The first version of any compliance scan produces a number nobody can act on. Thousands of findings, most of them true, all of them arriving at once. The team's rational response is to stop reading the report, and from that moment the scanner is decorative.
Coverage is the easy metric to chase and the wrong one to optimise first. A scanner covering sixty percent of controls that people actually act on beats one covering ninety-five percent that nobody opens.
What actually helps
Group by fix, not by finding. Fifty findings that share one remediation are one piece of work. Reporting them as fifty items is a choice, and it is the wrong one.
Rank by exploitability in your deployment, not by the severity field in the benchmark. A control rated high in a generic context may be unreachable in your architecture. Say so, with the reason recorded, and stop showing it at the top.
Separate "new since last scan" from "known and accepted". Most of the value of a recurring scan is in the delta. If your report cannot show the delta cleanly, it will be read once.
The uncomfortable part
Someone has to own the accepted-risk list, and it has to be reviewed. An exception with no expiry is a permanent hole with paperwork attached. Put a date on every exception and force the conversation again when it lapses.