Compliance
Compliance framework coverage
Per-control breakdown for all 6 supported frameworks: which controls auto-reconcile from posture findings and which always need a manual attestation. Auditor- and partner-facing one-pager.
Updated May 28, 2026 | 10 min
How coverage works
Each framework in the catalog is a curated subset of the official framework — every catalog control was selected because ITDR can speak to it. There are two ways a control gets reconciled to evidence:
- Tier 1 — Auto-mapped. The M365 posture scanner ships compliance metadata with each check, listing the frameworks and control IDs it covers. We read that directly. Frameworks: CIS M365 v4, CIS M365 v6, ISO 27001:2022. Every catalog control is auto-reconciled.
- Tier 2 — Curated map. Frameworks the scanner doesn't pre-tag use a hand-maintained mapping that links each posture check to the right control. Frameworks: HIPAA Security Rule, CMMC Level 1, CIS Controls IG1. Coverage is sparser — controls without a mapping always show pending in the UI until an operator adds a manual attestation.
In both tiers, the per-control status is one of:
- met — finding linked, none currently open
- gap — at least one open finding linked
- pending — no signal ever linked (either no scan has run, or the control requires manual attestation)
- n/a — operator marked this control not applicable; reconciliation never overwrites
Coverage at a glance
Tier 1
CIS Microsoft 365 Foundations Benchmark
v6.0
21 / 21
100% auto-reconciled
Tier 1
CIS Microsoft 365 Foundations Benchmark
v4.0
16 / 16
100% auto-reconciled
Tier 1
ISO/IEC 27001:2022 — Annex A
v2022
18 / 18
100% auto-reconciled
Tier 2
HIPAA Security Rule
v45 CFR §164.302-318
15 / 17
88% auto-reconciled
Tier 2
CMMC Level 1 (Foundational)
v2.0
8 / 17
47% auto-reconciled
Tier 2
CIS Critical Security Controls v8 — IG1
v8.1
10 / 17
59% auto-reconciled
Across all 6 frameworks: 88 controls auto-reconcile from posture findings, 18 always need a manual attestation.
CIS Microsoft 365 Foundations Benchmark
Version 6.0
Every catalog control here was selected because the M365 posture scanner runs a check that maps to it. Subscribing a tenant produces evidence for all 21 controls automatically — no curation needed.
| Coverage | Control ID | Title | Note |
|---|---|---|---|
| Auto | 1.1.3 | Ensure a Multi-tenant Administrator account is used | |
| Auto | 1.1.4 | Ensure Global Administrators have separate dedicated accounts | |
| Auto | 1.2.1 | Ensure no users have administrative privileges with low Authentication strength | |
| Auto | 5.1.2.1 | Ensure Per-User MFA is disabled in favor of Conditional Access | |
| Auto | 5.1.2.3 | Ensure Restricted User Settings are applied | |
| Auto | 5.1.2.4 | Ensure User can register applications is set to No | |
| Auto | 5.1.2.5 | Ensure Guest user access is restricted | |
| Auto | 5.1.5.2 | Ensure risky sign-in detection reviews are configured | |
| Auto | 5.1.8.1 | Ensure user consent to apps accessing company data is allowed for verified publishers | |
| Auto | 5.2.2.2 | Ensure password protection is configured for Active Directory | |
| Auto | 5.2.2.3 | Ensure SSPR is enabled | |
| Auto | 5.2.3.1 | Ensure SMS and Voice MFA is disabled | |
| Auto | 5.2.3.4 | Ensure phishing-resistant MFA is enforced for administrators | |
| Auto | 5.2.4.1 | Ensure sign-in frequency is configured for admin roles | |
| Auto | 5.2.4.2 | Ensure persistent browser sessions are disabled | |
| Auto | 6.1.2 | Ensure mailbox auditing is enabled for all users | |
| Auto | 6.5.1 | Ensure modern authentication for Exchange Online is enabled | |
| Auto | 6.5.2 | Ensure MailTips are enabled for end users | |
| Auto | 7.2.5 | Ensure SharePoint Online external sharing is restricted | |
| Auto | 8.1.1 | Ensure external file sharing in Teams is configured | |
| Auto | 8.5.1 | Ensure anonymous users cannot join Teams meetings |
CIS Microsoft 365 Foundations Benchmark
Version 4.0
Older CIS M365 version retained for tenants that already audit against v4. Same auto-coverage model as v6 — all controls reconcile from M365 posture findings.
| Coverage | Control ID | Title | Note |
|---|---|---|---|
| Auto | 1.1.1 | Ensure Multi-tenant Administrator account is used | |
| Auto | 1.1.2 | Ensure Global Administrators have separate dedicated accounts | |
| Auto | 1.1.3 | Ensure no users have administrative privileges with low Authentication strength | |
| Auto | 1.1.4 | Ensure self-service password reset is enabled | |
| Auto | 1.3.1 | Ensure Security Defaults are enabled (or Conditional Access equivalent) | |
| Auto | 1.3.2 | Ensure phishing-resistant MFA is enforced for administrators | |
| Auto | 1.3.3 | Ensure modern authentication is enabled | |
| Auto | 1.3.6 | Ensure legacy authentication is blocked | |
| Auto | 2.1.1 | Ensure mailbox auditing is enabled | |
| Auto | 2.1.2 | Ensure external forwarding is disabled | |
| Auto | 2.1.4 | Ensure Common Attachment Types filter is enabled | |
| Auto | 5.1.1 | Ensure SharePoint external sharing is restricted | |
| Auto | 5.1.2 | Ensure SharePoint user-driven sharing is limited | |
| Auto | 6.1.1 | Ensure Teams external access is configured | |
| Auto | 6.1.2 | Ensure Teams guest access is restricted | |
| Auto | 7.1.1 | Ensure anonymous Teams meeting joins are disabled |
ISO/IEC 27001:2022 — Annex A
Version 2022
ISO 27001 Annex A has 93 controls officially. We ship the 18 that the M365 posture scanner produces evidence for. Other Annex A controls (physical security, supplier relationships, etc.) need manual attestation if you need full ISO 27001 coverage.
| Coverage | Control ID | Title | Note |
|---|---|---|---|
| Auto | A.5.15 | Access control | |
| Auto | A.5.16 | Identity management | |
| Auto | A.5.17 | Authentication information | |
| Auto | A.5.18 | Access rights | |
| Auto | A.5.23 | Information security for use of cloud services | |
| Auto | A.5.25 | Assessment and decision on information security events | |
| Auto | A.5.26 | Response to information security incidents | |
| Auto | A.5.27 | Learning from information security incidents | |
| Auto | A.5.28 | Collection of evidence | |
| Auto | A.5.29 | Information security during disruption | |
| Auto | A.8.2 | Privileged access rights | |
| Auto | A.8.3 | Information access restriction | |
| Auto | A.8.5 | Secure authentication | |
| Auto | A.8.7 | Protection against malware | |
| Auto | A.8.15 | Logging | |
| Auto | A.8.16 | Monitoring activities | |
| Auto | A.8.22 | Segregation of networks | |
| Auto | A.8.23 | Web filtering |
HIPAA Security Rule
Version 45 CFR §164.302-318
Curated mapping covers administrative safeguards (§164.308) and technical safeguards (§164.312). Physical safeguards (§164.310) are intentionally excluded because ITDR has no signal for facility access or workstation use. 15 of 17 controls auto-reconcile; 2 always require attestation.
| Coverage | Control ID | Title | Note |
|---|---|---|---|
| Auto | §164.308(a)(1)(i) | Security Management Process | |
| Auto | §164.308(a)(1)(ii)(D) | Information System Activity Review | |
| Auto | §164.308(a)(3)(i) | Workforce Security | |
| Manual | §164.308(a)(3)(ii)(C) | Termination Procedures | HR/IT offboarding runbook — process control. Upload your termination procedure. |
| Auto | §164.308(a)(4)(i) | Information Access Management | |
| Auto | §164.308(a)(4)(ii)(B) | Access Authorization | |
| Auto | §164.308(a)(4)(ii)(C) | Access Establishment and Modification | |
| Auto | §164.308(a)(5)(ii)(C) | Log-in Monitoring | |
| Auto | §164.308(a)(5)(ii)(D) | Password Management | |
| Auto | §164.308(a)(6)(i) | Security Incident Procedures | |
| Auto | §164.312(a)(1) | Access Control | |
| Manual | §164.312(a)(2)(i) | Unique User Identification | M365 enforces unique UPNs; attest that the policy is documented. |
| Auto | §164.312(a)(2)(iii) | Automatic Logoff | |
| Auto | §164.312(b) | Audit Controls | |
| Auto | §164.312(c)(1) | Integrity | |
| Auto | §164.312(d) | Person or Entity Authentication | |
| Auto | §164.312(e)(1) | Transmission Security |
CMMC Level 1 (Foundational)
Version 2.0
CMMC L1 has 17 practices total. 8 auto-reconcile (access control, authentication, boundary, malware). 9 always need attestation — mostly physical (PE.*) and media handling, plus a few process controls. CMMC L1 self-assessment expects every practice to have evidence even when ITDR can't see it, so plan to attach manual attestations for the manual rows below.
| Coverage | Control ID | Title | Note |
|---|---|---|---|
| Auto | AC.L1-3.1.1 | Authorized Access Control | |
| Auto | AC.L1-3.1.2 | Transaction & Function Control | |
| Auto | AC.L1-3.1.20 | External Connections | |
| Manual | AC.L1-3.1.22 | Control Public Information | Policy + content review — outside the platform. |
| Manual | IA.L1-3.5.1 | Identification | M365 assigns unique UPNs; attest that account-issuance policy is documented. |
| Auto | IA.L1-3.5.2 | Authentication | |
| Manual | MP.L1-3.8.3 | Media Disposal | Physical / device disposal procedure — outside ITDR scope. |
| Manual | PE.L1-3.10.1 | Limit Physical Access | Facility access control — outside ITDR scope. |
| Manual | PE.L1-3.10.3 | Escort Visitors | Facility procedure — outside ITDR scope. |
| Manual | PE.L1-3.10.4 | Physical Access Logs | Facility log — outside ITDR scope. |
| Manual | PE.L1-3.10.5 | Manage Physical Access | Facility access management — outside ITDR scope. |
| Auto | SC.L1-3.13.1 | Boundary Protection | |
| Auto | SC.L1-3.13.5 | Public-Access System Separation | |
| Manual | SI.L1-3.14.1 | Flaw Remediation | Endpoint patching — typically RMM-resident, not ITDR. |
| Auto | SI.L1-3.14.2 | Malicious Code Protection | |
| Manual | SI.L1-3.14.4 | Update Malicious Code Protection | Antivirus update cadence — typically RMM-resident. |
| Auto | SI.L1-3.14.5 | System & File Scanning |
CIS Critical Security Controls v8 — IG1
Version 8.1
IG1 (Implementation Group 1) is the 56-safeguard small-business baseline. We map the 17 most identity- and M365-resident safeguards. 10 auto-reconcile; 7 need attestation — mostly inventory, log retention, and security awareness program docs.
| Coverage | Control ID | Title | Note |
|---|---|---|---|
| Manual | 5.1 | Establish and Maintain an Inventory of Accounts | Account inventory export — combine with the /identities page. |
| Auto | 5.2 | Use Unique Passwords | |
| Manual | 5.3 | Disable Dormant Accounts | Dormant-account review procedure — attach your offboarding cadence document. |
| Auto | 5.4 | Restrict Administrator Privileges to Dedicated Administrator Accounts | |
| Auto | 6.1 | Establish an Access Granting Process | |
| Manual | 6.2 | Establish an Access Revoking Process | Process control — attach your access-revocation runbook. |
| Auto | 6.3 | Require MFA for Externally-Exposed Applications | |
| Auto | 6.4 | Require MFA for Remote Network Access | |
| Auto | 6.5 | Require MFA for Administrative Access | |
| Auto | 8.1 | Establish and Maintain an Audit Log Management Process | |
| Manual | 8.2 | Collect Audit Logs | Log-collection policy — attach your retention SOP. |
| Manual | 8.3 | Ensure Adequate Audit Log Storage | Storage capacity attestation — outside ITDR scope. |
| Auto | 9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | |
| Auto | 10.1 | Deploy and Maintain Anti-Malware Software | |
| Manual | 14.1 | Establish and Maintain a Security Awareness Program | LMS / training program attestation — outside ITDR scope. |
| Auto | 17.1 | Designate Personnel to Manage Incident Handling | |
| Manual | 17.2 | Establish and Maintain Contact Information for Reporting | Roster + contact policy — attach your IR contact sheet. |
Working with manual controls
- Open the framework page at
/compliance/frameworks/<framework>and click into any control showing pending. - Use the "Add manual attestation" form to upload a short justification, a policy document reference, or a vendor letter. The attestation is permanent until removed and never overwritten by the nightly reconciler.
- For controls that genuinely don't apply to the tenant, set n/a instead of leaving them as pending — the audit package PDF distinguishes the two.
- Re-reconcile after attestation to refresh the framework summary and the coverage % shown on the dashboard.
What this is not
- This isn't a full GRC platform. We don't track risk registers, control ownership assignments, or audit due dates — that's Vanta/Drata territory. Use the audit-package PDF as an evidence dossier, not a workflow tool.
- An "auto" status only means we don't see open posture findings — it isn't a positive attestation that your written policy exists. For high-stakes audits, expect to attach a policy attestation on top of the automated evidence.
- The mappings are opinionated. If your auditor expects a different check-to-control mapping, the manual attestation form on the per-control page is the override path.