Policy Audit Release 1.17

October 6, 2026

This release introduces improved control statements for System Defined Controls (SDCs) and email notifications when a compliance scan fails. It also adds import and export support for Network UDCs, auto discovery for IBM DB2 and PostgreSQL authentication records, recurring timeframe options in policy report templates, and new QQL tokens to search policies. Policy Audit now supports Nutanix CVM, PostgreSQL 18.x, Oracle Database 26ai, Cisco NX-OS 8.x, 9.x, and 10.x, and VMware NSX Manager and NSX Edge 4.x, along with new Unix technologies for UDCs and several customer-reported fixes.

NEW FEATURE

Improved Control Statements for SDCs

What's New for You

You can now use clearer, more accurate control statements for system defined controls.

You can now use clearer, more accurate control statements for System Defined Controls (SDCs). Each new statement names the setting, service, or parameter that the control checks.

Previously, the Control Statements were not specific enough, making it harder to tell at a glance what each control evaluates. However, when enabled, you can see exactly what each control checks without opening its details.

Improved Control Statements Existing Control Statements
scan failure notification tab in setup tab.
scan failure notification tab in setup tab.

To enable the new control statements, navigate to Policies > Setup > Control Improvements. The Control Improvements Setup window is displayed.
Select Enable improved Control Statement. A confirmation message is displayed. Select Save.

The new control statements are displayed in the Controls tab for SDCs.

scan failure notification tab in setup tab.

You can also enable the new control statements from the Policies, Controls, and Posture tab. In the new banner, select Turn on now. The V2 Control Setup window is displayed.

Select the Enable V2 Control Statement checkbox. Select Save.
The new control statements are displayed in the Controls tab for SDCs.

scan failure notification tab in setup tab.


- Only Manager users can enable or disable control statements. 
- By default, the improved control statements are disabled. You can enable them from the Setup tab or using the banner in the Controls tab.

NEW FEATURE

Get Notified the Moment a Scan Fails

What's New for You

You can now receive email notifications when a Compliance scan enters the error state, helping you identify scan failures without manually checking scan status.

You can now configure Scan Failure Notifications for scans.

Previously, notifications were available for scan completion and certain pre-launch conditions, but no notification was sent when a scan failed after launch.

When the scan notification is enabled, an email is sent to the scan owner and the following relevant users when a scan enters an error state:

  • Managers, Auditors, and users with compliance access who are assigned to the asset groups in the scan
  • Any additional recipients from distribution groups you add on the Scan Failure Notification setup page (up to 50 distribution groups)
scan failure notification tab in setup tab.

The notification includes the following relevant scan details to help you identify and address scan failures more quickly:

  • Scan title and scan reference
  • Scan date and launch type (Scheduled or On demand)
  • Targets in the scan
  • Scan status
  • Failure time and failure reason

To enable the email notification, navigate to Scans > Setup > Scan Failure Notification. You can enable or disable scan failure email notification and configure additional recipients using Distribution Groups.

  • Only Manager users can enable or configure this setting.
  • Scan Failure Notification is disabled by default.
  • At least one Distribution Group must already exist in your subscription if you want to add additional recipients.
  • Configure this setting once at the subscription level to cover all your scan schedules.

New Feature

UDC Support for New Technologies

What's New for You

You can now select CentOS Stream 10.x, FreeBSD 14.x, FreeBSD 15.x, openSUSE 16.x and Rocky Linux 10.x technologies when creating a new control for Unix control types.

The new technologies CentOS Stream 10.x, FreeBSD 14.x, FreeBSD 15.x, openSUSE 16.x and Rocky Linux 10.x are supported for scanner based compliance scans. To select these technologies, navigate to:

  1. Policies > Controls > New > Control > UDC.
    The New Control window is displayed.
  2. In the left pane, select Unix Control Types > From the displayed control types, select a control type of your choice.
  3. In the left pane, select Control Technologies > Under Technologies, you can see the technologies - CentOS Stream 10.x, FreeBSD 14.x, FreeBSD 15.x, openSUSE 16.x and Rocky Linux 10.x.
New UDC supported technologies

Enhancement

Import and Export Support for Network UDCs

What Changed For You

You can now import and export Network User Defined Controls (UDCs) and Policies containing Network UDCs.

You can now import and export Network UDCs as XML, the same way as other UDCs, such as Windows, Unix, and Database controls.

Previously, you could not import or export Network UDCs. Import and export worked only for other UDC types.

New UDC supported technologies

To export a Network UDC, navigate to Policies > Controls > Select a Network UDC > Quick Actions > Export.

To import a Network UDC, navigate to Policies > Controls > New > Import an XML file. The Import Controls window is displayed. Select the required UDC file and select Import.

To export or import a policy with Network UDCs, navigate to Policies > Policies. To export, select the policy and choose Quick Actions > Export.

To import, choose New > Policy > Import from XML.

Enhancement

Auto Discovery Support for IBM DB2 and PostgreSQL Database Authentication

What Changed For You

You can now use instance discovery and auto-record creation for IBM DB2 and PostgreSQL authentication.

You can now automatically generate an authentication record for IBM DB2 and PostgreSQL by scanning your IP address to discover all required information.

Previously, creating authentication records for IBM DB2 and PostgreSQL required manual effort. With this enhancement, you can reduce the time and effort required to create authentication records.

To create a system record template for these technologies navigate to, Scans > Authentication > New > System Record Template.

Select either IBM DB2 or PostgreSQL.

New UDC supported technologies

Enhancement

New Timeframe Options in Compliance Policy Report Templates

What Changed For You

You can now have two recurring timeframe options: the date of every month and the day of every week for policy report templates.

Compliance policy report templates now support two recurring timeframe options: Date of every month and Day of every week.

Previously, you had to manually update the Limit Timeframe date at the beginning of each month or week to ensure reports included data only from the current reporting period.      

With the new recurring timeframe options, the template automatically determines the appropriate date range each time the report is generated. This keeps reports up to date without requiring manual changes.

New UDC supported technologies

To set recurring timeframe options for policy report templates, navigate to, Reports > Templates > New > Policy Template > Layout > Timeframe Selection.

You can also set the recurring timeframe options for existing report templates.  

Token

Support for New QQL Tokens to Search Policies

What Changed For You

You can now search for policies using Qualys Query Language (QQL) tokens based on the user who modified them, the modified date, and their related asset groups. 

We support the following three new QQL tokens:

  • asset.groups
  • policy.modifiedBy
  • policy.modifiedDate

We have introduced several new QQL tokens that help you search and filter policies more efficiently. These tokens allow you to locate policies based on attributes such as the policy creator, .

Token Description
asset.groups Search policies based on the asset group associated to the specific policy.

Example:

asset.groups:`Windows server 2012`

The asset groups with the 'Windows server 2012' is displayed in the result.

asset.groups:[`10.11.70.44 STIG AG - AR`,`WIN_AG`]

The asset groups with '10.11.70.44 STIG AG - AR','WIN_AG' is displayed in the result.

policy.modifiedBy Search for policies modified by specific users.

Examples:

policy.modifiedBy:"John Doe"

Policies modified by John Doe are displayed.

policy.modifiedDate Use this token to search for policies modified at the particular date.

Example:

policy.modifiedDate:[2026-07-01 .. 2026-07-14]

Policies modified in the date range are displayed.

New Feature

Support for New Technologies

What's New for You

We have now added support for the new technologies Nutanix CVM, PostgreSQL 18.x, Oracle Database 26ai, Cisco NX - OS 8.x, Cisco NX - OS 9.x, Cisco NX - OS 10.x, VMware NSX Manager 4.x, and VMware NSX Edge 4.x.

Nutanix CVM

Nutanix CVM technology is now supported for Policy Audit authenticated scans using agent and scanners. This technology is now available for use at the following places:

Policy Editor - When you create or edit a policy, Nutanix CVM is now available in the list of supported technologies.

Search Controls - When you search for controls, you see Nutanix CVM  in the list of technologies. Go to Policies > Controls > Search and under Technologies, select Nutanix CVM in the list.

New UDC supported technologies

Authentication Report

You can view the Nutanix CVM in the authentication report. In the Results section of the report, the Nutanix CVM details are displayed.

Sample Report

The sample report displays the tracking method and the instances for the scanner.

In Compliance Reports, you can view the instances of Nutanix CVM for scanned hosts. The sample report displays the scanner's tracking method as IP with an instance of Nutanix CVM.

New UDC supported technologies

PostgreSQL 18.x

PostgreSQL 18.x technology is now supported for Policy Audit authenticated scans using agent and scanners. This technology is now available for use at the following places:

Policy Editor - When you create or edit a policy, PostgreSQL 18.x is now available in the list of supported technologies.

Search Controls - When you search for controls, you see PostgreSQL 18.x in the list of technologies. Go to Policies > Controls > Search and under Technologies, select PostgreSQL 18.x in the list.

New UDC supported technologies

Authentication Report

You can view the PostgreSQL 18.x in the authentication report. In the Results section of the report, the PostgreSQL 18.x details are displayed.

New UDC supported technologies

Sample Report

The sample report displays the tracking method and the instances for the scanner and the agent:

  • Scanner - In Compliance Reports, you can view the instances of PostgreSQL 18.x for scanned hosts. The sample report displays the scanner's tracking method as IP with an instance of PostgreSQL 18.x.
  • Agent - In Compliance Reports, you can view the instances of PostgreSQL 18.x for scanned hosts. The sample report displays the tracking method for the agent as AGENT with an instance of PostgreSQL 18.x.
New UDC supported technologies

Oracle Database 26ai

Oracle Database 26ai technology is now supported for Policy Audit authenticated scans using agent and scanners. This technology is now available for use at the following places:

Policy Editor - When you create or edit a policy, Oracle Database 26ai is now available in the list of supported technologies.

Search Controls - When you search for controls, you see Oracle Database 26ai in the list of technologies. Go to Policies > Controls > Search and under Technologies, select Oracle Database 26ai in the list.

New UDC supported technologies

Authentication Report

You can view the Oracle Database 26ai in the authentication report. In the Results section of the report, the Oracle Database 26ai details are displayed.

New UDC supported technologies

Sample Report

The sample report displays the tracking method and the instances for the scanner and the agent:

  • Scanner - In Compliance Reports, you can view the instances of Oracle Database 26ai for scanned hosts. The sample report displays the scanner's tracking method as IP with an instance of Oracle Database 26ai.
  • Agent - In Compliance Reports, you can view the instances of Oracle Database 26ai for scanned hosts. The sample report displays the tracking method for the agent as AGENT with an instance of Oracle Database 26ai.
New UDC supported technologies

Cisco NX-OS 8.x, 9.x, and 10.x

Cisco NX-OS 8.x, 9.x, and 10.x technologies are now supported for Policy Audit using Out-of-Band Configuration Assessment (OCA). This technology is now available for use at the following places:

Policy Editor - When you create or edit a policy, Cisco NX-OS 8.x, 9.x, and 10.x are now available in the list of supported technologies.

Search Controls - When you search for controls, you see Cisco NX-OS 8.x, 9.x, and 10.x in the list of technologies. Go to Policies > Controls > Search and under Technologies, select Cisco NX-OS 8.x, 9.x, and 10.x from the list.

New UDC supported technologies

Policy Report

You can view the Cisco NX-OS 8.x, 9.x, and 10.x in the policy report. In the Detailed Results section of the report, the Cisco NX-OS 8.x, 9.x, and 10.x details are displayed.

New UDC supported technologies

VMware NSX Manager 4.x and VMware NSX Edge 4.x

VMware NSX Manager 4.x and VMware NSX Edge 4.x technologies are now supported for Policy Audit using Out-of-Band Configuration Assessment (OCA). This technology is now available for use at the following places:

Policy Editor - When you create or edit a policy, VMware NSX Manager 4.x and VMware NSX Edge 4.x are now available in the list of supported technologies.

Search Controls - When you search for controls, you see VMware NSX Manager 4.x and VMware NSX Edge 4.x in the list of technologies. Go to Policies > Controls > Search and under Technologies, select VMware NSX Manager 4.x and VMware NSX Edge 4.x in the list.

New UDC supported technologies

Policy Report

You can view VMware NSX Manager 4.x and VMware NSX Edge 4.x in the policy report. In the Detailed Results section of the report, the VMware NSX Manager 4.x and VMware NSX Edge 4.x details are displayed.

New UDC supported technologies

Fix

Issues Addressed

The following reported and notable customer issues are fixed in this release:

Component/Category Description
PA - Network UDC When users selected Info from the Quick Action menu for a Network User Defined control, the Technologies Included tab on the Technical Control Information page did not show the scan parameter values.
This is now resolved. The tab now shows the scan parameter values for the Network User Defined Control.
PA - Scan Schedule When users scheduled scans with a duration limit, the scans paused but did not resume automatically. The scans remained in the Paused status.
This issue is now resolved. The scans now resume automatically at the configured time.
SCA When users launched Compliance or SCA scans on Cloud Agent assets in subscriptions with native IPv6 enabled, the Cloud Agent scan completed successfully. However, the last scan date was not updated for some assets.
This is now resolved. Scan results have now been processed successfully for these assets, and the scan dates have been updated as expected.
PA - New UI When users searched for posture data in the Posture tab, a discrepancy was observed between the asset count on the posture listing page and the count in the exported CSV file.
This is now resolved. The count now matches the exported data.