Policy Compliance Library Updates, August 2026 

Vaishali Kulkarni

Qualys’ library of built-in policies makes it easy to comply with the widely adopted security standards and regulations. The platform offers a broad range of policies, including many that have been certified by the Center for Internet Security (CIS), as well as security guidelines and industry best practices from operating system and application vendors.  

Qualys’ Certification Page on the CIS website has also been updated.  

CIS Benchmark Policies

Center for Internet Security (CIS) Benchmark policies are technical guidelines for organizations to improve their cybersecurity posture by aligning with recommended secure configurations. By leveraging industry best practices, these guidelines help reduce the risk of cyberattacks, such as data breaches.

DISA STIG Policies

STIG stands for Security Technical Implementation Guide, which is a set of cybersecurity guidelines published by the Defense Information Systems Agency (DISA). These guidelines equip organizations with the necessary tools to adhere to rules, regulations, best practices, and federal laws, facilitating compliance and bolstering cybersecurity measures.

CIS STIG Policies

CIS STIG Benchmarks are secure configuration guidelines released by the Center for Internet Security (CIS) and derived directly from DISA Security Technical Implementation Guides (STIGs). They are functionally equivalent to DISA STIGs and differ only in formatting and presentation, not in security controls or remediation guidance.

Qualys Policies

Qualys oversees the discovery and resolution of technical issues while implementing robust policy frameworks. Researchers within Qualys actively identify cybersecurity misconfiguration and enact technical policies to fortify systems and safeguard against potential threats.

Safeguard Computer Security Evaluation Matrix (SCSEM)

It typically comprises a structured set of criteria, guidelines, and metrics designed to measure various aspects of security, such as confidentiality, integrity, availability, and compliance.

Compliance Standards

Compliance standards are regulatory frameworks that safeguard sensitive data and help ensure privacy and security. They offer guidelines and best practices for organizations to achieve compliance and mitigate risks in handling sensitive information.

New Policies/Mandates 

Listed below are the number of policies and mandates deployed in August 2026: 

CIS Benchmark Policies 10
DISA STIG Policy 6
CIS STIG Benchmark2
Industry Best Practices Policy 5
New Supported Mandates0
Deprecated Mandates0

Listed below are the newly published policies and mandates:  

CIS Benchmark Policies CIS Benchmark for Microsoft Windows Server 2025, v2.0.0,
Next-generation Windows Security Profile Policy 

CIS Benchmark for Microsoft Windows Server 2025 Stand-alone, v1.0.0, Next-generation Windows Security Profile Policy  

CIS Benchmark for Microsoft Windows Server 2022, v5.0.0,
Next-generation Windows Security Profile Policy 

CIS Benchmark for Microsoft Windows Server 2022 Stand-alone, v2.0.0, Next-generation Windows Security Profile Policy 

CIS Microsoft SQL Server 2025 Benchmark, v1.0.0

Note: Application Version 10.39.3.0 or later is required to generate scan results.

CIS Amazon Linux 2 Benchmark, v4.0.0

CIS Microsoft Intune for Windows 11 Benchmark, v5.0.0

CIS Microsoft Intune for Windows 10 Benchmark, v5.0.0

CIS Microsoft Windows 11 Enterprise Benchmark, v5.1.0

CIS Microsoft Windows Server 2022 Benchmark, v5.1.0
DISA STIG PoliciesDISA Security Technical Implementation Guide (STIG) for Microsoft Windows 11, V2R8

DISA Security Technical Implementation Guide (STIG) for Microsoft Windows Server 2019 DC, V3R8

DISA Security Technical Implementation Guide (STIG) for Microsoft Windows Server 2019 MS, V3R8

DISA Security Technical Implementation Guide (STIG) for Red Hat Enterprise Linux 8, V2R8

DISA Security Technical Implementation Guide (STIG) for Red Hat Enterprise Linux 9, V2R9

DISA Security Technical Implementation Guide (STIG) for Amazon Linux 2023, V1R4
CIS STIG BenchmarkCIS Benchmark for Apache Tomcat Application Server 9 STIG, v1.0.0 

CIS Benchmark for IBM z/OS Security Server RACF STIG, v1.0.0 
Industry and Best Practices Policies Security Configuration and Compliance Policy for OpenSuSE 16

Safeguard Computer Security Evaluation Matrix for Apache Tomcat 9.x

Safeguard Computer Security Evaluation Matrix for Apache Tomcat 10.x

Safeguard Computer Security Evaluation Matrix for MS IIS 10.x

Safeguard Computer Security Evaluation Matrix for Oracle Enterprise Linux 9
New Supported MandatesNA
Deprecated mandatesNA

Policy Updates 

We have updated your Policy Library. The following policies and mandates have been re-released as part of our customer CRM.

Policy Update  
CIS Benchmark for IBM DB2 11.x, v1.2.0Re-release for CIS Benchmark for IBM DB2 11.x, v1.2.0, to add Control 10186 and map it to control reference 8.1.7 (SVCENAME).
CIS Benchmark for IBM DB2 12.1, v1.0.0Re-release for CIS Benchmark for IBM DB2 12.1, v1.0.0, to add Control 10186 and map it to control reference 8.1.7 (SVCENAME).
CIS Benchmark for Bottlerocket Benchmark, v1.0.0Re-release for CIS Benchmark for Bottlerocket Benchmark, v1.0.0, to update the regular expression for the CID 14401 and CID 14402.
CIS Benchmark for Red Hat Enterprise Linux 9, v2.0.0Re-release for CIS Benchmark for Red Hat Enterprise Linux 9, v2.0.0, to enable the NL (No List) value for the CIDs 29162, 29164, and 29165.
Security Configuration and Compliance Policy for Verint Financial ComplianceRe-release for Security Configuration and Compliance Policy for Verint Financial Compliance, to add the NL Value 3 for the CID 26979 (SNMP Version 3).
CIS Benchmark for Alma Linux OS 9, v2.0.0Re-release for CIS Benchmark for Alma Linux OS 9, v2.0.0, to update the cover page of the policy.
CIS Benchmark for Oracle Linux 8, v4.0.0Re-release for CIS Benchmark for Oracle Linux 8, v4.0.0, to update the cover page of the policy.
CIS Benchmark for Oracle Linux 7, v4.0.0Re-release for CIS Benchmark for Oracle Linux 7, v4.0.0, to update the cover page of the policy.
CIS Benchmark for Rocky Linux 8, v3.0.0Re-release for Rocky Linux 8, to update the cover page of the policy.
CIS Benchmark for Microsoft Windows Server 2019, v5.0.0Re-release for CIS Benchmark for Microsoft Windows Server 2019, v5.0.0, to change the control reference numbers for CID 8249, CID 8250, CID 8252, and CID 8253.
CIS Benchmark for IBM z/OS with RACF, v1.0.0Re-release for CIS Benchmark for IBM z/OS with RACF, v1.0.0, to add support for the ‘IBM z/OS RACF 3.x’ technology.
CIS Benchmark for Ubuntu Linux 16.04 LTS, v2.0.0Re-release for CIS Benchmark for Ubuntu Linux 16.04 LTS, v2.0.0, to update the cardinality for the CID 13376.
Oracle Enterprise Linux 10Re-release for Oracle Enterprise Linux 10, to update the cover page of the policy.
Oracle Enterprise Linux 9Re-release for Oracle Enterprise Linux 9, to update the cover page of the policy.
Amazon Linux 2023Re-release for Amazon Linux 2023, to update the cover page of the policy.
Rocky Linux 10Re-release for Rocky Linux 10, to update the cover page of the policy.
AlmaLinux 10Re-release for AlmaLinux 10, to update the cover page of the policy.
SUSE Linux Enterprise Server 12Re-release for SUSE Linux Enterprise Server 12, to update the cover page of the policy.
Ubuntu Linux 24Re-release for Ubuntu Linux 24, to update the cover page of the policy.
Ubuntu Linux 22Re-release for Ubuntu Linux 22, to update the cover page of the policy.
CentOS Linux 7Re-release for CentOS Linux 7, to update the cover page of the policy.
CIS Benchmark for Microsoft SQL Server 2022, v1.3.0Re-release for CIS Benchmark for Microsoft SQL Server 2022, v1.3.0, to replace: CID 18053 with new CID 32539 CID 7389 with CID 32610.
CIS Benchmark for Check Point Firewall, v1.1.0Re-release for CIS Benchmark for Check Point Firewall, v1.1.0, for scratch review.
CIS Benchmark for F5 Networks, v1.0.0Re-release for CIS Benchmark for F5 Networks, v1.0.0,  for scratch review.
CIS Macos 26 v1.0.0 Re-release for CIS Macos 26 v1.0.0, to replace in the policy:

CID 24066 with CID 32522 

CID 22738 with CID 32519 

CID 18111 with CID 32517 

CID 22740 with CID 32521 

CID 22739 with CID 32520 

CID 19924 with CID 32518
Security Configuration and Compliance Policy for Citrix NetscalerRe-release for Security Configuration and Compliance Policy for Citrix Netscaler for scratch review.

Deprecated Policies

  • CIS Benchmark for Amazon Linux 2, v3.0.0
  • CIS Microsoft Intune for Windows 11 Benchmark, v4.0.0
  • CIS Microsoft Intune for Windows 10 Benchmark, v4.0.0
  • CIS Microsoft Windows 11 Enterprise Benchmark, v5.0.0
  • CIS Microsoft Windows Server 2022 Benchmark, v5.0.0
  • DISA Security Technical Implementation Guide (STIG) for Microsoft Windows Server 2019, V3R7
  • DISA Security Technical Implementation Guide (STIG) for Microsoft Windows 11, V2R7
  • DISA Security Technical Implementation Guide (STIG) for Red Hat Enterprise Linux 8, V2R6
  • DISA Security Technical Implementation Guide (STIG) for Amazon Linux 2023, V1R2 
  • DISA Security Technical Implementation Guide (STIG) for Red Hat Enterprise Linux 9, V2R7

Proposed Upcoming Policies

  We plan to release the following policies and updates next month:

  • CIS IBM AIX 7 Benchmark v1.2.0
  • CIS Apple macOS 14.0 Sonoma Benchmark, v3.1.0
  • CIS Apple macOS 26 Tahoe Benchmark, v1.1.0
  • CIS Apple macOS 15.0 Sequoia Benchmark, v2.1.0
  • DISA STIG for Red Hat Enterprise Linux 7 – Ver 3, Rel 15
  • DISA STIG for Solaris 11 SPARC – Ver 3, Rel 5
  • CIS Google Chrome Group Policy Benchmark, v1.0.0
  • CIS Microsoft Windows Server 2025 Benchmark, v2.1.0
  • CIS PostgreSQL 17 Benchmark, v1.1.0
  • CIS Google Chrome Group Policy Benchmark, v1.1.0
  • Safeguard Computer Security Evaluation Checkpoint Firewall
  • Safeguard Computer Security Evaluation Docker
  • Safeguard Computer Security Evaluation Kubernetes
  • Safeguard Computer Security Evaluation Red Hat OpenShift
  • Safeguard Computer Security Evaluation MySQL 5.7
  • Safeguard Computer Security Evaluation MySQL 8.0
  • Security Configuration and Compliance Policy for Opengear 25.x

Learn More 

Discover how Qualys Enterprise TruRiskTM Platform can help you reduce cyber risk and improve business outcomes through precise remediation activities. Learn more about it here

Additional Information 

Feel free to contact your Technical Account Manager (TAM) or Qualys Technical Support if you have any questions. 

What’s More:

  • Find all policy library updates here
  • Check out Qualys’ updated Certification Page at CIS here.

Share your Comments

Comments

Your email address will not be published. Required fields are marked *