Microsoft 365 compliance frameworks

Every framework asks the same thing in different words: prove your Microsoft 365 is configured securely and that it stays that way. Siemserva by Senserva turns that into evidence: findings mapped to each framework's controls, ranked by risk, with validated remediation.

Pick a framework below, or jump straight to the checks catalog and filter the Compliance evidence column, or browse it by control on the control reference (one page per MCSB control and CISA SCuBA policy). Outside the US? See Microsoft 365 compliance by country: NIS2, DORA, BSI, ANSSI, NCSC, Essential Eight, and more.

672 Microsoft 365 checks13 frameworks crosswalked100% carry an exact MCSB control code

The crosswalk, by the numbers

Every Senserva check carries the frameworks and controls it provides evidence for. So you can answer the auditor question the other way around: for a given control, here are the exact checks that evidence it, and whether they pass. The counts below are the framework's own control set next to how many of Senserva's 672 Microsoft 365 checks map to it.

FrameworkIts control setSenserva checks mapped
CISA SCuBA6 M365 service baselines632
Microsoft Cloud Security Benchmark12 control domains672
CIS Controls v8.118 controls, 153 safeguards632
NIST SP 800-53 Rev 520 families, 1,000+ controls672
SOC 25 Trust Services Criteria672
HIPAA Security Rule18 safeguard standards584
ISO/IEC 27001:202293 Annex A controlsidentity, device, logging
CMMC Level 2110 practices, 320 objectives800-171-aligned
NIST CSF 2.06 functions, 106 subcategoriesvia 800-53
Essential Eight8 strategies, 4 maturity levelsidentity, patch, device
UK Cyber Essentials5 technical controlsconfig, identity
PCI DSS 4.012 core requirementswhere in scope
FedRAMPLow / Moderate / High baselines800-53-aligned

Where a column reads "via 800-53" or "identity, device, logging," the framework does not carry its own tag in the catalog but is evidenced by the same underlying checks. Senserva is not an auditor and issues no certifications; it provides the technical configuration evidence, ranking, and remediation that make an audit defensible.

Every framework, what it asks, and where Senserva fits

Control counts are the framework's own, from its authoritative source. Check counts are how many of Senserva's Microsoft 365 checks provide evidence.

CISA SCuBA

Secure configuration baselines for the six core Microsoft 365 services: Entra ID, Exchange Online, SharePoint and OneDrive, Teams, Defender for Office 365, and Power Platform.

632 checksDirected for U.S. federal civilian agencies by CISA Binding Operational Directive 25-01 (December 2024).
Microsoft Cloud Security Benchmark

Microsoft's own security baseline, organized into 12 control domains spanning identity, network, data protection, logging, and posture. The backbone many other frameworks map to.

672 checks, each with an exact MCSB control codeMicrosoft's recommended baseline for Azure and Microsoft 365; voluntary.
CIS Controls and CIS Microsoft 365 Benchmark

The CIS Critical Security Controls v8.1 define 18 controls and 153 safeguards (Implementation Groups IG1 56, IG2 130, IG3 153). The CIS Microsoft 365 Foundations Benchmark adds roughly 140 M365-specific recommendations. Senserva turns CIS benchmark auditing into a scan: a CIS benchmark assessment of your tenant against 632 mapped checks, each finding carrying its safeguard as evidence for Microsoft 365 compliance reporting.

632 checksVoluntary; referenced in several U.S. state data-breach safe-harbor laws and used as a CMMC on-ramp.
NIST SP 800-53 Rev 5

20 control families and over 1,000 controls and control enhancements. The catalog behind FedRAMP and most U.S. federal security programs.

672 checksMandatory for U.S. federal information systems under FISMA; voluntary but widely adopted elsewhere.
NIST Cybersecurity Framework 2.0

6 functions (Govern, Identify, Protect, Detect, Respond, Recover), 22 categories, and 106 subcategories. A cross-industry de facto standard.

Mapped through the 800-53 controlsVoluntary; referenced by regulators and mapped to by most other frameworks.
SOC 2

Five Trust Services Criteria: Security (mandatory), Availability, Processing Integrity, Confidentiality, and Privacy. There is no fixed control list: 61 criteria and about 300 points of focus, against which an auditor tests the controls you define.

672 checks of technical evidenceVoluntary AICPA attestation; a de facto requirement in B2B SaaS procurement.
HIPAA Security Rule

Safeguard standards in three groups: Administrative (9), Physical (4), and Technical (5), each with required or addressable implementation specifications.

584 checksLegally mandated for U.S. covered entities and their business associates; enforced by HHS OCR.
ISO/IEC 27001:2022

93 Annex A controls in four themes: Organizational (37), People (8), Physical (14), and Technological (34). The leading international standard for an Information Security Management System, held by tens of thousands of certified organizations worldwide.

Evidenced through the identity, device, and logging checksVoluntary international ISMS standard, certified by accredited audit.
CMMC Level 2

110 practices and 320 assessment objectives across 14 domains, mirroring NIST SP 800-171 Rev 2. The DoD final rule (32 CFR Part 170, effective December 2024; the DFARS acquisition rule, effective November 2025) is phasing it into contracts, affecting roughly 337,000 Defense Industrial Base entities.

Evidenced through the 800-171-aligned checksMandatory for U.S. DoD contractors handling Controlled Unclassified Information.
Essential Eight (Australia)

Eight mitigation strategies (application control, patch applications, Office macro settings, user application hardening, restrict admin privileges, patch operating systems, multi-factor authentication, regular backups) across Maturity Levels Zero to Three.

Evidenced through the identity, patch, and device checksMandatory for Australian non-corporate Commonwealth entities (to Maturity Level Two).
UK Cyber Essentials

Five technical controls: firewalls, secure configuration, security update management, user access control, and malware protection. Over 33,000 certificates were issued in 2024.

Evidenced through the configuration and identity checksRequired for certain UK central government contracts.
PCI DSS 4.0

12 core requirements across six goals for protecting cardholder data.

Relevant where Microsoft 365 is part of the cardholder data environmentContractual mandate from the card brands for any entity that stores, processes, or transmits cardholder data.
FedRAMP

Low, Moderate, and High authorization baselines drawn from NIST SP 800-53 Rev 5. Relevant to Microsoft 365 GCC and GCC High.

Evidenced through the 800-53-aligned checksMandatory for U.S. federal agency cloud services.

Compliance framework questions, answered

The numbers that come up most, with the authoritative source behind each one.

How many controls are in NIST 800-53?

NIST SP 800-53 Revision 5 contains over 1,000 controls and control enhancements, organized into 20 control families such as Access Control (AC), Audit and Accountability (AU), and Identification and Authentication (IA). It is mandatory for U.S. federal systems under FISMA and is the control catalog behind FedRAMP.

How many ISO 27001 Annex A controls are there?

ISO/IEC 27001:2022 has 93 Annex A controls, down from 114 in the 2013 edition, grouped into four themes: Organizational (37), People (8), Physical (14), and Technological (34). ISO 27001 is the leading international standard for an Information Security Management System.

How many CMMC Level 2 practices are there?

CMMC Level 2 has 110 practices, assessed against 320 objectives across 14 domains, mirroring NIST SP 800-171 Revision 2 exactly. It is mandatory for U.S. Department of Defense contractors that handle Controlled Unclassified Information, phasing into contracts through the DoD final rule.

How many CIS Controls are there?

The CIS Critical Security Controls version 8.1 define 18 controls and 153 safeguards. The safeguards are split across three Implementation Groups: IG1 has 56, IG2 has 130, and IG3 has all 153. The separate CIS Microsoft 365 Foundations Benchmark adds around 140 M365-specific recommendations.

What is CISA SCuBA?

CISA SCuBA (Secure Cloud Business Applications) is a set of secure configuration baselines for the six core Microsoft 365 services: Entra ID, Exchange Online, SharePoint and OneDrive, Teams, Defender for Office 365, and Power Platform. Binding Operational Directive 25-01 directs U.S. federal civilian agencies to apply them.

What are the SOC 2 Trust Services Criteria?

SOC 2 has five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security (the Common Criteria) is mandatory in every SOC 2 report; the other four are included only when relevant. SOC 2 defines criteria, not a fixed control list, so the auditor tests the controls you map to them.

Does Microsoft 365 meet CMMC or NIST 800-171?

Microsoft 365 can provide the technical controls behind many of the 110 NIST 800-171 and CMMC Level 2 requirements, but no product makes a tenant compliant on its own. Compliance depends on how identity, device, logging, and data-protection settings are configured, which is what Senserva checks and evidences.

Take this crosswalk to your AI

Copy it into Claude, ChatGPT, or Copilot to pick a framework and plan the work. Free, no sign-in.

From mapping to evidence to fixed

A crosswalk on paper is a start. Senserva runs the checks against your tenant, ranks the gaps by real-world risk, and generates validated, approve-before-apply remediation, so the next scan proves the control is in place. That is what turns a framework into a defensible posture.

Scan your tenant free Browse the 672 checks

Explore the AI Enhanced suite

Agentic AI for Microsoft 365 security, end to end. Each piece works with the AI of your choice.

Works with any AIChatGPT, Claude, Gemini, Copilot, or a local model, with a built-in prompt builder. Claude & MCPRun Microsoft 365 security agentically from Claude through the Senserva MCP. AI security reportsSix AI-enhanced report types generated from one scan. AI remediationValidated, approve-before-apply fixes for every finding. AI complianceMap and close gaps against CISA SCuBA, MCSB, and more.

See the live Microsoft CVE and patch hot list: a free live list of the hottest Microsoft CVEs and patches, updated several times a day. Bookmark it and check back.

Senserva
Three Free Unlimited Audits
1 scan to find, 2 to review your fixes.
Setup and running in minutes. Your data stays local, in a results database only you hold.
Everything Siemserva by Senserva does: every missing patch ranked by real attacks, all 650+ security checks, and full reports.
All users · All settings · All patches · All tenants
Includes our advanced Claude MCP: everything you need to run full audits.

Free registration is all it takes, no card. Want it always on? Summer Special: unlimited use, up to 50 tenants, $600/mo or $6,500/yr.