Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
---
title: Security scans more frequent
description: Security Center now scans more often and runs for all accounts by default.
products:
- security-center
date: 2026-05-29
---

Security Insights scans now run more often. Cloudflare scans Free accounts **every 7 days**, Pro and Business accounts **every 3 days**, and Enterprise accounts **daily**.

In addition, all accounts and zones now receive scans by default. You no longer need to enable scans before Cloudflare checks your account for misconfigurations, vulnerabilities, and other security risks.

Granular on-demand scans are now available on any plan. You can trigger an on-demand scan for any zone, insight, insight type from the Cloudflare dashboard in order to quickly re-check your security posture after remediating an issue.

To learn more, refer to the [Security Insights documentation](/security/security-insights/).
2 changes: 1 addition & 1 deletion src/content/directory/infrastructure-attack-surface.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@ entry:

meta:
title: Cloudflare Infrastructure docs
description: The Infrastructure tab in Security Center displays an overview of the infrastructure associated with your Cloudflare account after enabling Security Insights.
description: The Infrastructure tab in Security Center displays an overview of the infrastructure associated with your Cloudflare account.
author: "@cloudflare"
17 changes: 5 additions & 12 deletions src/content/docs/security-center/get-started.mdx
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
pcx_content_type: get-started
title: Get started
description: Enable Security Insights to scan your account for misconfigurations and vulnerabilities.
description: Use Security Insights to scan your account for misconfigurations and vulnerabilities.
products:
- security-center
sidebar:
Expand All @@ -17,19 +17,17 @@ Security Center scans your Cloudflare account configuration and identifies poten
- A Cloudflare account.
- At least one [zone](/fundamentals/concepts/accounts-and-zones/#zones) (domain or subdomain) added to your Cloudflare account.

## Enable Security Insights and start initial scan

Security Insights scans are enabled by default. The scan reviews your Cloudflare account settings and product configurations across all your domains, then reports any issues it finds as [insights](/security/security-insights/) — potential security risks, misconfigurations, or vulnerabilities.
## Turn Security Insights on or off

<Render file="setup" product="security-center" />

### Start a new scan

To manually start a scan:

1. In the Cloudflare dashboard, go to the **Infrastructure** page.
1. In the Cloudflare dashboard, go to the **Security insights** page.

<DashButton url="/?to=/:account/security-center/inventory" />
<DashButton url="/?to=/:account/security-center" />

2. Select **Scan now**.

Expand All @@ -39,11 +37,6 @@ Only accounts with at least one Business or Enterprise zone, or accounts on the

### Scan frequency

After you enable Security Insights, Cloudflare performs scans automatically on a recurring schedule based on your plan:

| Plan | Scan frequency | On-demand scans |
| ---------------------- | -------------- | --------------- |
| Free, Pro, or Business | Every 7 days | Yes |
| Enterprise | Every 3 days | Yes |
<Render file="scan-frequency" product="security-center" />

For more details, refer to [How it works](/security/security-insights/how-it-works/#scan-frequency).
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ Only Super Admin users with edit permissions can start scans, turn scans off, or

The **Infrastructure** tab provides an overview of the IT assets associated with your Cloudflare account, including domains, IP addresses, and related configurations.

Infrastructure data is populated by [Security Insights](/security/security-insights/) scans. To view data in this tab, first [enable Security Insights](/security-center/get-started/) and wait for the initial scan to complete. Initial scan time depends on the number of IT assets across the domains in your account.
[Security Insights](/security/security-insights/) scans populate Infrastructure data. Initial scan time depends on the number of IT assets across the domains in your account.

To open the **Infrastructure** tab, go to Account Home > **Security Center** > **Infrastructure**.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ sidebar:

import { Render } from "~/components";

Once you [enable Security Insights](/security-center/get-started/), Cloudflare runs regular security scans on your account. These scans check your Cloudflare account settings, DNS record configurations, and product configurations — such as SSL/TLS, WAF, and Access — across all domains in your account.
Cloudflare runs regular security scans on your account. These scans check your Cloudflare account settings, DNS record configurations, and product configurations — such as SSL/TLS, WAF, and Access — across all domains in your account.

Each scan compares your current configuration against a set of ideal product configurations that indicate a strong security posture. When your configuration does not match an ideal configuration for one or more checks, the scan produces a **Security Insight** — a finding that represents a potential risk.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ sidebar:

import { DashButton } from "~/components";

After [enabling Security Insights](/security-center/get-started/) and letting the first scan run, check the **Security Insights** tab for a list of detected insights that you should address.
Check the **Security Insights** tab for a list of detected insights that you should address.

For each detected insight, you can resolve it or archive it, after understanding its risks.

Expand Down
7 changes: 4 additions & 3 deletions src/content/partials/security-center/scan-frequency.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -3,9 +3,10 @@

---

Once you enable Security Insights, Cloudflare performs scans automatically. Paying customers (as defined in the table below) are re-scanned daily and can trigger a scan manually:
Cloudflare performs scans automatically for all accounts and zones by default. On-demand scans are available on all plans:

| Plan | Scan Frequency | On-Demand |
| ----------------------------------------- | -------------- | --------- |
| Accounts on a Free, Pro, or Business plan | Every 7 days | Yes |
| Accounts on an Enterprise plan | Every 3 days | Yes |
| Free | Every 7 days | Yes |
| Pro and Business | Every 3 days | Yes |
| Enterprise | Daily | Yes |
2 changes: 1 addition & 1 deletion src/content/partials/security-center/setup.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@

import { DashButton } from "~/components";

Security Insights start scans by default. Security Insights will scan your Cloudflare environment and provide you with a list of detected [insights](/security/security-insights/). Refer to [How it works](/security/security-insights/how-it-works/) to learn more about how Security Insights perform a scan.
Security Insights scans are enabled by default. Security Insights will scan your Cloudflare environment and provide you with a list of detected [insights](/security/security-insights/). Refer to [How it works](/security/security-insights/how-it-works/) to learn more about how Security Insights perform a scan.

The initial scan time depends on the number of IT assets in all the domains of your Cloudflare account. When the scan is complete, the status of the page will change from **Scan in Progress** to **Last scan performed on: `<DATE_TIME>`**.

Expand Down
Loading