Compliance

Compliance framework coverage

Per-control breakdown for all 6 supported frameworks: which controls auto-reconcile from posture findings and which always need a manual attestation. Auditor- and partner-facing one-pager.

Updated May 28, 2026 | 10 min

How coverage works

Each framework in the catalog is a curated subset of the official framework — every catalog control was selected because ITDR can speak to it. There are two ways a control gets reconciled to evidence:

  • Tier 1 — Auto-mapped. The M365 posture scanner ships compliance metadata with each check, listing the frameworks and control IDs it covers. We read that directly. Frameworks: CIS M365 v4, CIS M365 v6, ISO 27001:2022. Every catalog control is auto-reconciled.
  • Tier 2 — Curated map. Frameworks the scanner doesn't pre-tag use a hand-maintained mapping that links each posture check to the right control. Frameworks: HIPAA Security Rule, CMMC Level 1, CIS Controls IG1. Coverage is sparser — controls without a mapping always show pending in the UI until an operator adds a manual attestation.

In both tiers, the per-control status is one of:

  • met — finding linked, none currently open
  • gap — at least one open finding linked
  • pending — no signal ever linked (either no scan has run, or the control requires manual attestation)
  • n/a — operator marked this control not applicable; reconciliation never overwrites

Coverage at a glance

Tier 1

CIS Microsoft 365 Foundations Benchmark

v6.0

21 / 21

100% auto-reconciled

Tier 1

CIS Microsoft 365 Foundations Benchmark

v4.0

16 / 16

100% auto-reconciled

Tier 1

ISO/IEC 27001:2022 — Annex A

v2022

18 / 18

100% auto-reconciled

Tier 2

HIPAA Security Rule

v45 CFR §164.302-318

15 / 17

88% auto-reconciled

Tier 2

CMMC Level 1 (Foundational)

v2.0

8 / 17

47% auto-reconciled

Tier 2

CIS Critical Security Controls v8 — IG1

v8.1

10 / 17

59% auto-reconciled

Across all 6 frameworks: 88 controls auto-reconcile from posture findings, 18 always need a manual attestation.

CIS Microsoft 365 Foundations Benchmark

Version 6.0

Tier 1 — Auto-mapped21 auto · 21 total

Every catalog control here was selected because the M365 posture scanner runs a check that maps to it. Subscribing a tenant produces evidence for all 21 controls automatically — no curation needed.

CoverageControl IDTitleNote
Auto1.1.3Ensure a Multi-tenant Administrator account is used
Auto1.1.4Ensure Global Administrators have separate dedicated accounts
Auto1.2.1Ensure no users have administrative privileges with low Authentication strength
Auto5.1.2.1Ensure Per-User MFA is disabled in favor of Conditional Access
Auto5.1.2.3Ensure Restricted User Settings are applied
Auto5.1.2.4Ensure User can register applications is set to No
Auto5.1.2.5Ensure Guest user access is restricted
Auto5.1.5.2Ensure risky sign-in detection reviews are configured
Auto5.1.8.1Ensure user consent to apps accessing company data is allowed for verified publishers
Auto5.2.2.2Ensure password protection is configured for Active Directory
Auto5.2.2.3Ensure SSPR is enabled
Auto5.2.3.1Ensure SMS and Voice MFA is disabled
Auto5.2.3.4Ensure phishing-resistant MFA is enforced for administrators
Auto5.2.4.1Ensure sign-in frequency is configured for admin roles
Auto5.2.4.2Ensure persistent browser sessions are disabled
Auto6.1.2Ensure mailbox auditing is enabled for all users
Auto6.5.1Ensure modern authentication for Exchange Online is enabled
Auto6.5.2Ensure MailTips are enabled for end users
Auto7.2.5Ensure SharePoint Online external sharing is restricted
Auto8.1.1Ensure external file sharing in Teams is configured
Auto8.5.1Ensure anonymous users cannot join Teams meetings

CIS Microsoft 365 Foundations Benchmark

Version 4.0

Tier 1 — Auto-mapped16 auto · 16 total

Older CIS M365 version retained for tenants that already audit against v4. Same auto-coverage model as v6 — all controls reconcile from M365 posture findings.

CoverageControl IDTitleNote
Auto1.1.1Ensure Multi-tenant Administrator account is used
Auto1.1.2Ensure Global Administrators have separate dedicated accounts
Auto1.1.3Ensure no users have administrative privileges with low Authentication strength
Auto1.1.4Ensure self-service password reset is enabled
Auto1.3.1Ensure Security Defaults are enabled (or Conditional Access equivalent)
Auto1.3.2Ensure phishing-resistant MFA is enforced for administrators
Auto1.3.3Ensure modern authentication is enabled
Auto1.3.6Ensure legacy authentication is blocked
Auto2.1.1Ensure mailbox auditing is enabled
Auto2.1.2Ensure external forwarding is disabled
Auto2.1.4Ensure Common Attachment Types filter is enabled
Auto5.1.1Ensure SharePoint external sharing is restricted
Auto5.1.2Ensure SharePoint user-driven sharing is limited
Auto6.1.1Ensure Teams external access is configured
Auto6.1.2Ensure Teams guest access is restricted
Auto7.1.1Ensure anonymous Teams meeting joins are disabled

ISO/IEC 27001:2022 — Annex A

Version 2022

Tier 1 — Auto-mapped18 auto · 18 total

ISO 27001 Annex A has 93 controls officially. We ship the 18 that the M365 posture scanner produces evidence for. Other Annex A controls (physical security, supplier relationships, etc.) need manual attestation if you need full ISO 27001 coverage.

CoverageControl IDTitleNote
AutoA.5.15Access control
AutoA.5.16Identity management
AutoA.5.17Authentication information
AutoA.5.18Access rights
AutoA.5.23Information security for use of cloud services
AutoA.5.25Assessment and decision on information security events
AutoA.5.26Response to information security incidents
AutoA.5.27Learning from information security incidents
AutoA.5.28Collection of evidence
AutoA.5.29Information security during disruption
AutoA.8.2Privileged access rights
AutoA.8.3Information access restriction
AutoA.8.5Secure authentication
AutoA.8.7Protection against malware
AutoA.8.15Logging
AutoA.8.16Monitoring activities
AutoA.8.22Segregation of networks
AutoA.8.23Web filtering

HIPAA Security Rule

Version 45 CFR §164.302-318

Tier 2 — Curated map15 auto · 2 manual · 17 total

Curated mapping covers administrative safeguards (§164.308) and technical safeguards (§164.312). Physical safeguards (§164.310) are intentionally excluded because ITDR has no signal for facility access or workstation use. 15 of 17 controls auto-reconcile; 2 always require attestation.

CoverageControl IDTitleNote
Auto§164.308(a)(1)(i)Security Management Process
Auto§164.308(a)(1)(ii)(D)Information System Activity Review
Auto§164.308(a)(3)(i)Workforce Security
Manual§164.308(a)(3)(ii)(C)Termination ProceduresHR/IT offboarding runbook — process control. Upload your termination procedure.
Auto§164.308(a)(4)(i)Information Access Management
Auto§164.308(a)(4)(ii)(B)Access Authorization
Auto§164.308(a)(4)(ii)(C)Access Establishment and Modification
Auto§164.308(a)(5)(ii)(C)Log-in Monitoring
Auto§164.308(a)(5)(ii)(D)Password Management
Auto§164.308(a)(6)(i)Security Incident Procedures
Auto§164.312(a)(1)Access Control
Manual§164.312(a)(2)(i)Unique User IdentificationM365 enforces unique UPNs; attest that the policy is documented.
Auto§164.312(a)(2)(iii)Automatic Logoff
Auto§164.312(b)Audit Controls
Auto§164.312(c)(1)Integrity
Auto§164.312(d)Person or Entity Authentication
Auto§164.312(e)(1)Transmission Security

CMMC Level 1 (Foundational)

Version 2.0

Tier 2 — Curated map8 auto · 9 manual · 17 total

CMMC L1 has 17 practices total. 8 auto-reconcile (access control, authentication, boundary, malware). 9 always need attestation — mostly physical (PE.*) and media handling, plus a few process controls. CMMC L1 self-assessment expects every practice to have evidence even when ITDR can't see it, so plan to attach manual attestations for the manual rows below.

CoverageControl IDTitleNote
AutoAC.L1-3.1.1Authorized Access Control
AutoAC.L1-3.1.2Transaction & Function Control
AutoAC.L1-3.1.20External Connections
ManualAC.L1-3.1.22Control Public InformationPolicy + content review — outside the platform.
ManualIA.L1-3.5.1IdentificationM365 assigns unique UPNs; attest that account-issuance policy is documented.
AutoIA.L1-3.5.2Authentication
ManualMP.L1-3.8.3Media DisposalPhysical / device disposal procedure — outside ITDR scope.
ManualPE.L1-3.10.1Limit Physical AccessFacility access control — outside ITDR scope.
ManualPE.L1-3.10.3Escort VisitorsFacility procedure — outside ITDR scope.
ManualPE.L1-3.10.4Physical Access LogsFacility log — outside ITDR scope.
ManualPE.L1-3.10.5Manage Physical AccessFacility access management — outside ITDR scope.
AutoSC.L1-3.13.1Boundary Protection
AutoSC.L1-3.13.5Public-Access System Separation
ManualSI.L1-3.14.1Flaw RemediationEndpoint patching — typically RMM-resident, not ITDR.
AutoSI.L1-3.14.2Malicious Code Protection
ManualSI.L1-3.14.4Update Malicious Code ProtectionAntivirus update cadence — typically RMM-resident.
AutoSI.L1-3.14.5System & File Scanning

CIS Critical Security Controls v8 — IG1

Version 8.1

Tier 2 — Curated map10 auto · 7 manual · 17 total

IG1 (Implementation Group 1) is the 56-safeguard small-business baseline. We map the 17 most identity- and M365-resident safeguards. 10 auto-reconcile; 7 need attestation — mostly inventory, log retention, and security awareness program docs.

CoverageControl IDTitleNote
Manual5.1Establish and Maintain an Inventory of AccountsAccount inventory export — combine with the /identities page.
Auto5.2Use Unique Passwords
Manual5.3Disable Dormant AccountsDormant-account review procedure — attach your offboarding cadence document.
Auto5.4Restrict Administrator Privileges to Dedicated Administrator Accounts
Auto6.1Establish an Access Granting Process
Manual6.2Establish an Access Revoking ProcessProcess control — attach your access-revocation runbook.
Auto6.3Require MFA for Externally-Exposed Applications
Auto6.4Require MFA for Remote Network Access
Auto6.5Require MFA for Administrative Access
Auto8.1Establish and Maintain an Audit Log Management Process
Manual8.2Collect Audit LogsLog-collection policy — attach your retention SOP.
Manual8.3Ensure Adequate Audit Log StorageStorage capacity attestation — outside ITDR scope.
Auto9.1Ensure Use of Only Fully Supported Browsers and Email Clients
Auto10.1Deploy and Maintain Anti-Malware Software
Manual14.1Establish and Maintain a Security Awareness ProgramLMS / training program attestation — outside ITDR scope.
Auto17.1Designate Personnel to Manage Incident Handling
Manual17.2Establish and Maintain Contact Information for ReportingRoster + contact policy — attach your IR contact sheet.

Working with manual controls

  • Open the framework page at /compliance/frameworks/<framework> and click into any control showing pending.
  • Use the "Add manual attestation" form to upload a short justification, a policy document reference, or a vendor letter. The attestation is permanent until removed and never overwritten by the nightly reconciler.
  • For controls that genuinely don't apply to the tenant, set n/a instead of leaving them as pending — the audit package PDF distinguishes the two.
  • Re-reconcile after attestation to refresh the framework summary and the coverage % shown on the dashboard.

What this is not

  • This isn't a full GRC platform. We don't track risk registers, control ownership assignments, or audit due dates — that's Vanta/Drata territory. Use the audit-package PDF as an evidence dossier, not a workflow tool.
  • An "auto" status only means we don't see open posture findings — it isn't a positive attestation that your written policy exists. For high-stakes audits, expect to attach a policy attestation on top of the automated evidence.
  • The mappings are opinionated. If your auditor expects a different check-to-control mapping, the manual attestation form on the per-control page is the override path.