Audit your Microsoft 365 tenant against CIS benchmarks and see how your configuration maps to ISO 27001, DORA, NIS2, and NIST CSF 2.0. Honest coverage, trade-off scoring, and actionable remediation.

61
Posture controls
381
Device hardening settings
6
Frameworks evaluated
15min
Time to first scores
Enterprise tools are overkill. Free scanners are too narrow. PostureIQ fills the gap — real regulatory mapping, not just a checklist.
Enterprise GRC
€50k+ per year. Designed for 10,000-seat deployments with dedicated compliance teams. Overkill and unaffordable for SMEs.
Free scanners
Check CIS benchmarks only. No regulatory mapping to DORA or NIS2. No remediation guidance. No trade-off analysis.
PostureIQ
CIS benchmarks mapped to four regulatory frameworks. Honest coverage, trade-off scoring, remediation guidance. Free to use.
No agents. No connectors. No Azure AD app registrations. Scroll the story.
PS> ./PostureIQ-Export.ps1
✓ Connected to Microsoft Graph — read-only scopes
✓ Entra ID · Conditional Access · auth methods
✓ Exchange Online · DKIM · SPF · DMARC
✓ Intune compliance + configuration profiles
✓ SharePoint · Teams · Purview
→ Export complete: posture-export.json (612 KB)
PS> ./PostureIQ-Export.ps1
✓ Connected to Microsoft Graph — read-only scopes
✓ Entra ID · Conditional Access · auth methods
✓ Exchange Online · DKIM · SPF · DMARC
✓ Intune compliance + configuration profiles
✓ SharePoint · Teams · Purview
→ Export complete: posture-export.json (612 KB)
Step 1 · Collect
26 data sources from Graph, Exchange, SharePoint, Teams, and Purview — exported to JSON on your machine in about five minutes. Your credentials never leave your machine, and you decide what to upload.

Step 2 · Score
PostureIQ evaluates 61 posture controls and 381 device hardening settings against all 6 frameworks instantly — with every score showing its honest denominator. Missing data reads N/A, never padded.

Step 3 · Triage
Filter by status, click a control to see the exact configuration that tripped it, and open remediation from the same pane.

Step 4 · Remediate
Every failing control comes with a step-by-step runbook and a trade-off score on four dimensions — so you can fix what matters most without triggering a helpdesk storm.

Step 5 · Prove it
Drill into any framework to see which clauses are covered, which controls map to each clause, and what the actual tenant configuration looks like. Export evidence packs as CSV for your auditor.
Platform Pillars
Not just a scanner. PostureIQ gives you the context to make decisions.
Security gain, user impact, effort, and disruption risk on every remediation. Fix what matters first — no surprise tickets.
Every score has a visible denominator. Unscored settings shown transparently. Missing data shows N/A — never padded.
Built for organisations subject to DORA and NIS2. Data processed and stored in Frankfurt. EUR pricing. No US replication.
MSPs: manage multiple tenants, compare scores side-by-side, share read-only client portals. Included in the €3 coffee tier.
Clause-by-clause CSV exports, framework crosswalk maps, and risk registers. Ready for your ISO 27001 or DORA auditor.
PowerShell script collects data. Upload JSON. See scores. No agents, connectors, or app registrations anywhere.
Framework Coverage
PostureIQ runs your M365 configuration against CIS benchmarks, then maps every finding to the regulatory framework that matters to you.
Technical baselines
CIS M365 v6.0.1
36 recommendations mappedMicrosoft 365 Foundations Benchmark — the industry-standard configuration hardening checklist. Identity, device compliance, SharePoint and Teams substantially covered; see per-section coverage.
CIS Intune Win11
381 settingsWindows 11 Enterprise device hardening benchmarks for Intune-managed endpoints.
Regulatory mappings
ISO 27001:2022
Information Security Management System
Annex A.8 technological controls
DORA
EU Digital Operational Resilience Act
Arts 8–12 (Chapter II)
NIS2
EU Network & Information Security Directive
Art. 21(2)(a–j)
NIST CSF 2.0
US Cybersecurity Framework
Protect & Detect functions
CIS benchmarks provide the technical assessment. Regulatory frameworks show how each finding maps to the compliance obligations that apply to your organisation.

Pricing
Full compliance scoring for free. No credit card. No trial countdown. If you find PostureIQ useful, buy us a coffee.
No strings attached
One-time payment. No subscription. No auto-renewal.
Your compliance data is sensitive. Here's how we handle it.
All data processed and stored in Frankfurt (eu-central-1). Zero replication outside the EU.
You control the export. PostureIQ never connects to your M365 tenant or stores your credentials.
Article 17 right to erasure. Full data export and account deletion available in Settings at any time.
Privacy policy and sub-processor list published before account creation. Read-only, no surprises.