Skip to content
CIS Microsoft 365 Foundations Benchmark

The CIS Microsoft 365 Benchmark.

140 controls across 9 areas of the Microsoft 365 platform. The most widely used security benchmark for Microsoft 365, mapped to identity, data, collaboration, and device management.

140

Total controls across all levels

9

Control areas across M365

2

Assessment levels: L1 and L2

v6.0.1

Latest benchmark version

Overview

What the benchmark covers.

The CIS Microsoft 365 Foundations Benchmark is a consensus-based set of security configuration guidance developed by the Center for Internet Security. It covers the major workloads in a Microsoft 365 tenant and is updated regularly to reflect platform changes.

The benchmark has two levels. Level 1 contains 97 controls covering configurations that are widely applicable, practical to implement, and unlikely to impair normal business operation. Level 2 adds 43 advanced hardening controls for environments that require a higher security baseline or operate in regulated sectors.

97
Level 1 controls — fixed price £299
43
Level 2 additional controls
3
Licence tiers mapped per control
Coverage areas

Nine areas of Microsoft 365.

Controls are grouped across the major workload areas of the Microsoft 365 platform.

01

Account & Authentication

Password policies, MFA requirements, and account security settings in Entra ID.

02

Identity Management

Privileged role management, guest access, and identity protection policies.

03

Exchange Online

Mail transport rules, anti-phishing, DMARC, DKIM, and external mail security.

04

SharePoint Online

Sharing policies, external access, legacy authentication, and data governance.

05

OneDrive

External sharing restrictions and sync client access controls.

06

Microsoft Teams

External access, guest access, and meeting security policies.

07

Data Management & Analytics

Information protection, DLP, and sensitivity labelling configuration.

08

Auditing

Audit log configuration, retention policies, and sign-in reporting.

09

Conditional Access

Baseline Conditional Access policies for identity and device compliance.

Assessment levels

Level 1 and Level 2.

Level 1

97 controls. £299 fixed price.

Level 1 controls are widely applicable, practical, and unlikely to impair day-to-day business operation. They represent the minimum security baseline for a Microsoft 365 tenant.

This is where most organisations start. The assessment covers all 97 L1 controls and produces a compliance score, a per-control findings table, and a prioritised remediation plan.

Book Level 1 — £299
Level 2

43 additional controls.

Level 2 adds advanced hardening controls that may have a higher operational impact or require additional tooling. Recommended for environments handling sensitive data or operating in regulated sectors.

Level 2 is assessed as a supplement to Level 1. A Level 1 assessment is a prerequisite. Priced separately — get in touch for a quote.

Get a quote for Level 2
Licence coverage

Not all controls apply to every licence.

Each CIS control requires specific Microsoft 365 features to be available in the tenant. The benchmark report includes a licence gap analysis identifying which controls your current licences cover and where gaps exist. The audit covers Business Premium, E3, and E5 licence tiers.

Business Premium

Best coverage at SMB price

Business Premium covers the majority of L1 controls. A small number of identity protection controls require E5 features.

Microsoft 365 E3

Missing some Defender and PIM

E3 covers most L1 controls but lacks Defender for Identity, Priority protection, and Privileged Identity Management without add-ons.

Microsoft 365 E5

Full L1 and L2 coverage

E5 satisfies all L1 and the majority of L2 controls natively. Recommended for organisations in regulated sectors.

Every audit includes a full licence gap analysis for your specific tenant. You will know exactly which controls you cannot satisfy with your current licences before you start remediation.

Ready to assess your M365 tenant?

CIS M365 Level 1 is £299 fixed price. Book directly or get in touch to discuss scope.