Back to Login

Frequently Asked Questions

Find answers to common questions about CyberCAAT

Getting Started

What is CyberCAAT?
CyberCAAT (Cybersecurity Assessment & Auditing Technology) is a comprehensive security and compliance management platform. It helps organizations assess their security posture, track compliance with various frameworks (NIST CSF, CMMC, SOC 2, etc.), manage vulnerabilities, and monitor for security threats.
How do I get started with CyberCAAT?
After logging in, we recommend:
  • Setting up your organization profile and assets
  • Selecting the compliance frameworks relevant to your industry
  • Running your first risk assessment
  • Configuring monitoring services for breach detection
Visit the Knowledge Base for detailed tutorials.
What compliance frameworks does CyberCAAT support?
CyberCAAT supports multiple compliance frameworks including:
  • NIST Cybersecurity Framework (CSF) 2.0
  • CMMC (Cybersecurity Maturity Model Certification)
  • CIS Controls
  • SOC 2
  • HIPAA
  • ISO 27001
  • PCI DSS
Our control catalog maps across frameworks to reduce duplicate effort.

Account & Access

How do I reset my password?
Click "Forgot Password" on the login page and enter your email address. You'll receive a password reset link within a few minutes. If you don't receive it, check your spam folder or contact support.
How do I add team members to my organization?
Administrators can add users by navigating to Settings > User Management. Click "Add User," enter their email and assign a role. The new user will receive an email invitation to create their account.
What user roles are available?
CyberCAAT offers several roles:
  • Administrator: Full access to all features and settings
  • Manager: Can manage assessments and view reports
  • Analyst: Can perform assessments and update control status
  • Viewer: Read-only access to dashboards and reports

Assessments & Compliance

How often should I run a risk assessment?
We recommend running a formal risk assessment at least annually, with quarterly reviews of high-risk areas. You should also perform assessments after significant changes to your environment, such as new systems, major incidents, or organizational changes.
What does the compliance score mean?
The compliance score represents the percentage of controls that are fully or partially implemented across your selected framework. A higher score indicates stronger alignment with the framework requirements. The score considers control effectiveness, implementation status, and evidence documentation.
Can I track remediation activities?
Yes! CyberCAAT includes a remediation tracking feature. For each control gap or finding, you can create remediation tasks, assign owners, set due dates, and track progress. You can also link remediation activities to project schedules.

Security Monitoring

What is breach monitoring?
Breach monitoring uses the Have I Been Pwned (HIBP) service to check if email addresses from your organization's domains have appeared in known data breaches. This helps you identify potentially compromised accounts and take proactive action.
How does Shodan integration work?
Shodan integration scans your organization's public-facing infrastructure to identify exposed services, open ports, and potential vulnerabilities visible from the internet. Results help you understand your external attack surface.
How often are vulnerability scans updated?
Vulnerability data sync frequency depends on your configuration. You can set automatic sync intervals (daily, weekly, etc.) or trigger manual syncs from the Vulnerability Management dashboard. Integration with tools like Rapid7 provides near real-time data.

Reports & Data

How do I export reports?
Most dashboards and report pages include export buttons. Look for the download icon (PDF, Excel, or CSV options) in the top-right area of each section. For executive reports, use the Reports menu to generate comprehensive documentation.
Is my data secure?
Yes. CyberCAAT implements enterprise-grade security including encryption at rest and in transit, role-based access controls, audit logging, and secure authentication. For details, see our Privacy Policy.
Can I integrate with other tools?
CyberCAAT supports integrations with various security and IT management tools including Rapid7 for vulnerability management, Shodan for infrastructure scanning, and HIBP for breach monitoring. Additional integrations are being added regularly.

Billing & Subscription

What subscription plans are available?
CyberCAAT offers flexible subscription plans based on organization size and feature requirements. Contact our sales team for pricing details and to discuss which plan best fits your needs.
How do I update my billing information?
Administrators can update billing information in Settings > Billing. You can change payment methods, update billing contacts, and view invoice history.

Still have questions?

Our support team is ready to help you get the answers you need.

Contact Support