Experience what an ISO 27001 audit feels like
Same questions a real auditor asks. See exactly where you stand — start instantly with our 30-minute audit preview, or engage with a GMS security consultant for a full tenant audit.
What do you need assessed?
30-Minute Audit Preview
Same methodology, condensed — start immediately
- Six NIST risk domains (Governance, Identify, Protect, Detect, Respond, Recover)
- AI-driven conversation — ~45 questions in 30–40 minutes
- Scored report with gap analysis and recommendations
- No tenant access required at this stage
- Results mapped to your M365 licence tier
Full Tenant Audit
Our engineers review your actual configuration
- Everything in Essentials, plus:
- Live tenant review — Entra ID, Defender, Intune, Purview
- Qualifying questions that probe deeper (Big 4 methodology)
- Findings report with weighted risk scores and remediation priorities
- Microsoft Secure Score benchmark comparison
- Recommendations mapped to Plan 1 / 2 / 3 delivery
Typically completed within one week. Includes a 60-minute findings presentation.
The essentials assessment takes approximately 30 minutes. No preparation needed.
You'll receive a gap analysis across six NIST risk domains with specific remediation priorities.
No tenant access required. Responses are encrypted and processed under our ISO 27001 ISMS. Privacy policy
What the assessment covers
- Entra ID configuration
- Conditional Access policies
- Privileged accounts
- Guest & external access
- Sensitivity labels
- DLP policies
- Retention & archiving
- Audit logging
- Defender for Endpoint
- Intune compliance
- Attack surface reduction
- Incident response
- Email authentication
- Backup & recovery
- Network controls
- Cloud app governance
30 M365 and Azure assets assessed across all six NIST risk domains.
Simple, secure, insightful
Name, email, company. Your assessment starts immediately — no waiting for a link.
Our AI auditor walks you through ~30 questions across six risk domains. No technical access to your tenant is needed.
Receive a scored report with gap analysis, risk ratings, and specific recommendations mapped to your M365 licence tier.