Senserva Federal

Senserva for CMMC

Siemserva by Senserva audits the Microsoft tenant your CMMC scope actually runs on and returns dated, ranked findings. The per-practice CMMC mapping is being built now, and this page says which parts exist today and which do not, because a CMMC page that blurs that line is the one an assessor would catch.

Coming soon

Per-practice CMMC evidence is being built now.

Senserva already audits the Microsoft tenant your CMMC scope runs on and returns dated, ranked findings. What is not built yet is the part this page is about: evidence organised practice by practice, so you can walk an assessor down the list rather than translating our findings into their language yourself.

Leave an email address and we will tell you when it ships. That is the whole form, and it is the only thing we will use the address for.

One email address, used to tell you when per-practice CMMC evidence ships and nothing else. Never sold. The free audits are separate and available today through Senserva Watch.

What an assessor actually asks for

Not a policy document. A CMMC assessor asks whether a practice is implemented and operating, and the artifact that answers is configuration state with a date on it: who has standing privilege, whether legacy authentication is still permitted, whether audit logging is on and retained, what is unpatched and for how long. Those are settings in Microsoft 365, Intune, Defender, Entra ID and Purview, which is exactly what Senserva reads.

Dated, not current

Every finding carries the date it was found and the object it was found on. A dashboard reading is a claim about right now; an assessment needs a record, and a record is a thing with a date.

Coverage as a fraction

A practice is covered, partially covered, or not covered, and the report says which. A percentage with no denominator is the shape of claim this audience has learned to discount.

Critical is earned

A vendor calling something Critical is a vendor opinion. Ours escalates on confirmed exploitation, a CISA KEV listing, or a direct path to tenant compromise, and it can always say which one fired.

The three audits, and what each one is for

Membership of Senserva Watch issues three free unlimited audits, and the sequence matters more than the number. One to find what is there. One to check the fixes landed. One to prove the remediation held, which is the run an assessor is really asking about, because a fix that regressed is not a fix.

RunWhat it answersWhy an assessment cares
Find itWhat is the configuration today, ranked, with dates.The gap list you would rather write yourself than receive.
Fix itDid the changes actually take effect in the tenant.An intended change and an applied change are different things, and only one of them is evidence.
Prove itIs it still true a period later.Assessors ask whether a practice is OPERATING, not whether it was once switched on.

What we may say, and what we may not

We produce evidence. A certified assessor decides compliance. Senserva is not a C3PAO, holds no FedRAMP authorization and no agency endorsement, and no report we generate makes an organization compliant or certified. Anyone in this market who tells you otherwise is telling you something you can check.

What we do claim, and will stand behind: more than 650 configuration checks across Microsoft 365, Intune, Defender, Entra ID and Purview; findings dated and attributed to the object they were found on; and a mapping from those checks to CMMC practices and NIST SP 800-53 controls that is our reading of the published control text, which is useful and is not a certification.

Read next