Release 3.39.0

Extended External Scans and Compliance Validation Dates

External scans and compliance reviews both need to happen more than once, and knowing when each was last done matters as much as running them in the first place. This release adds a broader external scan option, deeper mapping between findings and tasks, and validation dates that make it easier to track when each control was last reviewed.

Risk Management Integrations Compliance

What’s in This Release

  • Two external scan options, with the broader one adding subdomains and 27 checks
  • Deeper task mapping for findings from vulnerability and cloud posture integrations
  • Validation Date and Next Validation Date on every compliance control
  • Bulk scheduling, a past-due filter, and validation dates in exports and reports

Two External Scan Options

Depth and speed pull against each other in external scanning, and which one matters more depends on the engagement in front of you. Cynomi now offers two external scanning options, so you pick the level of coverage each client warrants. Both feed the same remediation flow:

  • External Security Scan – a faster scan covering common external security risks across selected domains, URLs, and IP addresses
  • Extended External Scan – a broader scan that adds subdomain coverage and 27 additional checks across web-facing assets, including HTTP security headers, exposed files and endpoints, publicly accessible cloud storage, information disclosure, and domain-level protections such as DNSSEC

Every finding from either scan is linked to a relevant remediation task, so an exposure arrives as work rather than as a line in a report. One thing to plan around: because it performs broader discovery and additional checks, the Extended External Scan may take longer to complete.

Deeper Task Mapping for VM and CSPM Integrations

Findings are more actionable when they are connected directly to the work that resolves them, and that mapping is now considerably deeper. Findings from vulnerability management and cloud security posture management integrations, including Qualys, Tenable, SentinelOne, CrowdStrike, Microsoft Secure Score, AWS Security Hub, and Cavelo, are mapped to Cynomi tasks at far greater depth than before. Every finding therefore arrives with somewhere to go.

You can see the mapping in the Scanner results and on each linked task. It also gives the Findings Coworker more signals to reason over, so the reconciliation it proposes between scan state and task state rests on a better picture of what a given finding actually relates to. That mapping is what keeps risk management tied to what the scanners can actually see.

Findings arrive attached to the tasks that resolve them, which is where a technician can act on them.

Validation Dates on Every Control

Cynomi now records when each control was validated and when it is due for review again. Each control carries a Validation Date, set automatically whenever its Validation Status is updated, and a Next Validation Date, which you set manually to schedule the next review. A Next Validation Date that has passed is highlighted in red.

Three things build on that:

  • Bulk-Update the Next Validation Date – set the Next Validation Date across multiple controls at once, applying a review schedule to an entire framework in a single action
  • Filter by Past-Due Validation – a filter surfaces every control whose Next Validation Date has passed, so revalidation happens before it becomes an audit gap
  • Validation Dates in Reporting – both dates are included in CSV downloads and in the CMMC SPRS report, printed from the Validated Score tab

Controls that do not apply to a client’s environment can also now be marked N/A, which keeps Validated Score accurate across the control view, the Compliance dashboard, and the Compliance report rather than counting a non-applicable control against the client.

Why this matters

A date on each control, a bulk action to apply a schedule across a whole framework, and a filter for what has lapsed make revalidation a recurring task with its own dates. This gives each compliance score a clearer validation timeline.

Also in This Release

  • Control evidence text is now included in the Task CSV export, so evidence travels with your task data wherever you export or present it in dashboards and reporting
  • Users with the Viewer role can open compliance evidence files, giving read-only stakeholders full visibility into how each control is met
  • Client users now have view permissions for shared vendors, improving third-party risk management visibility directly from the Client view

What This Adds Up To

Together, these changes shorten the path from identifying an exposure to assigning remediation work, while keeping validation records current. A broader scan finds more, deeper mapping attaches what it finds to real work, and validation dates make sure the sign-off behind a compliance score has an age you can see. For a partner carrying dozens of clients through recurring audit cycles, currency is the hard part, and most of this release is about it.

Frequently Asked Questions

What is the difference between the External Security Scan and the Extended External Scan?

The External Security Scan is faster and covers common external security risks across selected domains, URLs, and IP addresses. The Extended External Scan adds subdomain coverage and 27 additional checks across web-facing assets.

Does the Extended External Scan take longer to run?

Yes. Because it performs broader discovery and additional checks, the Extended External Scan may take longer to complete than the External Security Scan.

Which integrations now map findings to tasks at greater depth?

Vulnerability management and cloud security posture management integrations, including Qualys, Tenable, SentinelOne, CrowdStrike, Microsoft Secure Score, AWS Security Hub, and Cavelo. The mapping is visible in the Scanner results and on each linked task.

How do I schedule the next review of a control?

Set a Next Validation Date on the control. It is set manually, and it is highlighted in red once the date has passed. The Validation Date is set automatically whenever a control's Validation Status is updated.

Can I apply a review schedule to a whole framework at once?

Yes. Bulk-Update the Next Validation Date sets it across multiple controls in one action, which applies a review schedule to an entire framework and keeps validation cycles consistent across clients.

Which Cynomi release do these changes ship in?

Release 3.39.0, July 2026. It covers external scanning, vulnerability and cloud posture integrations, compliance validation tracking, and reporting.

The Security Growth Platform
for Service Providers

Discover how Cynomi can help you standardize delivery, accelerate onboarding, and scale your CISO advisory services.