Does CISGuard deploy on air-gapped networks?
Yes. Air-gapped deployment is a first-class supported configuration, not a workaround. Benchmark definition updates are RSA-signed by the server and verified by every agent before use; software updates ship as offline media with published SHA-256 checksums. Agent-based scanning needs no outbound connectivity; only cloud-account scanning (Azure, AWS, Microsoft 365) reaches the provider APIs. Built for classified and isolated environments where outbound connectivity is prohibited.
The longer answer.
An air-gapped network is one with no physical or logical path to the public internet, used where the consequences of exfiltration or remote compromise are unacceptable: classified government systems, critical infrastructure control networks, and defense enclaves. Any tool intended for these environments has to assume it will never reach a vendor cloud for licensing, updates, or telemetry, because that connectivity simply does not exist by design.
Supporting air-gapped operation as a first-class mode, rather than a stripped-down fallback, means the update path is built around signed offline media and the running system expects zero outbound calls. That lets a scanner keep its benchmark content current through a controlled import process while satisfying the strict connectivity rules of high-assurance impact levels, instead of forcing operators to choose between staying current and staying isolated.
More questions on Deployment?
Our compliance engineers can show you exactly how CISGuard handles Deployment in a briefing scoped to your environment.