61 controls + 336 settings across 6 frameworks

Know your M365
compliance posture

Audit your Microsoft 365 tenant against CIS benchmarks and see how your configuration maps to ISO 27001, DORA, NIS2, and NIST CSF 2.0. Honest coverage, trade-off scoring, and actionable remediation.

Why SMEs struggle with M365 compliance

Enterprise tools are overkill. Free scanners are too narrow. There's a gap in between.

Enterprise tools

EUR 50k+ per year. Designed for 10,000-seat deployments with dedicated compliance teams. Overkill for SMEs.

Free scanners

Check CIS benchmarks only. No regulatory mapping to DORA or NIS2. No remediation guidance or trade-off analysis.

PostureIQ

CIS benchmarks mapped to 4 regulatory frameworks. Honest coverage, trade-off scoring, remediation guidance. Free to use.

From export to compliance scores in 15 minutes

No agents, connectors, or Azure AD app registrations required.

Step 1

Run the PowerShell script

Our script collects M365 configuration from Graph, Exchange, SharePoint, Teams, and Purview. Exports to JSON.

Step 2

Upload your JSON export

PostureIQ evaluates 61 posture controls and 336 device hardening settings against all 6 frameworks instantly.

Step 3

See your compliance scores

Framework scores, quick wins ranking, clause-by-clause breakdowns, and downloadable evidence packs for auditors.

One scan. Six frameworks.

PostureIQ runs your M365 configuration against CIS benchmarks, then maps every finding to the regulatory framework that matters to you.

Technical baselines

CIS M365 v3

52 controls

Microsoft 365 Foundations Benchmark. The industry-standard configuration hardening checklist.

CIS Intune

285+ settings

Windows 11 Enterprise device hardening benchmarks for Intune-managed endpoints.

Regulatory mappings

ISO 27001:2022

Information Security Management System

Annex A controls

DORA

EU Digital Operational Resilience Act

Art. 9 & 10

NIS2

EU Network & Information Security Directive

Art. 21

NIST CSF 2.0

US Cybersecurity Framework

PR & DE functions

CIS benchmarks provide the technical assessment. Regulatory frameworks show how each finding maps to the compliance obligations that apply to your organisation.

Built for compliance officers and MSPs

Not just a scanner. PostureIQ gives you the context to make decisions.

Trade-off Scoring

Every remediation rated for security gain, user impact, effort, and disruption. Fix what matters first.

Honest Coverage

We show exactly what we assess and what we don't. No inflated percentages or false confidence.

EU-First Design

Built for organisations subject to DORA, NIS2, and ISO 27001. EU data residency. EUR pricing.

Multi-Tenant Ready

MSPs: manage multiple tenants, compare scores side-by-side, and share read-only client portals.

Auditor Evidence Packs

Clause-by-clause CSV exports, framework crosswalk maps, and risk registers. Ready for your auditor.

Results in 15 Minutes

PowerShell script collects data. Upload JSON. See scores. No agents, connectors, or app registrations.

No paywalls. Just compliance.

Full compliance scoring for free. No credit card required. No trial countdown. If you find PostureIQ useful, buy us a coffee.

Free

€0

No strings attached

  • Upload and scan your M365 tenant
  • All 6 compliance frameworks
  • Up to 3 audits
  • Dashboard, findings & remediation
  • Framework deep-dives & crosswalk
  • Device hardening analysis
  • 1 tenant
Support us

Buy me a coffee

€3/ 30 days

One-time payment. No subscription. No auto-renewal.

  • Everything in Free, plus:
  • Unlimited audits
  • PDF compliance reports
  • Multi-tenant management (up to 10)
  • Side-by-side tenant comparison
  • Read-only client portal
  • Audit history

Frequently asked questions

Built for trust

Your compliance data is sensitive. Here is how we handle it.

EU Data Residency

All data processed and stored in Frankfurt (eu-central-1). No replication outside the EU.

No Direct Tenant Access

You control the data export. PostureIQ never connects to your M365 tenant or stores your credentials.

GDPR Compliant

Article 17 right to erasure. Full data export and account deletion available in Settings at any time.

Transparent Policies

Privacy policy and Data Processing Agreement published and available before you create an account.

Ready to assess your M365 compliance posture?

Free to use. See your scores in 15 minutes.

Get started