Skip to main content
Cloud / STACKIT / Products / STACKIT CSPM - Cloud Security Posture Management

STACKIT CSPM - Cloud Security Posture Management

STACKIT CSPM: managed service for assessing your cloud security posture with a compliance dashboard, BSI C5 Basic benchmark, and mitigation guidance.

Security
Pricing Model Pricing as published in the STACKIT pricing calculator
Availability Availability as documented by STACKIT
Data Sovereignty Operated as a managed service within the STACKIT Portal
Reliability SLA as published by the provider SLA

What is STACKIT CSPM?

Cloud Security Posture Management (CSPM) helps organizations monitor, assess, and improve the security posture of their cloud environments. The service identifies risks, misconfigurations, and compliance violations across cloud infrastructure and services, and provides guidance on how to address them.

STACKIT CSPM is a native, integrated solution: it operates entirely as a fully managed service within the STACKIT Portal, no software is deployed locally, and updates are applied automatically.

Core Features

  • Compliance dashboard: Overall compliance status with percentage, policy breakdown, and 30-day trend
  • Top violations: The five most frequently violated policies including occurrence counts
  • Asset context: Affected STACKIT resources such as load balancers or storage, with name, severity, and last detection timestamp
  • Benchmark filtering: Evaluation against benchmarks such as BSI C5 Basic and an internal STACKIT standard
  • Mitigation guidance: Detailed policy description with remediation instructions
  • CSV export: Point-in-time snapshot of the compliance report
  • API access: API reference available in version v1beta

Typical Use Cases

Continuous monitoring: Misconfigurations are detected automatically instead of surfacing only during an audit.

Compliance evidence: Filtering by benchmarks such as BSI C5 Basic provides a structured basis for audits and internal reporting.

Prioritization in the security team: Severity levels and the list of most frequent policy violations help focus limited capacity on the relevant risks.

Recurring reporting: The CSV export produces a snapshot that fits into existing reporting processes.

Benefits

  • Natively integrated: Directly in the STACKIT Portal, without separate agents or appliances
  • No maintenance effort: The service updates itself automatically
  • Actionable findings: Concrete assets, severity levels, and timestamps instead of generic hints
  • Guided remediation: Every policy comes with instructions on how to fix it
  • Audit-ready: Benchmark context and CSV export for audits

Integration with innFactory

As an official STACKIT partner, innFactory supports you with CSPM: assessing and prioritizing findings, remediating misconfigurations, setting up compliance reporting, and connecting it to your existing security processes.

Typical Use Cases

Continuous assessment of the cloud security posture
Detecting misconfigurations in STACKIT resources
Compliance evidence against the BSI C5 Basic benchmark
Prioritizing security risks by severity
Recurring reporting for security and audit teams

Technical Specifications

API API reference available as v1beta at docs.api.stackit.cloud
Benchmarks Benchmark filtering, including BSI C5 Basic and an internal STACKIT standard
Dashboard Overall compliance status with compliance percentage, policy breakdown, and 30-day trend
Delivery Fully managed service within the STACKIT Portal, no software deployed locally
Findings Affected STACKIT assets with names, severity levels, and last detection timestamps
Remediation Mitigation guidance with detailed policy description and remediation instructions
Reporting CSV export of the compliance report as a point-in-time snapshot
Updates Automatic updates without version management overhead for the customer

Frequently Asked Questions

What is STACKIT CSPM?

Cloud Security Posture Management helps organizations monitor, assess, and improve the security posture of their cloud environments. The service identifies risks, misconfigurations, and compliance violations across cloud infrastructure and services.

Do I have to install software?

No. CSPM operates entirely as a fully managed service within the STACKIT Portal. No software is deployed locally, and updates are applied automatically without version management overhead.

Which compliance standards are supported?

Results can be filtered by benchmark. Documented benchmarks include BSI C5 Basic and an internal STACKIT standard.

How are findings presented?

The dashboard shows the overall compliance status with a percentage, a policy breakdown, and a 30-day trend, plus the top five violated policies including occurrence counts. For each policy, the affected assets are listed with severity level and last detection timestamp.

How do I know how to fix a finding?

Selecting a policy opens mitigation guidance containing a detailed policy description and instructions for remediation. For reporting, the compliance report can be exported as CSV.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.

STACKIT Partner

innFactory is an official STACKIT Partner. We provide consulting, implementation, and managed services for the sovereign cloud.

STACKIT Official Partner

Ready to start with STACKIT CSPM - Cloud Security Posture Management?

Our certified STACKIT experts help you with architecture, integration, and optimization.

Schedule Consultation