The crosswalk, by the numbers
Every Senserva check carries the frameworks and controls it provides evidence for. So you can answer the auditor question the other way around: for a given control, here are the exact checks that evidence it, and whether they pass. The counts below are the framework's own control set next to how many of Senserva's 672 Microsoft 365 checks map to it.
| Framework | Its control set | Senserva checks mapped |
|---|---|---|
| CISA SCuBA | 6 M365 service baselines | 632 |
| Microsoft Cloud Security Benchmark | 12 control domains | 672 |
| CIS Controls v8.1 | 18 controls, 153 safeguards | 632 |
| NIST SP 800-53 Rev 5 | 20 families, 1,000+ controls | 672 |
| SOC 2 | 5 Trust Services Criteria | 672 |
| HIPAA Security Rule | 18 safeguard standards | 584 |
| ISO/IEC 27001:2022 | 93 Annex A controls | identity, device, logging |
| CMMC Level 2 | 110 practices, 320 objectives | 800-171-aligned |
| NIST CSF 2.0 | 6 functions, 106 subcategories | via 800-53 |
| Essential Eight | 8 strategies, 4 maturity levels | identity, patch, device |
| UK Cyber Essentials | 5 technical controls | config, identity |
| PCI DSS 4.0 | 12 core requirements | where in scope |
| FedRAMP | Low / Moderate / High baselines | 800-53-aligned |
Where a column reads "via 800-53" or "identity, device, logging," the framework does not carry its own tag in the catalog but is evidenced by the same underlying checks. Senserva is not an auditor and issues no certifications; it provides the technical configuration evidence, ranking, and remediation that make an audit defensible.
Every framework, what it asks, and where Senserva fits
Control counts are the framework's own, from its authoritative source. Check counts are how many of Senserva's Microsoft 365 checks provide evidence.
Secure configuration baselines for the six core Microsoft 365 services: Entra ID, Exchange Online, SharePoint and OneDrive, Teams, Defender for Office 365, and Power Platform.
Microsoft's own security baseline, organized into 12 control domains spanning identity, network, data protection, logging, and posture. The backbone many other frameworks map to.
The CIS Critical Security Controls v8.1 define 18 controls and 153 safeguards (Implementation Groups IG1 56, IG2 130, IG3 153). The CIS Microsoft 365 Foundations Benchmark adds roughly 140 M365-specific recommendations. Senserva turns CIS benchmark auditing into a scan: a CIS benchmark assessment of your tenant against 632 mapped checks, each finding carrying its safeguard as evidence for Microsoft 365 compliance reporting.
20 control families and over 1,000 controls and control enhancements. The catalog behind FedRAMP and most U.S. federal security programs.
6 functions (Govern, Identify, Protect, Detect, Respond, Recover), 22 categories, and 106 subcategories. A cross-industry de facto standard.
Five Trust Services Criteria: Security (mandatory), Availability, Processing Integrity, Confidentiality, and Privacy. There is no fixed control list: 61 criteria and about 300 points of focus, against which an auditor tests the controls you define.
Safeguard standards in three groups: Administrative (9), Physical (4), and Technical (5), each with required or addressable implementation specifications.
93 Annex A controls in four themes: Organizational (37), People (8), Physical (14), and Technological (34). The leading international standard for an Information Security Management System, held by tens of thousands of certified organizations worldwide.
110 practices and 320 assessment objectives across 14 domains, mirroring NIST SP 800-171 Rev 2. The DoD final rule (32 CFR Part 170, effective December 2024; the DFARS acquisition rule, effective November 2025) is phasing it into contracts, affecting roughly 337,000 Defense Industrial Base entities.
Eight mitigation strategies (application control, patch applications, Office macro settings, user application hardening, restrict admin privileges, patch operating systems, multi-factor authentication, regular backups) across Maturity Levels Zero to Three.
Five technical controls: firewalls, secure configuration, security update management, user access control, and malware protection. Over 33,000 certificates were issued in 2024.
12 core requirements across six goals for protecting cardholder data.
Low, Moderate, and High authorization baselines drawn from NIST SP 800-53 Rev 5. Relevant to Microsoft 365 GCC and GCC High.
Compliance framework questions, answered
The numbers that come up most, with the authoritative source behind each one.
How many controls are in NIST 800-53?
NIST SP 800-53 Revision 5 contains over 1,000 controls and control enhancements, organized into 20 control families such as Access Control (AC), Audit and Accountability (AU), and Identification and Authentication (IA). It is mandatory for U.S. federal systems under FISMA and is the control catalog behind FedRAMP.
How many ISO 27001 Annex A controls are there?
ISO/IEC 27001:2022 has 93 Annex A controls, down from 114 in the 2013 edition, grouped into four themes: Organizational (37), People (8), Physical (14), and Technological (34). ISO 27001 is the leading international standard for an Information Security Management System.
How many CMMC Level 2 practices are there?
CMMC Level 2 has 110 practices, assessed against 320 objectives across 14 domains, mirroring NIST SP 800-171 Revision 2 exactly. It is mandatory for U.S. Department of Defense contractors that handle Controlled Unclassified Information, phasing into contracts through the DoD final rule.
How many CIS Controls are there?
The CIS Critical Security Controls version 8.1 define 18 controls and 153 safeguards. The safeguards are split across three Implementation Groups: IG1 has 56, IG2 has 130, and IG3 has all 153. The separate CIS Microsoft 365 Foundations Benchmark adds around 140 M365-specific recommendations.
What is CISA SCuBA?
CISA SCuBA (Secure Cloud Business Applications) is a set of secure configuration baselines for the six core Microsoft 365 services: Entra ID, Exchange Online, SharePoint and OneDrive, Teams, Defender for Office 365, and Power Platform. Binding Operational Directive 25-01 directs U.S. federal civilian agencies to apply them.
What are the SOC 2 Trust Services Criteria?
SOC 2 has five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security (the Common Criteria) is mandatory in every SOC 2 report; the other four are included only when relevant. SOC 2 defines criteria, not a fixed control list, so the auditor tests the controls you map to them.
Does Microsoft 365 meet CMMC or NIST 800-171?
Microsoft 365 can provide the technical controls behind many of the 110 NIST 800-171 and CMMC Level 2 requirements, but no product makes a tenant compliant on its own. Compliance depends on how identity, device, logging, and data-protection settings are configured, which is what Senserva checks and evidences.
Copy it into Claude, ChatGPT, or Copilot to pick a framework and plan the work. Free, no sign-in.
From mapping to evidence to fixed
A crosswalk on paper is a start. Senserva runs the checks against your tenant, ranks the gaps by real-world risk, and generates validated, approve-before-apply remediation, so the next scan proves the control is in place. That is what turns a framework into a defensible posture.