Map Microsoft 365 security products to NIST CSF 2.0 controls, find your compliance gaps, get priced product recommendations and export the analysis.
This tool answers one narrow question: given the Microsoft security products you already own, which controls in a chosen compliance framework do they actually address, and which ones are left open? You pick a framework, tick the products in your tenant, and get a control-by-control coverage view, a per-function breakdown, a ranked list of gaps, and suggestions for which additional Microsoft product would close the most of them.
It is a product-to-control mapper, not a framework-to-framework crosswalk. It will not tell you how ISO 27001 A.8.7 lines up with NIST CSF PR.PS-02. It tells you whether Defender for Endpoint P2 covers PR.PS-02 and how well. If you need a crosswalk between two standards, this is not that tool.
Six frameworks ship with the tool, each with its own control set, its own grouping labels, and its own hand-built product mappings:
| Framework | Controls included | What the tool calls them | Product mappings |
|---|---|---|---|
| NIST CSF 2.0 | 48 | Controls, grouped by Function (Govern, Identify, Protect, Detect, Respond, Recover) | 66 |
| HIPAA Security Rule | 49 | Implementation Specifications, flagged required or addressable | 54 |
| SOC 2 | 51 | Criteria, grouped by Trust Services Category | 39 |
| PCI DSS 4.0 | 52 | Sub-Requirements | 32 |
| CMMC 2.0 | 56 | Practices | 45 |
| CIS Controls v8 | 56 | Safeguards | 43 |
These are curated subsets, not the complete published control catalogues. NIST CSF 2.0 in full has considerably more subcategories than 48. The tool covers the controls where a Microsoft security product is plausibly relevant, plus the process-only controls it needs to name in order to exclude them honestly. Treat the control list as a working scope, not as an authoritative reproduction of the standard.
On the product side, 22 Microsoft security SKUs are modelled — Entra ID P1/P2 and the Entra Suite, Defender for Business, Defender for Endpoint P1/P2, Defender for Server P1/P2, Defender Vulnerability Management, Defender for Office 365 P1/P2, Defender for Identity, Defender for Cloud Apps, Sentinel, Security Copilot, Azure Information Protection P1/P2, Purview Information Protection, Compliance Manager, Insider Risk Management, Purview Audit (Premium), and Intune P1.
Products carry an includes relationship that the tool resolves transitively. Selecting Defender for Endpoint P2 automatically credits you with P1's coverage; selecting Entra ID P2 credits P1. You do not have to tick both.
This is the part that matters more than the interface. A control in a compliance framework is a statement of intent expressed in the language of that framework, and a product is a set of capabilities. They almost never correspond one to one. A single product often partially satisfies a control, several products together satisfy one control, and one product touches a dozen controls at different depths.
The tool encodes that explicitly with three coverage levels rather than a binary tick, plus two more states for controls no product can reach:
| State | Meaning | Weight in the overall score |
|---|---|---|
| Covered (full) | The product substantively implements the control | 100 |
| Partial | The product implements part of it; something else is still needed | 50 |
| Supports | The product provides evidence or telemetry that helps, but does not implement the control | 25 |
| Gap | Nothing you selected touches it | 0 |
| Non-technical | A process, policy or governance control no product can satisfy | Excluded from the denominator |
The overall coverage percentage is the weighted sum of those points divided by the number of assessable controls. Non-technical controls drop out of the denominator entirely — but only while nothing covers them, so a governance control that happens to have a product mapping is counted normally. Per-function percentages use a slightly coarser weighting than the headline figure: there, partial and supports both count as 50 rather than 50 and 25. Expect the function bars and the top-line number to disagree slightly. That is the arithmetic, not a bug.
The design decision worth understanding is why “supports” exists at all. Most vendor coverage matrices collapse it into “covered”, which is how organisations end up telling an auditor they have implemented a control when what they actually have is a log source that would help prove it if they had implemented it. Keeping supports at a quarter weight makes that distinction survive into the score.
A product mapping is a starting hypothesis about where to look for evidence. It is not evidence, and it is not an assessment. Three specific traps:
The defensible way to use the output is the inverse: as a gap register. “These fourteen controls have no Microsoft product behind them, here is what each would need” is a statement you can hand to a compliance lead and act on. Each gap carries a plain-English note explaining why no Microsoft product addresses it and what category of control would — a third-party tool, a documented procedure, a physical control, or a contractual one.
Setup. Choose one of the six frameworks, then load a stack. Four presets cover the common starting points:
Presets are a starting selection, not a lock — switch to Custom and tick or untick individual products, which is what you want if you are on E3 with a couple of add-ons.
Dashboard. Headline coverage percentage, a bar chart per framework function, and counts of covered, partial, gap, and non-technical controls in each. This is where the shape of the problem shows: a stack that is strong on Protect and empty on Recover looks very different from one that is evenly thin.
Controls. The full list, searchable and filterable by function and by coverage state. Filter to gaps only and you have your work list. Expand any control to see which of your products touch it and the specific capability that does the touching — not just “Intune” but what Intune does for that control.
Recommendations. Products you have not selected, ranked by how many of your current gaps they would close.
For each unselected product the tool counts two things: gaps it would close outright, and controls currently at partial or supports that it would raise to full. Priority is assigned by gap count alone — four or more gaps is high, two or three is medium, one is low. Coverage gain is computed as (gaps closed × 100 + upgrades × 50) divided by the assessable control count.
Two limits to keep in mind. First, the products are scored independently, so if two candidates both close the same five gaps, both show a five-gap gain — buying both does not double the benefit. Second, the PDF export sums the per-user list price of every recommendation into a “total additional cost to address all gaps” line. That is the cost of buying the entire recommendation list, overlaps and all. It is an upper bound on a shopping list nobody would actually buy, not a budget.
The tool does ship list prices — a per-user-per-month figure for each of the 22 products, used to annotate recommendations. Microsoft list pricing changes and varies by agreement, region, and channel, so read those as the figures the tool was built with rather than as your price. Products with genuinely different billing units are flagged in their descriptions: Defender for Server is licensed per server, Sentinel is billed per GB per day ingested, and Security Copilot is billed per Security Compute Unit per hour. A per-user figure for any of those three is a rough planning proxy, not how you will be invoiced.
Two export formats. CSV gives you one row per control — control ID, name, status, covering products, the specific capability text, a gap flag, and the non-Microsoft alternative where one is recorded — which is the right shape to paste into a compliance tracker. PDF produces a formatted assessment with an executive summary, a per-function table, the full control detail, and the recommendations table. Both are generated in your browser and downloaded directly; the tool does not upload your product selections anywhere.
Nothing is saved between visits. Reloading resets the framework and the selected stack, so export before you close the tab if you want the result.
Used that way the tool does the one thing that is genuinely tedious to do by hand — holding six frameworks, 22 products, and a few hundred mapping relationships in view at once — and leaves the judgement calls where they belong.