The TATER Control Framework

One original control framework — 4,000+ TATER-authored controls, evaluated with automated scanning and threshold-based analysis — crosswalked to the 30+ standards your auditors ask for: CIS, CISA SCuBA, DISA STIGs, NIST, ISO 27001, SOC 2, PCI DSS, HIPAA, CMMC, UK Cyber Essentials, Australian Essential Eight and more. Collect evidence once; see exactly where each control lands in every framework. Mappings are identifier crosswalks, not certifications.

Explore

Standards at a glance

The frameworks, the coverage model, and how scoring works — drill into any topic for the full detail.

Frameworks Covered

CIS, CISA SCuBA, NIST 800-53, ISO 27001, SOC 2, HIPAA, PCI, UK Cyber Essentials, AU Essential Eight — and 20+ more. One control set, mapped to all of them.

Explore →

Unified Control Model

One control definition, evaluated by a threshold engine, mapped to every framework it satisfies at once.

Explore →

Predict the Unknown

Turn Manual-Review controls into predicted pass/fail from platform defaults, shrinking the unknown surface area.

Explore →

Federal / ATO

POA&M (OMB/eMASS), the NIST RMF 6-step tracker, SSP to OSCAL, and GCC / GCC High / DoD support.

Explore →

Compliance Scoring

How raw configuration becomes a live, per-framework compliance score you can trend over time. Licensing-aware: controls for M365 features you don’t license are auto-marked ⊘ Not Applicable from your tenant’s service plans and excluded from the compliance % — and a Commercial compliance profile can exclude federal / DISA-STIG controls for non-government orgs.

Explore →

M365 Coverage

Entra ID, Exchange, SharePoint, Teams, Defender, Purview & Power Platform — with real per-app control counts.

Explore →
CIS M365 CISA SCuBA DISA STIGs NIST 800-53 ISO 27001 SOC 2 PCI-DSS v4.0 HIPAA NIST CSF 2.0 CIS Controls v8 CIS Windows 11 CIS Windows Server CIS Chrome CIS Edge CIS Intune CIS Defender Antivirus CISA SCuBA (Google Workspace) macOS CIS AWS Foundations CIS Linux (Ubuntu/RHEL) CIS SQL Server CIS Docker CIS Kubernetes CIS Cisco IOS/NX-OS CIS Palo Alto NIST 800-171 / CMMC L2 UK Cyber Essentials AU Essential Eight ITIL 4 NIST SP 800-61 ISO/IEC 42001 NIST AI RMF EU AI Act Custom Frameworks
Compliance Frameworks

One framework, mapped to every standard your auditors care about

TATER evaluates its own control set with real configuration data — not questionnaires — then crosswalks each control to the frameworks below by identifier. A crosswalk shows where a control aligns; it is not a certification or an attestation of compliance.

Regulatory & Industry Frameworks

NIST 800-53 Rev 5

261 controls · 20 families

The gold standard for federal information security. TATER maps M365 and endpoint configurations to all 20 Rev 5 control families-from Access Control (AC) through Supply Chain Risk Management (SR)-giving you a continuous compliance posture instead of point-in-time snapshots.

ISO 27001:2022

93 Annex A controls

Complete Annex A coverage across all four themes: Organizational, People, Physical, and Technological. TATER links technical scan results to each ISO control and generates audit-ready narratives that describe your actual implementation posture.

SOC 2 Trust Services

5 trust service categories

Maps technical controls to Security, Availability, Processing Integrity, Confidentiality, and Privacy criteria. Cross-references automated scan evidence so your SOC 2 Type II audit starts with machine-verified data rather than manual screenshots.

PCI-DSS v4.0

12 requirement areas

Payment Card Industry requirements mapped to your M365 tenant and endpoint configurations. TATER evaluates network segmentation controls, encryption posture, access restrictions, and logging requirements against PCI-DSS 4.0 sections.

HIPAA Security Rule

Administrative, Physical & Technical

Safeguards for electronic protected health information (ePHI) mapped to your actual tenant configuration. Covers access controls, audit controls, transmission security, and authentication requirements from 45 CFR 164.312.

Government & Defense

CISA SCuBA Baselines

130 controls

Secure Cloud Business Applications baselines as mandated by BOD 25-01 for federal agencies. TATER evaluates the SCuBA baselines for Entra ID, Exchange Online, Defender, SharePoint, Teams, and Power BI — 73 of the 130 controls run as automated checks that match CISA's exact evaluation criteria, and the remaining 57 as Manual Review. Google Workspace is covered by its own baseline set, below.

CISA SCuBA — Google Workspace

135 controls

CISA's Secure Cloud Business Applications baselines for Google Workspace, the non-Microsoft half of BOD 25-01. Covers Gmail, Drive & Docs, Calendar, Chat, Meet, Groups, Sites, Classroom, Gemini, and Workspace-wide common controls — sharing policies, authentication requirements, DLP rules, and app access controls. Automated evaluation is in progress: 6 of these controls are checked automatically today (SPF, DKIM, DMARC and 2-Step Verification enrolment); the remaining 129 are catalogued with full guidance for manual review while automated checks are built out.

DISA STIGs

62 controls

Defense Information Systems Agency Security Technical Implementation Guides for DoD-compliant configurations. TATER ships STIG requirements for Entra ID and Intune in the cloud scan and for Windows Server and Linux on the agent — each as a Manual Review control carrying its own guidance, remediation text and evidence capture — plus the full DISA STIG Windows Server 2022 (V1R5) definition to crosswalk against.

NIST 800-171 / CMMC Level 2

110 practices · 14 families

Protection of Controlled Unclassified Information (CUI) for the Defense Industrial Base. TATER crosswalks the 110 NIST SP 800-171 security requirements — aligned to CMMC Level 2 — across all 14 control families, tying each to the M365 and endpoint checks it already evaluates so contractors can track assessment readiness continuously.

UK Cyber Essentials

23 controls · 5 technical themes

The UK NCSC baseline for essential cyber hygiene, across all five technical themes — firewalls, secure configuration, user access control, malware protection, and security update management. TATER maps each to the M365 and endpoint checks it already evaluates, so UK organisations can track Cyber Essentials readiness from live configuration.

Australian Essential Eight

27 controls · 8 mitigation strategies

The Australian Cyber Security Centre (ACSC) Essential Eight mitigation strategies — application control, patch applications, configure Office macros, user application hardening, restrict admin privileges, patch operating systems, multi-factor authentication, and regular backups. TATER crosswalks each strategy to its M365 and endpoint checks for continuous maturity tracking.

Technical Benchmarks (CIS)

CIS Microsoft 365 Foundations

141 controls

The most comprehensive automated benchmark for M365. TATER's own controls are evaluated automatically, on every scan, then crosswalked by identifier to all nine CIS benchmark sections — Entra ID, Exchange, SharePoint, Teams, Defender, Purview, and Microsoft Fabric.

CIS Windows 11 Enterprise

731 controls

Endpoint hardening for Windows 11 evaluated locally via the TATER Agent. TATER's own controls check security policies, registry settings, audit policies, firewall rules, and service configurations, crosswalked to the full CIS L1 and L2 benchmark.

CIS Windows Server

580–620 controls per version

Server hardening benchmarks for Windows Server 2019, 2022, and 2025. Each version gets version-specific checks covering security options, user rights, audit subcategories, and Windows Firewall with Advanced Security profiles.

CIS Microsoft Intune

800 controls (Windows 11 + Office)

Device configuration compliance for Intune-managed endpoints. Evaluates Settings Catalog policies, device configuration profiles, and compliance policies, crosswalked to CIS Intune benchmarks for both Windows 11 and Microsoft 365 Apps.

CIS Google Chrome

134 controls

Browser hardening for Google Chrome evaluated via Group Policy and registry settings. Covers security, privacy, content, extensions, and network policies to ensure browsers do not become attack vectors.

CIS Microsoft Edge

285 controls

Comprehensive Edge browser benchmark including SmartScreen, InPrivate mode, password manager, telemetry, and extension controls. Evaluated locally by the TATER Agent alongside other endpoint benchmarks in a single scan pass.

CIS Microsoft Defender Antivirus

64 controls

Antimalware hardening evaluated on-device by the TATER Agent: all 17 Attack Surface Reduction rules plus cloud-delivered protection and MAPS reporting, real-time and behavior monitoring, archive and removable-drive scanning, scheduled scan and signature-update policy, quarantine handling, and blocking of potentially unwanted applications.

Infrastructure & Cloud Benchmarks (CIS)
These benchmarks are not evaluated by the TATER Agent — it runs on Windows, Linux and macOS endpoints, not on database servers, container hosts, switches or firewalls. Each card states how TATER actually assesses it: config upload (automated rules run against an export you upload) or manual review (a tracked, assignable, evidence-backed checklist your team completes). The Linux and macOS cards are the exception — those checks do run on-device.

CIS AWS Foundations v3.0

30 controls · config upload

Foundational AWS account-security controls — IAM, logging (CloudTrail / Config), monitoring, networking, and storage exposure. TATER assesses these two ways: 14 rules run automatically against an AWS CLI JSON export you upload (IAM / S3 / CloudTrail), and the multi-cloud posture API ingests findings pushed from an external CSPM scanner. TATER does not hold AWS credentials or scan a live account itself, so the 30 benchmark items ship as a tracked checklist that those two inputs fill in.

CIS Linux (Ubuntu / RHEL)

60 on-device checks

Server and workstation hardening for Ubuntu and Red Hat Enterprise Linux, evaluated locally by the cross-platform TATER Agent — filesystem, service, network, logging, and access-control checks mapped to the CIS Linux benchmarks.

CIS macOS

55 on-device checks

Mac hardening evaluated locally by the same cross-platform TATER Agent — FileVault, firewall, Gatekeeper and SIP, screen lock and login window, sharing and remote management, software update policy, and audit configuration. Runs on Apple Silicon and Intel in the same scan pass as the Windows and Linux fleet.

CIS SQL Server

20 controls · manual review

Microsoft SQL Server configuration hardening — surface-area, authentication, authorization, auditing, and encryption settings, crosswalked to the CIS SQL Server benchmark's control areas. There is no SQL Server scanner: these 20 controls ship as a review checklist your DBA works through, with TATER handling assignment, evidence, exceptions and framework roll-up. The pass / fail call is theirs, not a scan's.

CIS Docker

25 controls · manual review

Container host and daemon hardening — daemon configuration, image and build files, container runtime, and Docker security operations, crosswalked to the CIS Docker benchmark's control areas. The TATER Agent does not run inside container hosts, so these 25 controls ship as a review checklist your platform team works through, tracked and evidenced in TATER like any other control.

CIS Kubernetes

25 controls · manual review

Kubernetes control-plane and worker-node security — API server, etcd, kubelet, RBAC policies, and pod security, crosswalked to the CIS Kubernetes benchmark's control areas. TATER has no cluster connector: these 25 controls ship as a review checklist, so you can evidence cluster hardening in the same register as everything else without TATER pretending to have scanned it.

CIS Cisco IOS / NX-OS

25 controls · config upload

Cisco router and switch hardening — management-plane, control-plane, and data-plane configuration for IOS and NX-OS. Paste or upload a running-config and TATER evaluates 22 built-in rules against it automatically (AAA, SSH, SNMP, logging, VTY and service hardening) and records the results as findings. TATER does not log into your network devices; the remaining benchmark items in the 25-control checklist are reviewed by hand.

CIS Palo Alto Firewall

22 controls · manual review

Palo Alto Networks firewall hardening — device management, security zones and policies, logging, and threat-prevention configuration, crosswalked to the CIS Palo Alto Firewall benchmark's control areas. TATER has no PAN-OS connector, so these 22 controls ship as a review checklist. (The Cisco card above is the one network benchmark with automated rules, and those run against an uploaded config.)

Cross-Mapping & Emerging Frameworks

NIST CSF 2.0

6 core functions

The Cybersecurity Framework 2.0 adds Govern alongside Identify, Protect, Detect, Respond, and Recover. TATER cross-maps your existing technical controls to CSF functions and categories, providing a risk-based maturity view without duplicate evaluation.

CIS Controls v8

18 control groups

Prioritized set of safeguards organized into Implementation Groups (IG1, IG2, IG3). TATER maps your technical scan results to CIS Controls and shows which Implementation Group level your organization currently achieves across all 18 control areas.

Custom Frameworks

Build your own

Create organization-specific or industry-specific frameworks with the visual framework builder. Define custom domains, map controls with threshold logic, import/export JSON for MSP distribution, and cross-reference your custom framework to any standard framework.

Service Management & Incident Response

ITIL 4

Incident, Service Request & Problem

TATER Ops ships three ITIL 4-aligned process profiles out of the box: Incident Management (8-state lifecycle, impact/urgency/severity, business service, configuration items, per-priority SLAs), Service Request (Approval Pending + Fulfilled states, customer-visible by default), and Problem Management (root-cause analysis + Known Error states). Field-visibility templating means your team only sees the columns the chosen process requires.

NIST SP 800-61

Computer Security IR Handling

The Computer Security Incident Handling Guide lifecycle (Detected → Triage → Contained → Eradicating → Recovering → Resolved → Post-Incident Review → Closed) ships as a pre-seeded process profile with a False Positive branch and aggressive Critical SLAs (15-minute response). Use it standalone for security incident response or alongside the ITIL Incident profile for split ITSM/SecOps workflows.

AI Governance

ISO/IEC 42001 · NIST AI RMF · EU AI Act

Govern the AI tools, models, and agents your organization uses. The AI Governance pack ships an AI System Inventory (classified by EU AI Act risk tier — prohibited / high-risk / GPAI / limited / minimal) and a 22-control checklist crosswalked across ISO/IEC 42001 (clauses 4–10 + Annex A), the NIST AI RMF (Govern / Map / Measure / Manage), and the EU AI Act (risk management, data governance, transparency, human oversight, logging). AI systems link to your vendor register for third-party AI supply-chain risk, and posture rolls up into TATER Insights — answering "what AI do we use, how is each classified, and are our AI controls in place?" as the EU AI Act comes into force.

SOC 2 (Trust Services Criteria)

CC1–CC9 + Availability / Confidentiality / PI / Privacy

SOC 2 readiness without re-scanning. TATER crosswalks the Trust Services Criteria — the mandatory Common Criteria (CC1–CC9) plus the optional Availability, Confidentiality, Processing Integrity, and Privacy categories — to the M365 control checks it already evaluates (MFA, conditional access, privileged-access management, logging, DLP, device compliance, and more). A computed readiness view shows coverage per category and per criterion, citing the exact controls that evidence each one and flagging the criteria that remain auditor-attested. Surfaced in TATER Insights and queryable from the MCP server for live SOC 2 gap analysis.

Coverage matrix

Automated vs. Manual Review per framework

A practitioner-grade view of where TATER does the work for you and where Manual Review is required. Every number below is an exact count from the control catalog that ships with the product — not an estimate — and matches the per-framework counts on the cards above. "Predict the Unknown" surfaces a confidence-rated guess for unscanned manual controls, so the Manual Review column is not the whole picture.

Scanned baselines — Microsoft 365 & Google Workspace
“Automated” counts controls TATER evaluates without human input. Google Workspace automation is newer and still expanding — the figures below are what is implemented today, not what is planned.
Baseline Controls Automated Manual review Automated coverage
CIS Microsoft 365 Foundations Benchmark1411291291%
CISA SCuBA — Microsoft 365130735756%
CISA SCuBA — Google Workspace13561294%
DISA STIG — Microsoft 365 / Entra ID120120%
All scanned baselines41820821050%
Crosswalk targets — mapped by identifier, not scanned separately
Framework Framework size TATER governance controls
NIST SP 800-53 Rev 5261 controls · 20 families36
NIST SP 800-171 Rev 2 / CMMC Level 2110 practices · 14 families30
NIST CSF 2.0106 subcategories · 6 functions30
CIS Controls v8.1153 safeguards · 18 control groups40
ISO/IEC 27001:2022 Annex A93 controls · 4 themes30
PCI DSS v4.0.193 sub-requirements · 12 requirement areas30
SOC 2 Trust Services Criteria62 criteria · 5 trust service categories30
HIPAA Security Rule59 safeguards · 45 CFR 164.308–164.31632
Endpoint & infrastructure benchmarks — how each one is actually assessed
“On-device” means the TATER Agent runs a check on the machine itself. “Config upload” means TATER runs automated rules against a configuration export you provide. “Manual review” means TATER supplies the checklist, assignment, evidence and framework roll-up, and a human makes the call — there is no scanner.
Benchmark Checks How it is assessed
CIS Windows 111,282On-device (TATER Agent)
CIS Windows Server 2019 / 2022 / 20251,795On-device (TATER Agent)
CIS Microsoft Intune394On-device (TATER Agent)
CIS Microsoft Edge143On-device (TATER Agent)
CIS Google Chrome134On-device (TATER Agent)
CIS Microsoft Defender Antivirus64On-device (TATER Agent)
CIS Linux (Ubuntu / RHEL)60On-device (TATER Agent)
CIS macOS55On-device (TATER Agent)
CIS Cisco IOS / NX-OS25Config upload — 22 automated rules against a running-config
CIS AWS Foundations v3.030Config upload — 14 automated rules against AWS CLI JSON, plus ingested CSPM findings
CIS Docker25Manual review checklist
CIS Kubernetes25Manual review checklist
CIS Palo Alto Firewall22Manual review checklist
CIS SQL Server20Manual review checklist
DISA STIG — Windows / Linux50Manual review checklist
Linux / macOS supplementary catalog items70Manual review checklist — additional to the on-device checks above
Total4,1943,927 on-device · 55 config upload · 212 manual review

Crosswalk frameworks are not scanned separately: their coverage is inherited from the scanned baselines above by identifier mapping, alongside the TATER governance controls listed for each. The endpoint and infrastructure benchmarks add a further 3,927 checks the TATER Agent evaluates on-device — Windows 11 and Windows Server, Intune, Edge, Chrome, Defender Antivirus, Linux and macOS — whose pass / fail / manual outcome is decided per device at scan time, so there is no fixed catalog split to publish for those. The container, orchestration, database, firewall and DISA STIG benchmarks are not agent-evaluated: they and the AWS and Cisco cards are broken out in the table directly above, so you can see exactly which coverage is automated and which is a checklist before you buy. Not Applicable and Skipped are likewise per-tenant runtime outcomes driven by your licensed service plans, not catalog properties. Manual Review controls represent legitimate human-in-the-loop checks (paper policies, vendor attestations, training records) that no platform can fully automate. Predict the Unknown surfaces a TATER-generated confidence-rated guess for unscanned controls so coverage gaps are explicit instead of invisible.

Evaluation Pipeline

From raw configuration to compliance score

TATER does not rely on self-assessment questionnaires. Every control is evaluated against live configuration data collected from your tenant and endpoints.

1

Collect

TATER reads the live configuration of Microsoft 365, Exchange Online, Defender, and Intune, while the TATER Agent runs TATER's own on-device hardening checks — crosswalked to CIS and other benchmarks — on Windows, Linux, and macOS machines.

2

Evaluate

The V2 threshold engine analyzes each data point using typed evaluators: boolean, compare, includes, excludes, count, regex, and composite (AND/OR) rules. No ambiguity-every control has a deterministic pass/fail outcome.

3

Map

Each evaluated control is cross-mapped to every framework it satisfies. One MFA control maps to NIST AC-7, ISO A.8.5, SOC CC6.1, PCI 8.3, and HIPAA 164.312(d) simultaneously. Evidence collected once serves all frameworks.

4

Report

Gap analysis breaks each framework into sections with per-section compliance percentages. AI-generated narratives, exportable reports, and trust center dashboards present results to auditors, executives, and clients.

Overlap Detection

Eliminate duplicate evidence collection

Many compliance frameworks share overlapping requirements. Enabling MFA satisfies controls in NIST AC-7, ISO 27001 A.8.5, SOC 2 CC6.1, PCI-DSS 8.3, and HIPAA 164.312(d). TATER identifies these overlaps and maps them automatically, reducing audit preparation from weeks to hours.

Cross-Framework Mapping
MFA Policy→ NIST AC-7, ISO A.8.5, SOC CC6.1
Encryption→ NIST SC-28, ISO A.8.24, PCI 3.5
Audit Logs→ NIST AU-2, ISO A.8.15, HIPAA 312(b)
Access Ctrl→ NIST AC-3, ISO A.8.3, SOC CC6.3
DLP Policy→ NIST MP-4, ISO A.8.12, PCI 3.4
Gap Analysis

Know exactly where you stand

TATER breaks each framework into its constituent sections and shows which controls map to each one, along with the current compliance percentage. Drill down from framework to section to individual control status in seconds.

NIST 800-53 Gap Analysis
AC - Access Control
92%
AU - Audit & Accountability
85%
CM - Config Management
78%
IA - Identification & Auth
95%
SC - System & Comms
88%
SI - System & Info Integrity
81%
AI-Powered

Compliance narratives that write themselves

For each standard section, TATER analyzes your linked controls, their current pass/fail status, overrides, and exceptions-then generates a narrative tailored to your actual posture. Not generic boilerplate. Your specific implementation, described accurately.

AI Narrative - NIST 800-53 AC: Access Control
Generated Narrative
The organization enforces multi-factor authentication for all privileged and standard user accounts through Microsoft Entra ID Conditional Access policies. Access reviews are conducted automatically through TATER's control testing schedule, with quarterly recertification of privileged role assignments. Legacy authentication protocols are blocked at the tenant level, and session timeout policies enforce re-authentication after 60 minutes of inactivity.
Linked Controls (6 of 14 passing)
ENT_001 Block Legacy Auth ENT_003 MFA Enforced ENT_005 Session Timeout ENT_010 Privileged Roles ENT_024 MFA Capable ENT_032 Conditional Access
Frameworks Satisfied
NIST AC-7 · ISO A.8.5 · SOC CC6.1 · PCI-DSS 8.3 · HIPAA 164.312(d) · CIS Controls 6.3
300+
Standard sections covered
30+
Frameworks crosswalked
1-Click
Generation per section
Editable
Review, revise, and save

Ready to map your compliance posture?

Get audit-ready across all frameworks in days, not months.

Launch TATER → Contact Sales