Compliance
Compliance evidence aggregator
How ITDR turns Microsoft 365 posture findings into auditor-ready compliance evidence across CIS, ISO 27001, HIPAA, CMMC, and CIS IG1.
Updated May 26, 2026 | 7 min
What this does
- Subscribes each tenant to one or more compliance frameworks (CIS M365, ISO 27001, HIPAA, CMMC L1, CIS IG1).
- Maps every posture finding to one or more controls — automatically for frameworks that ship with built-in compliance metadata, and via a curated map for the rest.
- Reconciles per-control evidence nightly: each control is marked Met / Gap / N/A / Pending.
- Generates an auditor-ready PDF audit package on demand, with control-by-control evidence and linked open findings.
- Surfaces a cross-client coverage rollup so an MSP can see every tenant's coverage at a glance.
Frameworks at launch
- CIS Microsoft 365 Foundations Benchmark v6.0 — Auto-mapped — Vendor-specific hardening guide. Controls auto-populated from the posture scanner's built-in compliance metadata.
- CIS Microsoft 365 Foundations Benchmark v4.0 — Auto-mapped — Older benchmark retained for clients still mid-migration.
- ISO/IEC 27001:2022 Annex A (identity-and-access subset) — Auto-mapped — Auto-populated from the scanner's ISO27001-2022 compliance metadata.
- HIPAA Security Rule (45 CFR §164.302-318) — Curated map — Curated check → standard mapping. ~30 mappings at launch.
- CMMC Level 1 (foundational, v2.0) — Curated map — Curated mapping covering 17 CMMC L1 practices.
- CIS Critical Security Controls v8 — IG1 — Curated map — Generic SMB baseline. ~30 mappings at launch.
Tier explainer
- Auto-mapped: Control catalog is populated from the M365 posture scanner's built-in compliance metadata. Each finding already carries the framework/control identifiers — we just normalize them. Zero curation effort per finding.
- Curated map: We curate a check → control mapping in JSON. A single posture finding can contribute evidence to multiple regulated frameworks (e.g. "admin users without MFA" → HIPAA §164.308(a)(5)(ii)(D) + CMMC IA.L1-3.5.2 + CIS IG1 6.5).
- Custom: Reserved for tenant-authored frameworks in a future release. Not yet exposed in the UI.
Control status values
- Met — No open posture findings linked to the control. Considered in compliance.
- Gap — One or more open findings linked. Remediation recommended.
- N/A — Operator-set: control not applicable to this tenant. Preserved across reconciliations.
- Pending — No signal has been observed yet. Reconciliation has not seen any findings reference this control.
How to start
- Open /compliance and pick a framework to Subscribe.
- Wait for the next M365 posture scan cycle (every 6h) — or hit "Re-reconcile now" on the framework page to force-update the evidence state immediately if there is already finding data in the tenant.
- Open a control with status Gap to see the linked open posture findings.
- Optionally upload manual attestation (a vendor letter, a screenshot of a setting) for controls that require operator-attested evidence.
- Generate an audit package PDF when ready — coverage % and per-control evidence are baked into the package.
Current limits
- Tier-2 frameworks (HIPAA, CMMC L1, CIS IG1) ship with intentionally sparse mappings at launch (~17-30 entries each). Add more entries to check_to_control_map.json to grow coverage.
- RMM, backup, and LMS integrations are not yet in scope. Manual attestation handles those controls until those integrations land.
- Reconciliation runs nightly (24h). Click Re-reconcile now on a framework drill page to refresh on demand.
- PDF audit packages store bytes inline in the database. Future versions will externalize to the S3 archive.