Major Highlights
- Redesigned Build Hub — Every MDM upload is now a guided Settings, Review, Upload, Verify flow, with saved servers, permission checks, and activity history. Each MDM also gained features built for its platform, from Smart Groups in Jamf Pro to Compliance Policies in Intune and Fleet.
- Baseline Compare Hub — Put two baselines side by side: different frameworks, OS versions, mSCP sources, or your own projects. See what only one side includes, what differs rule by rule, and compare a project against its framework to see just your changes. Export the comparison as CSV, Markdown, or HTML.
- Rule Exemptions — Mark a rule as exempt with a reason and it flows through everything: the editor, every build and MDM upload, audit results, and generated documentation. The rule is still checked, nothing enforces it, and reports say why.
- Custom Rule Sources — Build from mSCP beta branches or any public GitHub fork that follows the mSCP 2.0 layout. Fork mSCP, edit rules your way, and point MACE at your repo. Projects remember their source, and Switch Branch moves a project between sources in one step.
- Map Framework from SCF — Pick any of 230+ frameworks from the Secure Controls Framework (ISO 27002, GovRAMP, CMMC, privacy laws, and more) and MACE maps your rules to it through their NIST 800-53 references. Export the mapping, add the framework to your project, or switch to it outright.
Main App Changes
- Added: A Compare Baselines button on the main menu opens the new Baseline Compare Hub.
- Added: mSCP Source setting under Settings › General › Rules. Pick Release (main) or a Beta branch such as dev_2.0 or dev_27, and new projects get their platform, version, and compliance lists from that branch. Beta branches are discovered automatically and kept up to date alongside main when Auto-Download is on.
- Added: Additional Sources. Point MACE at any public repository that follows the mSCP 2.0 layout (
src/mscp/data/rules) asowner/repoor a GitHub URL. Fork mSCP, edit rules as you like, and build against your own copy. Private repositories aren't supported. - Changed: Every project records the source and branch it was created from, and updates follow that branch. The New Project sheet shows a "Using beta branch" badge when a Beta source is active.
- Changed: "Auto-Download mSCP Rules" is now Auto-Download Rules and covers every source you follow.
Compliance Editor Changes
- Added: Map Framework from SCF, in the Rules menu. Pick any of 230+ frameworks from the Secure Controls Framework (ISO 27002, GovRAMP, CMMC, privacy laws, and more) and MACE works out which rules satisfy it through their NIST 800-53 references. Export mapping files only, add the framework to the project so it appears under Change Build, or switch the project to it right away. Custom rules are never touched. Idea from @boberito's mscp_scripts. Thanks, Bob!
- Added: Exempt rules. The include checkbox has a third state: one click turns a checked rule into a dash, meaning it stays in the baseline and is still checked by the compliance script, but nothing enforces it. A second click disables it as before, and Option-click disables directly. Exempt rules get an indigo badge, an optional reason in the sidebar, Exempt Rule and Remove Exemption in the right-click menu, an exempt count in the bottom bar, and Exempt, Modified, Disabled, and Flagged entries in the filter dropdown.
- Added:
$ODVplaceholders are highlighted in the rule list and every field, and hovering shows the value for your compliance. Settings › Appearance › Rule Editor offers On, Off, or Always Show Value. - Changed: Title and discussion show
$ODVas written instead of the filled-in number. Changing an ODV no longer marks those fields as Modified or writes them into the custom override. - Added: Rules ▸ Switch Branch… moves a project to a different source: Release, a beta branch, or a fork. It downloads that branch's rules and checks for updates in one step.
- Added: What's Changing. The update sheet lists every rule and project file the update touches. Click a row for an inline before and after diff with Wrap, Whole file, and folds for unchanged parts. Open shows one file's diff in its own window with a Split view and a link to its history on GitHub.
- Changed: Rules ▸ "Check for mSCP Updates" is now Check for Rule Updates and checks against the project's own source.
- Fixed: Rules that change their check or fix for a specific OS version (e.g.
audit_auditd_enabledon macOS 15) now use that version's check and fix in the editor, compliance script, Tenable audit and documentation. - Fixed: Rules you add or remove now stay that way when you reopen a project. A colon in the Benchmark Name, Author, Organization, or a new rule's title produced a file that couldn't be read, so the project quietly went back to the default rule set. Affected projects recover on their own. Reported by @mahlmanj (#30). Thanks!
- Fixed: Switching rules could briefly leave the previous rule's details in the sidebar, so a value typed at that moment landed on the wrong rule. The sidebar now clears instantly. Thanks @jmahlman.
- Fixed: Commit history links used a path GitHub stopped tracking in September 2025, so history stopped there. They now follow the project's source and branch.
Build Hub Changes
Note: The Build Hub was redesigned. Every MDM tab and Local Build share a guided flow that connects, reviews, uploads, and verifies in one window, and the compliance script was rebuilt to full parity with mSCP 2.0's own script template.
- Changed: Uploading to Jamf Pro, Workspace ONE, Intune, Fleet, Iru, and Addigy is now a guided four-step flow: Settings, Review, Upload, Verify. Build and Upload options are merged into one panel with Off, Combined, and Individual per item, and the Build Hub remembers all your choices between sessions.
- Added: Review before upload. See everything headed to your MDM, uncheck what you don't want, and preview any file. Nothing is sent until you confirm.
- Added: Upload verification. After uploading, MACE confirms every item arrived on your server, with a link to each item's console page and what to do next.
- Added: Save multiple servers, tenants, or organizations and switch between them from the connection header. Credentials live in the macOS Keychain, and your last-used one connects automatically.
- Added: Test Connection verifies every permission MACE needs and shows what's missing. Optional ones gray out their features; required ones disable exporting until fixed.
- Added: Activity history. Every connection test and upload is saved per project with date, account, and per-item results.
- Added: Jamf Pro: Smart Groups upload creates a matched Compliant and Non-Compliant pair, Audit Policy upload runs the audit on your schedule and updates inventory, and Sites support assigns profiles to a site. The category picker adapts to your account's permissions. Smart Groups and Audit Policy are macOS only.
- Added: Workspace ONE: choose Sensors or Custom Attributes for compliance reporting, and Scripts or an inactive Product for script delivery.
- Added: Intune: Settings Catalog delivery uploads supported settings as native policies and ships the rest as preference files. Compliance Policy marks failing Macs noncompliant with the failing rules named, created unassigned, with a Mark Noncompliant grace period. An Assignment Filter matches your project's OS version, and Script Frequency sets how often scripts rerun.
- Added: Fleet: Compliance Policy as one policy or one per rule with an optional Critical flag, plus a Failed Rules report. A Version Label matches your project's OS, and Hold for Scoping (on by default) stages uploads behind an empty label. Test Connection reports Premium or Free, MDM-enrolled host count, and your role per fleet. Uploaded scripts can be run on hosts from the results, and a GitOps kit is written with every export.
- Added: Iru: Blueprint assignment as a review step, with a staging Blueprint option. Each script sets its own audit and remediation slot modes, and updates replace in place so IDs and assignments survive.
- Added: Addigy: Policy assignment as a review step, saved Organizations, and Test Connection grays out anything your API key can't do instead of failing mid-upload.
- Added: The Advanced installer's uninstaller now uploads alongside the installer on every MDM.
- Changed: Local Build was rebuilt on the MDM tabs' layout, with Off, Combined, and Individual per item and the build running inline in the hub. Results list every generated file, verify it exists, and let you expand it to read its contents, with Show in Finder and Open. Compliance Reporting scripts moved to Additional Outputs, and the audit is always part of the compliance script.
- Added: Local Build writes Fleet GitOps files to
build/fleet_gitops/via the Compliance Reporting & Other MDM Files toggle: everything the Fleet export would upload, ready forfleetctl gitops. - Added: Local Build includes the Intune custom compliance files in
extension_attributes/, the same discovery script and rules JSON Export to Intune uploads, with a README walkthrough for setting up the policy by hand. - Added: Compliance script flags for MDMs:
--stats,--compliant,--non_compliant, and--jsonread the audit plist without re-scanning or needingjq.--resetand--reset-allclear results without touching exemptions.--list,--check-rule <id>,--fix-rule <id>, and--dry-runwork on single rules.--exempt <id> <reason>,--unexempt <id>, and--exemptionsmanage exemptions.--quiet=1,--quiet=2, and--versionround it out. - Added: Running the script with no arguments on a real terminal opens an interactive menu: scan, fix, view and save a report, check a rule, manage exemptions. From an MDM, LaunchDaemon, or CI it prints usage and exits cleanly.
- Added: Script arguments can be set through a
compliance_argskey inorg.<baseline>.audit, so an MDM profile can change what the script does without redeploying it. - Added: Results also go to the unified log and a CSV alongside the existing log. Log and CSV filenames carry the hostname. Architecture-specific rules are gated on the actual machine, and
manualand Excluded-section rules are skipped rather than counted. - Changed: Rules that can't be evaluated (needing a logged-in user, Intel-only on Apple silicon) are recorded as not applicable instead of silently passing. The audit plist carries a summary tally and drops per-rule citations, so it fell from about 65 KB to 9 KB. Usage errors return exit status 2. The script header and
--helpare generated from one source. - Changed: Individual-script mode builds each script from the combined script's engine scoped to its single rule, with the same header and settings.
- Added: Exempt rules build the same way in Local Build and every MDM upload. Audit preferences carry
exempt = trueand the reason, exempt rules stay in the script but are left out of profiles, DDM declarations, and the vendor manifest, and the README lists every exemption. mSCP engine builds patch exemptions in after the run. - Added: The build README documents every script option, the interactive menu, exit codes, exemptions, and log files, generated from the same source as
--help. Hiding MACE branding now also removes the "Generated by M.A.C.E." line. - Changed: DDM builds now handle every declaration type, including future mSCP ones and custom rules, instead of a fixed list.
- Fixed: Exemptions delivered by a configuration profile were ignored by the compliance script. It now checks managed preferences first.
- Fixed: Workspace ONE custom attributes with a multi-word baseline name failed to record anything. They now write correctly.
- Fixed: DDM declarations were missing settings when more than one rule targeted the same setting group, so a CIS Level 1 build only enforced one of the three automatic software update rules. Reported by @patgmac (#32). Thanks!
- Fixed: Vendor Manifest leaves out rules a scanner can't check, includes severity, uses real ODV values in fixes, and matches the compliance script's results path.
- Fixed: Tenable Audit keeps multi-line checks intact (about half were collapsed and couldn't run), follows the community script for warnings, and its
see_alsolinks point at the project's actual repository and branch.
Audit Builder Hub Changes
- Added: Include Exemptions dropdown: Local (deployed on this Mac), Compliance (marked Exempt in the project), or both, with live counts. Exempt rules keep their real Pass or Fail and show the badge. An Exemption Source picker in the export sidebar chooses whether reports count only project exemptions (default) or everything the scan honored.
- Added: Exemptions in every export: an Exemptions group mirroring the Flagged for Review controls, an Exclude Exempt Rules switch, Exempt and Exemption Reason columns in CSV and XLSX, an exempt flag in JSON, callouts in HTML and PDF, and the reason in STIG checklist comments with the real status kept.
- Changed: Pass rate leaves exempt rules out, and Need Attention no longer counts exempt failures.
- Added: Row badges for Exempt, Modified, and N/A next to each rule, with matching header filters. Rule details show the exemption reason and source, Review Comment and Disabled Justification blocks, and a Modified Rule block listing each changed field with baseline and custom values.
- Added: PDFs include bookmarks, so Preview's sidebar shows a clickable Table of Contents, and the detailed Table of Contents shows page numbers.
- Changed: Rule titles in the audit show the actual value instead of
$ODV, so what you see matches what was checked. - Fixed: An ODV changed while the audit window was open was ignored. The audit now uses the current saved value. Thanks @jmahlman.
- Fixed: Table of Contents links in exported PDFs did nothing on macOS 27. They jump to the right section or rule again.
Documentation Builder Hub Changes
- Added: Exempt group under Rule Options with Show Exempt Indicator, Include Reasons, and Own Section. Exempt rules get an indigo badge and reason block in HTML and PDF, a callout in Markdown and AsciiDoc, fields in JSON, and columns in CSV and XLSX.
- Added: PDFs include bookmarks for Preview's sidebar, Table of Contents entries show page numbers, and the Quick Reference table has a clickable Page column.
- Changed: "Page X of Y" is now part of the page instead of a movable note. PDFs are noticeably smaller: a 111-rule report went from 4.2 MB to 1.5 MB.
- Fixed: Scrolling the PDF preview could freeze the app. The dotted Table of Contents lines and dashed dividers caused it and are now drawn safely.
- Fixed: Table of Contents and Quick Reference links in exported PDFs did nothing on macOS 27. They work again.
- Fixed: Exporting a single format took several seconds to load rules while Generate All was quick. Both are now fast.
- Fixed: Long discussions in the PDF were cut off at about 2,000 characters. The full text now renders.
- Fixed: AsciiDoc admonitions leaked into HTML, PDF, and Markdown as raw
[IMPORTANT] ====markup. They now render as NOTE, WARNING, CAUTION, or TIP callouts. - Fixed: Underscores in rule IDs were eaten by italic formatting in HTML and PDF, turning os_gatekeeper_enable into "osgatekeeperenable".
- Fixed: PDF tables no longer leave a lone row at the bottom of a page, the Both color scheme writes both light and dark files, Page Numbers work without the date, and Date Format applies to the "generated on" date.
Rule Builder Hub Changes
No changes this release.
Baseline Compare Hub (New)
- Added: Compare two baselines side by side: different frameworks, OS versions, mSCP sources, or one of your own MACE projects. Summary counts and All / Left / Right / Differences filters show what only one side includes and what differs, with each rule's ODV, check, fix and references compared in a sidebar.
- Added: Compare a project against its framework to see only your real changes, with removed, exempt and edited rules marked as in the Compliance Editor. Search by STIG ID or CCE, ignore wording changes that don't affect the requirement, and export as CSV, Markdown or HTML.
Feedback Needed
We'd love your help testing features to make sure everything works as expected.
Framework mapping is new. The SCF cross-walk is only as good as the NIST 800-53 references on each rule, so a framework that maps to no rules usually means it only covers policy or privacy controls. If a mapping looks wrong for a framework you know well, please say so.
If you run into any issues or have suggestions, please open an issue at github.com/mace-app/mace.
Known Issues
- mSCP Engines: I expect issues with the mSCP engines since they rely on the mSCP 2.0 Python scripts, which don't have everything fully mapped out yet.
- mSCP Engines: Custom rules are not currently supported.
- MDM console links: The per-item links after uploading are best guesses at each console's routes. If one opens the wrong page, please report it.
- UI font sizing: May vary depending on your system's accessibility, display, or font settings. A fix requires reworking fonts across every screen, so this is on hold for now.
- (Sequoia & Below): Glass/blur effects don't look quite right on older macOS versions. Adjusting visuals to work well without these effects will take time.
- Console logging: May not capture all events. Logging is being improved incrementally as features are updated.