Skip to main content

Exporting Reports

Export audit results to PDF, HTML, CSV, or DISA STIG CKL format.

Generate professional reports for auditors, documentation, and compliance tracking.

Export Formats

MACE can export audit results in four formats:

📄

PDF

Professional report format. Ideal for sharing with auditors, management, or for official documentation. Includes charts and formatted tables.

🌐

HTML

Interactive web report. Can be opened in any browser. Includes responsive design and expandable details. Great for internal review.

📊

CSV

Spreadsheet format. Import into Excel, Google Sheets, or other tools. Useful for data analysis, filtering, and custom reporting.

🛡️

STIG CKL

DISA STIG Checklist format (XML). Required for DoD compliance. Updates existing CKL templates with your audit results.

Which Format Should I Use?

📄PDFShare with auditors or management
🌐HTMLReview results in a browser
📊CSVAnalyze data in Excel or Google Sheets
🛡️STIG CKLSubmit for DoD compliance

Export Options

Before exporting, you can configure what to include in your report:

Author and Metadata

👤Include Author Data (Default: ON)

Adds your name, organization, and benchmark name to the report header. Helps identify who performed the audit.

🏢Author Name & Organization

Your name and organization appear in the report header. Set these in the export options.

Device Information

💻Include Device Info (Default: OFF)

Adds the audited Mac's serial number, model name, and macOS version to the report. Identifies which specific device was checked.

🖥️Include Hostname (Default: OFF)

Adds the computer's hostname to the device information section.

Logo and Branding

🖼️Include Logo (Default: ON)

Adds a logo to the report header. MACE looks for a file named logo.png in your project folder. If not found, uses the default MACE logo.

🏷️Hide M.A.C.E. Branding (Default: OFF)

Removes "Generated by M.A.C.E." attribution from the report. Use this for sanitized or white-labeled reports.

🦶Hide Footer (Default: OFF)

Removes the entire footer section from the report, including generation timestamp and any branding.

Content Options

📋Hide Outputs (Default: OFF)

Hides the Expected Output and Actual Output columns. Simplifies the report if these details aren't needed.

📝Hide Discussions (Default: OFF)

Hides the Discussion/Notes column. Reduces report length if rule explanations aren't needed.

⏱️Hide Execution Time (Default: OFF)

Hides the time taken for each check. Simplifies the output if timing isn't relevant.

📜Include Check Script (Default: OFF)

Shows the command that was run for each rule. Useful for technical reviewers who want to see exactly what was tested.

🔧Include Fix Script (Default: OFF)

Shows the remediation command for each rule. Helps teams understand how to fix failing items.

Analysis Options

📊Include Section Summary (Default: OFF)

Adds a breakdown of pass/fail rates by section. Highlights problem areas with lowest pass rates first.

✏️Include Override Indicators (Default: OFF)

Adds a column showing which results were manually modified. Important for audit trails where changes must be documented.

📋Include Executive Summary (Default: OFF, PDF only)

Adds a high-level overview at the beginning of the report. Summarizes key findings and critical areas for management review.

✍️Include Signature Section (Default: OFF)

Adds signature lines at the end of the report for auditor sign-off. Includes fields for Signature, Date, Printed Name, and Title/Role.

Format-Specific Options

🖨️Paginate for Printing (Default: OFF, PDF only)

Formats the PDF for US Letter paper with page breaks. When off, creates a continuous single-page document (better for digital viewing).

🔢Show STIG ID (STIG compliance only)

Displays STIG IDs (like APPL-15-005001) instead of Rule IDs in the table. Standard for STIG documentation.

📑Include CIS ID (CIS compliance only)

Adds a column showing CIS Benchmark reference numbers (like 2.6.6).

PDF Export

The PDF export creates a professional compliance report suitable for auditors and official documentation.

What's Included

  • Header: Logo, report title, author, organization, date
  • Summary Statistics: Total rules, pass/fail counts, pass rate percentage
  • Pie Chart: Visual breakdown of results by status
  • Device Information (optional): Serial number, model, OS version
  • Executive Summary (optional): High-level findings overview
  • Section Summary (optional): Pass rates by category
  • Results Table: All rules with status, expected/actual values, comments
  • Signature Section (optional): Sign-off lines for auditors
  • Footer: Generation timestamp, page numbers (if paginated)

How to Export PDF

  1. Complete your audit
  2. Click Export in the results toolbar
  3. Select PDF
  4. Configure export options
  5. Choose save location
  6. Click Export

HTML Export

The HTML export creates an interactive web report that can be opened in any browser.

Features

  • Responsive Design: Works on desktop, tablet, and mobile
  • Dark Mode Support: Automatically adapts to system preferences
  • Expandable Details: Click rows to see more information
  • Status Color Coding: Visual pass/fail indicators
  • Section Navigation: Jump to specific sections
  • Pie Chart: SVG visualization of results

How to Export HTML

  1. Complete your audit
  2. Click Export in the results toolbar
  3. Select HTML
  4. Configure export options
  5. Choose save location
  6. Click Export

Viewing the Report

Open the exported .html file in any web browser (Safari, Chrome, Firefox, etc.). The report is self-contained with all styles embedded.

CSV Export

The CSV export creates a spreadsheet-compatible file for data analysis.

What's in the File

  • Summary info at the top with pass/fail counts
  • Column headers based on your export options
  • One row per rule with all the details

How to Export CSV

  1. Complete your audit
  2. Click Export in the results toolbar
  3. Select CSV
  4. Configure export options
  5. Choose save location
  6. Click Export

Using the CSV

Import into:

  • Microsoft Excel: File → Open → Select the CSV
  • Google Sheets: File → Import → Upload the CSV
  • Numbers: File → Open → Select the CSV

The CSV format allows you to:

  • Create custom pivot tables
  • Apply your own filtering and sorting
  • Generate charts and graphs
  • Combine with other data sources

STIG CKL Export

The CKL (Checklist) export creates DISA STIG-compliant XML files required for DoD security assessments.

What is CKL?

CKL is the standard format for DISA STIG checklists. It's an XML file that contains:

  • Device identification
  • Vulnerability assessments
  • Finding details and status
  • Comments and notes

How CKL Export Works

MACE updates an existing CKL template file with your audit results:

  1. You provide a template CKL (from DISA or your organization)
  2. MACE matches STIG IDs between your audit and the template
  3. Results are merged into the template
  4. Updated CKL is saved with your findings

Status Mapping

MACE audit statuses map to CKL statuses:

PassNotAFinding
FailOpen
N/ANot_Applicable
⚠️ErrorNot_Reviewed
👁️Manual ReviewNot_Reviewed
PendingNot_Reviewed

How to Export CKL

  1. Complete your audit (must be STIG compliance)
  2. Go to Audit → STIG CKL Export in the menu bar
  3. Select your CKL template file
  4. Choose where to save the updated CKL
  5. Click Export

The Audit menu only appears when the audit results window is open.

What Gets Updated

For each matching STIG ID:

  • STATUS: Updated to match audit result
  • FINDING_DETAILS: Populated with check command and output
  • COMMENTS: Filled with user comments or rule discussion
  • HOST_NAME: Set from device information

Requirements

  • Audit must use a STIG baseline
  • You must have a CKL template file
  • STIG IDs must match between your audit and the template

To use your organization's logo in reports:

  1. Create a PNG image named logo.png
  2. Place it in your MACE project folder
  3. MACE automatically uses it in PDF and HTML exports

Logo recommendations:

  • Format: PNG with transparency
  • Size: 200-400 pixels wide
  • Aspect ratio: Horizontal works best

Best Practices

📋
Export before remediation

Create a "before" snapshot of your compliance state. This documents your starting point for comparison after fixes.

✏️
Include overrides for auditors

When sharing with auditors, enable "Include Override Indicators" so they can see which results were manually changed.

📊
Use section summary for management

Enable "Section Summary" when creating reports for management. It highlights problem areas at a glance.

💾
Keep CSV for analysis

Export to CSV if you need to do custom analysis, create charts, or combine audit data with other systems.

🛡️
Use CKL for DoD compliance

If you're submitting to a DoD security assessment, the CKL format is required. Keep your template CKL up to date.