Compliance / By country
Microsoft 365 compliance by country and framework
Security frameworks differ by country, but they converge on the same Microsoft 365 and Entra ID controls: multi-factor authentication, Conditional Access, privileged access, and logging. This page maps the national and international frameworks customers ask about to the Senserva checks that evidence them, so one scan supports many obligations.
Each framework page is informational: what the framework is, its official reference, and how Siemserva maps to it. Senserva provides configuration evidence and remediation, not certification. For the control-by-control view, see the frameworks crosswalk and the control reference.
Global benchmarks
- CIS Microsoft 365 Foundations BenchmarkThe CIS Microsoft 365 Foundations Benchmark is the consensus, prescriptive hardening baseline for a Microsoft 365 tenant.
European Union
- NIS2 DirectiveThe EU-wide cyber resilience law (2024) with binding MFA, access-control, and incident-reporting duties.
- Digital Operational Resilience ActICT risk-management and third-party oversight rules for EU financial entities.
Germany
- BSI IT-GrundschutzGermany's BSI security methodology; the ORP.4, OPS.1.1.5, and DER.1 building blocks map to Entra and M365.
- BSI C5 (Cloud Computing Compliance Criteria Catalogue)Germany's cloud attestation catalogue, often required in cloud procurement.
France
- ANSSI SecNumCloudFrance's qualification standard for trusted cloud providers.
Netherlands
- BIO (Baseline Informatiebeveiliging Overheid)The Dutch government information-security baseline.
Belgium
- CyFun (Cyber Fundamentals Framework)Belgium's tiered Basic / Important / Essential framework, referenced for NIS2.
Switzerland
- FINMA Circular 2018/3 (Outsourcing)Swiss financial-sector outsourcing and access-control oversight.
Austria
- NISG (Network and Information System Security Act)Austria's transposition of NIS2 into national law.
Spain
- ENS (Esquema Nacional de Seguridad)Spain's national security framework, mandatory for the public sector.
Italy
- ACN Perimetro di Sicurezza Nazionale CiberneticaItaly's national cybersecurity perimeter for critical entities.
Portugal
- CNCS guidelinesPortugal's national cybersecurity center guidance, aligned to NIS2.
United Kingdom
- NCSC Cyber Assessment Framework (CAF)The UK's outcome-based framework for critical infrastructure and public-sector resilience.
- Cyber Essentials and Cyber Essentials PlusThe UK government-backed baseline certification, common in public-sector and supply-chain contracts.
United States
- NIST SP 800-53The US federal control catalog; already in Senserva's reference set.
- NIST Cybersecurity Framework (CSF)The widely adopted voluntary framework; Identify / Protect / Detect map to M365 findings.
- Cybersecurity Maturity Model Certification (CMMC)Required for US DoD contractors; access control and audit logging overlap with M365.
- SOC 2The common SaaS attestation; access control and monitoring overlap with M365.
Canada
- ITSG-33 (Canadian Centre for Cyber Security)Canada's federal IT security risk-management framework; parallels NIST 800-53.
Australia and New Zealand
- ACSC Essential EightThe ACSC's prioritized eight mitigations; MFA and admin-privilege restriction map to core findings.
- Australian Government Information Security Manual (ISM)Australia's broader government security manual, heavily referenced in public-sector deals.
- New Zealand Information Security Manual (NZISM)New Zealand government's information-security manual.
Looking for a specific control? The control reference maps every MCSB control and CISA SCuBA policy to the checks that evidence it.