Siemserva by Senserva audits the Microsoft tenant your CMMC scope actually runs on and returns dated, ranked findings. The per-practice CMMC mapping is being built now, and this page says which parts exist today and which do not, because a CMMC page that blurs that line is the one an assessor would catch.
Senserva already audits the Microsoft tenant your CMMC scope runs on and returns dated, ranked findings. What is not built yet is the part this page is about: evidence organised practice by practice, so you can walk an assessor down the list rather than translating our findings into their language yourself.
Leave an email address and we will tell you when it ships. That is the whole form, and it is the only thing we will use the address for.
One email address, used to tell you when per-practice CMMC evidence ships and nothing else. Never sold. The free audits are separate and available today through Senserva Watch.
Not a policy document. A CMMC assessor asks whether a practice is implemented and operating, and the artifact that answers is configuration state with a date on it: who has standing privilege, whether legacy authentication is still permitted, whether audit logging is on and retained, what is unpatched and for how long. Those are settings in Microsoft 365, Intune, Defender, Entra ID and Purview, which is exactly what Senserva reads.
Every finding carries the date it was found and the object it was found on. A dashboard reading is a claim about right now; an assessment needs a record, and a record is a thing with a date.
A practice is covered, partially covered, or not covered, and the report says which. A percentage with no denominator is the shape of claim this audience has learned to discount.
A vendor calling something Critical is a vendor opinion. Ours escalates on confirmed exploitation, a CISA KEV listing, or a direct path to tenant compromise, and it can always say which one fired.
Membership of Senserva Watch issues three free unlimited audits, and the sequence matters more than the number. One to find what is there. One to check the fixes landed. One to prove the remediation held, which is the run an assessor is really asking about, because a fix that regressed is not a fix.
| Run | What it answers | Why an assessment cares |
|---|---|---|
| Find it | What is the configuration today, ranked, with dates. | The gap list you would rather write yourself than receive. |
| Fix it | Did the changes actually take effect in the tenant. | An intended change and an applied change are different things, and only one of them is evidence. |
| Prove it | Is it still true a period later. | Assessors ask whether a practice is OPERATING, not whether it was once switched on. |
We produce evidence. A certified assessor decides compliance. Senserva is not a C3PAO, holds no FedRAMP authorization and no agency endorsement, and no report we generate makes an organization compliant or certified. Anyone in this market who tells you otherwise is telling you something you can check.
What we do claim, and will stand behind: more than 650 configuration checks across Microsoft 365, Intune, Defender, Entra ID and Purview; findings dated and attributed to the object they were found on; and a mapping from those checks to CMMC practices and NIST SP 800-53 controls that is our reading of the published control text, which is useful and is not a certification.