Auto-Checks: Cloudflare

Last updated: September 9, 2026

Auto-Checks is a feature that verifies technical configurations in your cloud environment against ISO 27001 requirements. These checks are run automatically and linked to your implementation steps within Kertos.

Auto-Checks for Cloudflare verify the security settings of your Cloudflare zones: TLS and certificate configuration, HSTS, WAF and rate limiting, DNSSEC, and DNS records. Instead of exporting screenshots from the Cloudflare dashboard for every audit cycle, you connect Cloudflare once and Kertos collects the evidence for the controls that require it.

The checks cover the Cloudflare zone, dns and firewall settings and are mapped to controls in ISO 27001:2022, NIS2 and SOC 2.

How It Works

How to activate Auto-Checks for Cloudflare in Kertos?

  1. Go to Integrations in the navigation bar and then to Discovery.

  2. Locate the Cloudflare card and click Setup.

  3. Click Sign in with Cloudflare.

  4. Log in to Cloudflare and confirm the access request. Kertos asks for read-only access to your account, zones, zone settings and DNS records.

  5. Back in Kertos, click Save.

  6. Click Sync on the Cloudflare card to run the checks for the first time.

You do not need to create an API token or select permission scopes yourself. The login flow requests the required read-only permissions.

Once the run is finished, the Cloudflare Auto-Checks are linked automatically to the corresponding controls and implementation steps in your frameworks. You can find them in the tab Controls and in the tab Auto-Checks.

What Are the Cloudflare Auto-Checks Based On?

In close collaboration with auditors, we curated the checks that matter most for security and compliance and mapped each of them to controls in ISO 27001:2022, NIS2 and SOC 2. Every check comes with a description of the finding and remediation guidance you can follow in the Auto Check Overview Page.

Which Auto-Checks are available for Cloudflare, and how are they mapped to ISO 27001:2022 controls?

Each Auto-Check is mapped to at least one control, which helps to demonstrate the technical implementation of key security requirements.
You can find the Auto-Checks in the respective Controls Page under the Section Evidence.

Auto-Check Title

What it verifies

Cloudflare service

Severity

ISO 27001:2022

SSL/TLS encryption mode is set to Full (Strict)

Cloudflare connects to your origin server with end-to-end encryption and certificate validation, which prevents man-in-the-middle attacks between Cloudflare and the origin.

zone

high

A.8.24

Minimum TLS version is set to 1.2 or higher

TLS 1.0 and 1.1 are disabled. Both are deprecated and vulnerable to BEAST and POODLE.

zone

high

A.8.24

TLS 1.3 is enabled

TLS 1.3 is active, which improves performance and security over older TLS versions.

zone

medium

A.8.24

HTTPS redirect is enabled

All HTTP traffic is redirected to HTTPS, so no data is transmitted unencrypted.

zone

high

A.8.21, A.8.24

HSTS is enabled with recommended max-age and includes subdomains

HTTP Strict Transport Security is configured with a max-age of at least six months and covers subdomains, which prevents SSL stripping.

zone

high

A.8.21, A.8.24

WAF is enabled

The Web Application Firewall is active on your zones.

zone

high

A.8.20, A.8.21

OWASP managed WAF rulesets are enabled

The OWASP Core Ruleset is active in the Cloudflare WAF and blocks SQL injection, XSS and other OWASP Top 10 attack vectors.

zone

high

A.8.25, A.8.26

Rate limiting is configured for the zone

Rate limiting rules exist to protect against DDoS, brute force and API abuse.

zone

high

A.8.21

DNSSEC is enabled

DNS responses are cryptographically signed, which protects against DNS spoofing and cache poisoning.

zone

high

A.8.20

DNS records do not use wildcard entries

A, AAAA, CNAME, MX and SRV records avoid wildcards such as *.example.com, which can expose unintended services and allow mail interception.

dns

medium

A.8.20

Several of these checks also serve as evidence for other frameworks. The TLS and SSL checks map to GDPR Art. 32 and PCI-DSS requirements, the WAF and rate limiting checks to OWASP and PCI-DSS.

How do I fix a failed check?

  1. Open the failed check in Kertos and read the description and the remediation guidance.

  2. Change the setting in the Cloudflare dashboard. All checks refer to settings under SSL/TLS, Security or DNS of the respective zone.

  3. Click Sync on the Cloudflare card, or wait for the next scheduled run.

  4. The check moves to Passed and its implementation step is ticked off.

Which Cloudflare products are covered?

The current version covers the zone, DNS and firewall settings listed above. Cloudflare Access, R2 and Workers are not part of it yet.

FAQs

How often do the Cloudflare Auto-Checks run?

They run during every discovery run. You can trigger a run at any time with the Sync button on the Cloudflare card.

Which permissions does Kertos get in my Cloudflare account?

Read-only access to account settings, zones, zone settings and DNS records. Kertos does not change any setting in Cloudflare.

Are all zones scanned?

Yes. The checks run against every zone that the connected account has access to.

Why is a check marked as "Unable to verify"?

Auto-Checks only run for services that are in use and readable in the connected environment. If a zone could not be reached or a setting is not available in your Cloudflare plan, the check is not evaluated and is shown as "Unable to verify" instead of failed.

Does a failing check change the status of my control?

A passing check marks its implementation step as complete, and the control moves to Implemented once all steps are complete. If a passing check later fails, the implementation step is unchecked, and the control stays in Implemented.

How do I disconnect Cloudflare?

Go to the Cloudflare integration in Kertos and remove the integration. You can additionally revoke the access in your Cloudflare account under My Profile and then Authorized Apps.