSA wants to see.
  • PCI-DSS 4.0 control evidence with Req 1/2/6/8/10 mapping.
  • White-label PDF for the bank's annual ROC supporting evidence.
MSSP · BATCH
FOR USE BY · 03

MSSPs & Consultancies

  • Headless CLI scans 100 configs in a batch from a single workstation.
  • White-labeled PDFs swap company name, logo, and footer per client.
  • One per-analyst machine license — no per-device meter to manage.
CI / CD
FOR USE BY · 04

DevSecOps

  • SARIF output renders natively in GitHub & Azure DevOps PRs.
  • Exit code 2 on critical/high — fail the build, block the merge.
  • Config-as-code friendly. The rule engine is itself YAML.
§ 07 · CI/CDSARIF · FIRST-CLASS

Drop it in your
pipeline. Done.

natmesh-cli is a single static binary. Add a step to your GitHub Actions or Azure DevOps pipeline. The same SARIF that flows into GitHub Security tab also lands in Defender, Sentinel, and any modern SIEM.

.github/workflows/audit.yml GITHUB ACTIONS
# Audit every config on push to main
name: network-config-audit
on: [push, pull_request]

jobs:
  audit:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Run NatMesh
        run: |
          natmesh-cli scan \
            --config ./configs/*.cfg \
            --format sarif \
            --exit-on critical,high \
            --out natmesh.sarif

      - uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: natmesh.sarif
natmesh.sarif (excerpt) FINDING · SARIF v2.1.0
{
  "ruleId": "natmesh.snmp-001",
  "level": "error",
  "message": { "text": "Default SNMP community 'public'" },
  "locations": [{
    "physicalLocation": {
      "artifactLocation": { "uri": "edge-fw-01.cfg" },
      "region": { "startLine": 42 }
    }
  }],
  "properties": {
    "cvss": 9.8,
    "stig": "CAT-I",
    "cwe": "CWE-798",
    "natmesh-role-score": 87,
    "compliance": ["PCI-DSS 2.1", "STIG-V-220547"]
  }
}

# Pipeline summary
 scan complete: 1247 lines · 12 findings · 3 critical
 exit code 2: build blocked by critical findings
§ 08 · LICENSEMACHINE-LOCKED · OFFLINE

One license file.
One machine. No server.

Pay once. The license file natmesh.lic binds to a machine ID and works forever on that workstation. No phone-home. No subscription meter. No SaaS dependency to lose when your contract changes.

TIER · 01SOLO

Analyst

One workstation. One operator. Everything an in-house security engineer needs to audit their fleet.

Contact us
One-time · per machine · perpetual
  • All 202 security rules
  • All 28 vendor parsers
  • All 6 compliance frameworks
  • PDF · HTML · Excel · CSV · SARIF · JSON
  • Drift & tamper-evident audit chain
  • GUI + headless CLI
  • White-label branding
  • Priority support SLA
Request License
TIER · 03FLEET

Command

For defense primes, federal SI, and large financial. Unlimited seats. Custom rule packs. On-site enablement.

Custom
Contact for quote
  • Everything in Field Unit
  • Unlimited machine licenses
  • Custom rule packs (we write, you own)
  • Air-gap install & classified-net guidance
  • Dedicated Signal channel + named TAM
  • On-site enablement (1 week, included)
  • Source escrow available
  • Priority CVE-pack updates
Talk to us
§ 09 · FAQ

Questions
we get often.

If something isn't here, ask. Engineers answer Engineering.

No. Zero telemetry. No license server. No update beacon. natmesh.lic is verified locally against the machine ID. The binary runs on air-gapped Class C networks without modification.

A curated KB of 22 high-impact real-world CVEs ships in the binary (CVE-2024-3400, CVE-2024-21762, CVE-2023-27997, CVE-2022-42475, CVE-2018-0101, and others). An offline NVD JSON cache lives at ~/.natmesh/nvd_cache/. The live NVD API is opt-in only.

Yes. Rules are pure YAML — prerequisite_patterns, required_patterns, negative_patterns, plus the narrative fields that flow directly into the report (checked_text, matters_text, impact_rating). No Python required to extend the engine.

Four parallel scores per finding: CVSS v3.1, DISA STIG CAT, Cisco SIR, and a NatMesh 0–100 composite weighted by the device's role in the traffic path. The same SNMP "public" community on a border firewall and an access switch produce very different role-weighted numbers.

Every scan event is hash-chained to the prior event. verify_audit_integrity() walks the chain end-to-end. A single altered byte anywhere in the history breaks the chain and is flagged.

natmesh-cli exits 0 on clean, 1 on info/low findings, and 2 on any critical or high finding. Drop it in CI with --exit-on critical,high and your pipeline will block the merge automatically.

Yes. The license file binds to a machine ID and is perpetual on that workstation. Annual maintenance is optional — and only buys you new rule packs and CVE updates. The engine you bought continues to run regardless.

REQUEST · CLR-LIC-2026 · FORM A

Pull the trigger
on the audit you've been
deferring.

Fifteen-day evaluation license. Drops onto one machine. No demos to sit through, no SDR to dodge — the binary just runs.