SOC 2 (AICPA)
Audited by a licensed CPA firm against the Trust Services Criteria.
- Security (the Common Criteria) is always in scope; Availability, Confidentiality, Processing Integrity, and Privacy are added as you scope them
- Logical and physical access controls, and least privilege
- Change management and system monitoring
- Incident response and risk management
- Vendor and vrisk management
- MFA enforcement and access reviews
- Audit logging and monitoring
- Vulnerability and patch management
- Onboarding and offboarding records
- For Type II, the auditor tests that controls operated over the whole period
ISO/IEC 27001:2022
Certified by an accredited certification body against the ISMS standard.
- The ISMS itself (clauses 4 to 10): context, leadership, risk treatment, internal audit, management review
- Annex A controls (93 in the 2022 revision) across Organizational, People, Physical, and Technological themes
- Your Statement of Applicability and risk treatment plan
- Risk assessment and Statement of Applicability
- Access control and identity records
- Logging and vulnerability management
- Configuration and change evidence showing the controls operate
HIPAA Security Rule
Enforced by HHS Office for Civil Rights, usually on investigation or after a breach.
- Administrative, physical, and technical safeguards
- A required, documented risk analysis
- Access control, audit controls, integrity, person or entity authentication, and transmission security
- The risk analysis and risk management plan
- Unique user IDs, access control, and authentication
- Audit logs and encryption
- Workforce access management and Business Associate Agreements
PCI DSS 4.0
Assessed by a QSA, or self-assessed via an SAQ, as required by your acquirer and the card brands.
- 12 requirements and roughly 300 controls
- Secure configuration and the removal of defaults
- MFA for all access into the cardholder data environment (expanded in 4.0)
- Access control, logging and monitoring, vulnerability management, patching, and anti-malware
- Configuration and network evidence
- MFA and access reviews
- Log retention and review
- Quarterly vulnerability scans and patch SLAs
NIST CSF 2.0 and NIST 800-53
Assessed against an agency ATO cycle (800-53) or used voluntarily as a backbone (CSF).
- CSF functions: Govern, Identify, Protect, Detect, Respond, and Recover
- 800-53 control families (Access Control, Audit and Accountability, Configuration Management, Identification and Authentication, Risk Assessment, System and Information Integrity, and more) at a low, moderate, or high baseline
- Control implementation statements
- Access control and audit logging
- Configuration management and flaw remediation
- Continuous monitoring data
CISA SCuBA
Reported by US federal civilian agencies under CISA direction; usable by anyone hardening Microsoft 365.
- Secure Configuration Baselines per service: Entra ID, Exchange Online, SharePoint and OneDrive, Teams, Defender, and Power Platform
- MFA, Conditional Access, legacy authentication, external sharing, and logging policy
- Per-policy conformance against each baseline
- Documented, justified exceptions
CMMC 2.0 and NIST 800-171
Level 2 requires a C3PAO third-party assessment; lower handling allows self-assessment.
- The 110 NIST 800-171 controls across 14 families
- Access control, audit and accountability, identification and authentication, configuration management, and system and information integrity
- FIPS-validated cryptography for CUI
- A System Security Plan (SSP) and Plan of Action and Milestones (POA&M)
- Access control, MFA, and audit logs
- Configuration baselines and flaw remediation
GDPR
Enforced by EU and UK Data Protection Authorities on investigation, DPIA review, or breach.
- Article 32 appropriate technical and organizational measures
- Access control, encryption, and pseudonymization
- Confidentiality, integrity, and availability of processing
- Breach detection and 72-hour notification, plus data subject access request (DSAR) handling
- Access controls and encryption
- Logging and breach detection
- Records of processing and DPIAs
- DSAR fulfillment, often through Purview
One backbone behind every audit
SOC 2, ISO 27001, HIPAA, PCI DSS, NIST, SCuBA, CMMC, and GDPR use different language, but they audit the same handful of controls. In a Microsoft 365 estate that means multi-factor authentication, Conditional Access, privileged and PIM access, device compliance, audit logging, patch and CVE posture, and data protection. Get those right once and you have most of the evidence for all of them.
Siemserva collects that backbone on every scan, ranks each gap by Severity, maps it to the frameworks an auditor asks about, and attaches a validated fix. Because configuration, logs, and CVEs sit in one connected model, the same scan answers many audits at once, continuously, not in a fire drill the week before fieldwork.
Walk into your next audit with the evidence ready.
Run Siemserva by Senserva against your Microsoft 365, Intune, and Entra ID tenant and get audit-ready evidence on the first scan, mapped to the framework in front of you. Demo and Game Mode run free, no registration and no access to your tenant. Windows and Mac.