Compliance

Compliance evidence aggregator

How ITDR turns Microsoft 365 posture findings into auditor-ready compliance evidence across CIS, ISO 27001, HIPAA, CMMC, and CIS IG1.

Updated May 26, 2026 | 7 min

What this does

  • Subscribes each tenant to one or more compliance frameworks (CIS M365, ISO 27001, HIPAA, CMMC L1, CIS IG1).
  • Maps every posture finding to one or more controls — automatically for frameworks that ship with built-in compliance metadata, and via a curated map for the rest.
  • Reconciles per-control evidence nightly: each control is marked Met / Gap / N/A / Pending.
  • Generates an auditor-ready PDF audit package on demand, with control-by-control evidence and linked open findings.
  • Surfaces a cross-client coverage rollup so an MSP can see every tenant's coverage at a glance.

Frameworks at launch

  • CIS Microsoft 365 Foundations Benchmark v6.0Auto-mappedVendor-specific hardening guide. Controls auto-populated from the posture scanner's built-in compliance metadata.
  • CIS Microsoft 365 Foundations Benchmark v4.0Auto-mappedOlder benchmark retained for clients still mid-migration.
  • ISO/IEC 27001:2022 Annex A (identity-and-access subset)Auto-mappedAuto-populated from the scanner's ISO27001-2022 compliance metadata.
  • HIPAA Security Rule (45 CFR §164.302-318)Curated mapCurated check → standard mapping. ~30 mappings at launch.
  • CMMC Level 1 (foundational, v2.0)Curated mapCurated mapping covering 17 CMMC L1 practices.
  • CIS Critical Security Controls v8 — IG1Curated mapGeneric SMB baseline. ~30 mappings at launch.

Tier explainer

  • Auto-mapped: Control catalog is populated from the M365 posture scanner's built-in compliance metadata. Each finding already carries the framework/control identifiers — we just normalize them. Zero curation effort per finding.
  • Curated map: We curate a check → control mapping in JSON. A single posture finding can contribute evidence to multiple regulated frameworks (e.g. "admin users without MFA" → HIPAA §164.308(a)(5)(ii)(D) + CMMC IA.L1-3.5.2 + CIS IG1 6.5).
  • Custom: Reserved for tenant-authored frameworks in a future release. Not yet exposed in the UI.

Control status values

  • MetNo open posture findings linked to the control. Considered in compliance.
  • GapOne or more open findings linked. Remediation recommended.
  • N/AOperator-set: control not applicable to this tenant. Preserved across reconciliations.
  • PendingNo signal has been observed yet. Reconciliation has not seen any findings reference this control.

How to start

  1. Open /compliance and pick a framework to Subscribe.
  2. Wait for the next M365 posture scan cycle (every 6h) — or hit "Re-reconcile now" on the framework page to force-update the evidence state immediately if there is already finding data in the tenant.
  3. Open a control with status Gap to see the linked open posture findings.
  4. Optionally upload manual attestation (a vendor letter, a screenshot of a setting) for controls that require operator-attested evidence.
  5. Generate an audit package PDF when ready — coverage % and per-control evidence are baked into the package.

Current limits

  • Tier-2 frameworks (HIPAA, CMMC L1, CIS IG1) ship with intentionally sparse mappings at launch (~17-30 entries each). Add more entries to check_to_control_map.json to grow coverage.
  • RMM, backup, and LMS integrations are not yet in scope. Manual attestation handles those controls until those integrations land.
  • Reconciliation runs nightly (24h). Click Re-reconcile now on a framework drill page to refresh on demand.
  • PDF audit packages store bytes inline in the database. Future versions will externalize to the S3 archive.