Skip to content

The 41 Cloudflare security checks Black Cat runs

Black Cat SSPM evaluates 41 security policies against your Cloudflare configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect Cloudflare — what access Black Cat needs, and why.

Access control & privilege (9)

Encryption, keys & secrets (9)

Network security (3)

Configuration hardening (5)

AI governance (12)

Other checks (3)

severity: high MFA Not Enabled fix difficulty: easy #

Require Cloudflare account members to enable two-factor authentication

  1. Instruct the account member to log in to their Cloudflare profile
  2. Navigate to My Profile > Authentication
  3. Enable two-factor authentication using TOTP or security key
  4. Verify MFA is active for the account

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: critical Two-Factor Enforcement Disabled fix difficulty: easy #

Enable two-factor authentication enforcement for all Cloudflare account members

  1. Log in to the Cloudflare Dashboard
  2. Navigate to the Members page
  3. Enable 2FA enforcement for the account
  4. Notify members so they can enroll an authenticator app or security key before the policy takes effect

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.5 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: high Cloudflare AI Gateway Agent Orphaned Owner fix difficulty: easy #

Reassign the AI Gateway agent to an active owner

  1. Identify the agent owner in the Cloudflare dashboard
  2. Transfer ownership to an active team member

Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial