Preview Your Audit
Comply

Compliance Benchmarks

CIS Microsoft 365 benchmarks, security baselines, and compliance scoring.

CIS benchmarks deployed and scored — not just documented.

ISO 27001 Certified 3x Microsoft Partner of the Year 1,200+ Organisations Secured 30+ Years

Without a measurable baseline, security is subjective — and your auditor knows it. We deploy CIS v6.0.1 with 170+ prescriptive checks across your entire M365 tenant, score your current state, remediate gaps, and monitor for drift. Compliance is continuous, not a point-in-time exercise you prepare for the week before audit.

Below is what we deploy, measure, and continuously monitor. Every benchmark check produces evidence your auditor can verify.

Foundation (Plan 1)

  • Exchange CIS Fundamentals — CIS Microsoft 365 Foundations benchmark settings for Exchange Online
  • SharePoint CIS Fundamentals — CIS Microsoft 365 Foundations benchmark settings for SharePoint Online
  • Teams CIS Fundamentals — CIS Microsoft 365 Foundations benchmark settings for Microsoft Teams
  • OneDrive CIS Fundamentals — CIS Microsoft 365 Foundations benchmark settings for OneDrive for Business
  • Entra ID CIS Hardening (Identity) — CIS M365 v6.0.1 Entra ID hardening: guest access, consent, group creation, app registration, PIM approval, device join
  • Entra ID CIS Hardening (Authentication) — CIS M365 v6.0.1 authentication hardening: device code flow, enrollment frequency, authenticator settings, email OTP, session controls
  • Intune CIS Hardening — CIS M365 v6.0.1 Intune hardening: SecureByDefault, personal enrollment, Entra join, device quota, LAPS
  • Microsoft Physical Access Controls — Microsoft-managed physical access controls for datacentres including monitoring, intrusion detection, and access logging
  • Microsoft Environmental Protection — Microsoft-managed fire protection, water damage protection, emergency power, and environmental controls
  • Microsoft Media Handling — Microsoft-managed media storage, sanitization, and disposal procedures
  • Microsoft Datacentre Infrastructure — Microsoft-managed datacentre security including perimeter protection, cabling, and equipment protection
  • Microsoft Equipment Maintenance — Microsoft-managed equipment maintenance and operational procedures

Added in Endpoint (Plan 2)

  • Windows CIS L1 Benchmark — CIS Level 1 security baseline for Windows 11 Enterprise
  • macOS CIS L1 Benchmark — CIS Level 1 security baseline for macOS
  • Chrome CIS L1 Benchmark — CIS Level 1 security baseline for Google Chrome
  • Edge CIS L1 Benchmark — CIS Level 1 security baseline for Microsoft Edge

What you receive

Delivery PackageDurationStakeholdersKey Deliverables
CIS M365 Hardening5–12 daysIT Admin, Security AnalystCIS assessment baseline report; Remediation plan (prioritised by risk); Deployed CIS-compliant configurations; Exception documentation
Passwordless & FIDO2 Strategy5–15 daysCISO, IT Admin, End UsersCredential strategy document; Auth method registration policies; FIDO2 key deployment plan; WHfB enrolment configuration; Password elimination roadmap
CIS Endpoint Hardening5–15 daysIT Admin, Security AnalystCIS L1 profiles per platform; Policy exception documentation; Compliance reporting baseline; Browser hardening profiles

Risk impact

RiskBeforeAfterReduction
Policy and Standards Non-Conformance16381%
Regulatory and Legal Non-Compliance16381%
Uncontrolled Changes to Systems12283%
Cryptographic Non-Compliance8275%
Large Supplier Non-Compliance8275%

Risk scores use a likelihood × impact matrix (1–25). Lower is better.


Ready to see where you stand? Our free assessment benchmarks your compliance posture against these capabilities — in 30 minutes, no tenant access required. Start your assessment.


ISO 27001 controls covered

The following physical controls are inherited from Microsoft as the cloud service provider:

Auditor Question Bank — 788 questions with difficulty ratings mapped to ISO 27001 controls
788 auditor questions mapped to controls — we know what they will ask