The CIS Microsoft 365 Benchmark.
140 controls across 9 areas of the Microsoft 365 platform. The most widely used security benchmark for Microsoft 365, mapped to identity, data, collaboration, and device management.
140
Total controls across all levels
9
Control areas across M365
2
Assessment levels: L1 and L2
v6.0.1
Latest benchmark version
What the benchmark covers.
The CIS Microsoft 365 Foundations Benchmark is a consensus-based set of security configuration guidance developed by the Center for Internet Security. It covers the major workloads in a Microsoft 365 tenant and is updated regularly to reflect platform changes.
The benchmark has two levels. Level 1 contains 97 controls covering configurations that are widely applicable, practical to implement, and unlikely to impair normal business operation. Level 2 adds 43 advanced hardening controls for environments that require a higher security baseline or operate in regulated sectors.
Nine areas of Microsoft 365.
Controls are grouped across the major workload areas of the Microsoft 365 platform.
Account & Authentication
Password policies, MFA requirements, and account security settings in Entra ID.
Identity Management
Privileged role management, guest access, and identity protection policies.
Exchange Online
Mail transport rules, anti-phishing, DMARC, DKIM, and external mail security.
SharePoint Online
Sharing policies, external access, legacy authentication, and data governance.
OneDrive
External sharing restrictions and sync client access controls.
Microsoft Teams
External access, guest access, and meeting security policies.
Data Management & Analytics
Information protection, DLP, and sensitivity labelling configuration.
Auditing
Audit log configuration, retention policies, and sign-in reporting.
Conditional Access
Baseline Conditional Access policies for identity and device compliance.
Level 1 and Level 2.
97 controls. £299 fixed price.
Level 1 controls are widely applicable, practical, and unlikely to impair day-to-day business operation. They represent the minimum security baseline for a Microsoft 365 tenant.
This is where most organisations start. The assessment covers all 97 L1 controls and produces a compliance score, a per-control findings table, and a prioritised remediation plan.
Book Level 1 — £29943 additional controls.
Level 2 adds advanced hardening controls that may have a higher operational impact or require additional tooling. Recommended for environments handling sensitive data or operating in regulated sectors.
Level 2 is assessed as a supplement to Level 1. A Level 1 assessment is a prerequisite. Priced separately — get in touch for a quote.
Get a quote for Level 2Not all controls apply to every licence.
Each CIS control requires specific Microsoft 365 features to be available in the tenant. The benchmark report includes a licence gap analysis identifying which controls your current licences cover and where gaps exist. The audit covers Business Premium, E3, and E5 licence tiers.
Best coverage at SMB price
Business Premium covers the majority of L1 controls. A small number of identity protection controls require E5 features.
Missing some Defender and PIM
E3 covers most L1 controls but lacks Defender for Identity, Priority protection, and Privileged Identity Management without add-ons.
Full L1 and L2 coverage
E5 satisfies all L1 and the majority of L2 controls natively. Recommended for organisations in regulated sectors.
Every audit includes a full licence gap analysis for your specific tenant. You will know exactly which controls you cannot satisfy with your current licences before you start remediation.
Ready to assess your M365 tenant?
CIS M365 Level 1 is £299 fixed price. Book directly or get in touch to discuss scope.
