One original control framework — 4,000+ TATER-authored controls, evaluated with automated scanning and threshold-based analysis — crosswalked to the 30+ standards your auditors ask for: CIS, CISA SCuBA, DISA STIGs, NIST, ISO 27001, SOC 2, PCI DSS, HIPAA, CMMC, UK Cyber Essentials, Australian Essential Eight and more. Collect evidence once; see exactly where each control lands in every framework. Mappings are identifier crosswalks, not certifications.
The frameworks, the coverage model, and how scoring works — drill into any topic for the full detail.
CIS, CISA SCuBA, NIST 800-53, ISO 27001, SOC 2, HIPAA, PCI, UK Cyber Essentials, AU Essential Eight — and 20+ more. One control set, mapped to all of them.
Explore →One control definition, evaluated by a threshold engine, mapped to every framework it satisfies at once.
Explore →Turn Manual-Review controls into predicted pass/fail from platform defaults, shrinking the unknown surface area.
Explore →POA&M (OMB/eMASS), the NIST RMF 6-step tracker, SSP to OSCAL, and GCC / GCC High / DoD support.
Explore →How raw configuration becomes a live, per-framework compliance score you can trend over time. Licensing-aware: controls for M365 features you don’t license are auto-marked ⊘ Not Applicable from your tenant’s service plans and excluded from the compliance % — and a Commercial compliance profile can exclude federal / DISA-STIG controls for non-government orgs.
Explore →Entra ID, Exchange, SharePoint, Teams, Defender, Purview & Power Platform — with real per-app control counts.
Explore →TATER evaluates its own control set with real configuration data — not questionnaires — then crosswalks each control to the frameworks below by identifier. A crosswalk shows where a control aligns; it is not a certification or an attestation of compliance.
The gold standard for federal information security. TATER maps M365 and endpoint configurations to all 20 Rev 5 control families-from Access Control (AC) through Supply Chain Risk Management (SR)-giving you a continuous compliance posture instead of point-in-time snapshots.
Complete Annex A coverage across all four themes: Organizational, People, Physical, and Technological. TATER links technical scan results to each ISO control and generates audit-ready narratives that describe your actual implementation posture.
Maps technical controls to Security, Availability, Processing Integrity, Confidentiality, and Privacy criteria. Cross-references automated scan evidence so your SOC 2 Type II audit starts with machine-verified data rather than manual screenshots.
Payment Card Industry requirements mapped to your M365 tenant and endpoint configurations. TATER evaluates network segmentation controls, encryption posture, access restrictions, and logging requirements against PCI-DSS 4.0 sections.
Safeguards for electronic protected health information (ePHI) mapped to your actual tenant configuration. Covers access controls, audit controls, transmission security, and authentication requirements from 45 CFR 164.312.
Secure Cloud Business Applications baselines as mandated by BOD 25-01 for federal agencies. TATER evaluates the SCuBA baselines for Entra ID, Exchange Online, Defender, SharePoint, Teams, and Power BI — 73 of the 130 controls run as automated checks that match CISA's exact evaluation criteria, and the remaining 57 as Manual Review. Google Workspace is covered by its own baseline set, below.
CISA's Secure Cloud Business Applications baselines for Google Workspace, the non-Microsoft half of BOD 25-01. Covers Gmail, Drive & Docs, Calendar, Chat, Meet, Groups, Sites, Classroom, Gemini, and Workspace-wide common controls — sharing policies, authentication requirements, DLP rules, and app access controls. Automated evaluation is in progress: 6 of these controls are checked automatically today (SPF, DKIM, DMARC and 2-Step Verification enrolment); the remaining 129 are catalogued with full guidance for manual review while automated checks are built out.
Defense Information Systems Agency Security Technical Implementation Guides for DoD-compliant configurations. TATER ships STIG requirements for Entra ID and Intune in the cloud scan and for Windows Server and Linux on the agent — each as a Manual Review control carrying its own guidance, remediation text and evidence capture — plus the full DISA STIG Windows Server 2022 (V1R5) definition to crosswalk against.
Protection of Controlled Unclassified Information (CUI) for the Defense Industrial Base. TATER crosswalks the 110 NIST SP 800-171 security requirements — aligned to CMMC Level 2 — across all 14 control families, tying each to the M365 and endpoint checks it already evaluates so contractors can track assessment readiness continuously.
The UK NCSC baseline for essential cyber hygiene, across all five technical themes — firewalls, secure configuration, user access control, malware protection, and security update management. TATER maps each to the M365 and endpoint checks it already evaluates, so UK organisations can track Cyber Essentials readiness from live configuration.
The Australian Cyber Security Centre (ACSC) Essential Eight mitigation strategies — application control, patch applications, configure Office macros, user application hardening, restrict admin privileges, patch operating systems, multi-factor authentication, and regular backups. TATER crosswalks each strategy to its M365 and endpoint checks for continuous maturity tracking.
The most comprehensive automated benchmark for M365. TATER evaluates every CIS recommendation across all nine benchmark sections — Entra ID, Exchange, SharePoint, Teams, Defender, Purview, and Microsoft Fabric — automatically, on every scan.
Endpoint hardening for Windows 11 evaluated locally via the TATER Agent. Checks security policies, registry settings, audit policies, firewall rules, and service configurations against the full CIS L1 and L2 benchmark.
Server hardening benchmarks for Windows Server 2019, 2022, and 2025. Each version gets version-specific checks covering security options, user rights, audit subcategories, and Windows Firewall with Advanced Security profiles.
Device configuration compliance for Intune-managed endpoints. Evaluates Settings Catalog policies, device configuration profiles, and compliance policies against CIS Intune benchmarks for both Windows 11 and Microsoft 365 Apps.
Browser hardening for Google Chrome evaluated via Group Policy and registry settings. Covers security, privacy, content, extensions, and network policies to ensure browsers do not become attack vectors.
Comprehensive Edge browser benchmark including SmartScreen, InPrivate mode, password manager, telemetry, and extension controls. Evaluated locally by the TATER Agent alongside other endpoint benchmarks in a single scan pass.
Antimalware hardening evaluated on-device by the TATER Agent: all 17 Attack Surface Reduction rules plus cloud-delivered protection and MAPS reporting, real-time and behavior monitoring, archive and removable-drive scanning, scheduled scan and signature-update policy, quarantine handling, and blocking of potentially unwanted applications.
Foundational AWS account-security controls — IAM, logging (CloudTrail / Config), monitoring, networking, and storage exposure — evaluated against the CIS AWS Foundations Benchmark v3.0 through TATER's multi-cloud posture scanning.
Server and workstation hardening for Ubuntu and Red Hat Enterprise Linux, evaluated locally by the cross-platform TATER Agent — filesystem, service, network, logging, and access-control checks mapped to the CIS Linux benchmarks.
Microsoft SQL Server configuration hardening — surface-area, authentication, authorization, auditing, and encryption settings — assessed against the CIS SQL Server benchmark.
Container host and daemon hardening — daemon configuration, image and build files, container runtime, and Docker security operations — evaluated against the CIS Docker benchmark.
Kubernetes control-plane and worker-node security — API server, etcd, kubelet, RBAC policies, and pod security — mapped to the CIS Kubernetes benchmark.
Cisco router and switch hardening — management-plane, control-plane, and data-plane configuration for IOS and NX-OS — assessed against the CIS Cisco benchmarks.
Palo Alto Networks firewall hardening — device management, security zones and policies, logging, and threat-prevention configuration — mapped to the CIS Palo Alto Firewall benchmark.
The Cybersecurity Framework 2.0 adds Govern alongside Identify, Protect, Detect, Respond, and Recover. TATER cross-maps your existing technical controls to CSF functions and categories, providing a risk-based maturity view without duplicate evaluation.
Prioritized set of safeguards organized into Implementation Groups (IG1, IG2, IG3). TATER maps your technical scan results to CIS Controls and shows which Implementation Group level your organization currently achieves across all 18 control areas.
Create organization-specific or industry-specific frameworks with the visual framework builder. Define custom domains, map controls with threshold logic, import/export JSON for MSP distribution, and cross-reference your custom framework to any standard framework.
TATER Ops ships three ITIL 4-aligned process profiles out of the box: Incident Management (8-state lifecycle, impact/urgency/severity, business service, configuration items, per-priority SLAs), Service Request (Approval Pending + Fulfilled states, customer-visible by default), and Problem Management (root-cause analysis + Known Error states). Field-visibility templating means your team only sees the columns the chosen process requires.
The Computer Security Incident Handling Guide lifecycle (Detected → Triage → Contained → Eradicating → Recovering → Resolved → Post-Incident Review → Closed) ships as a pre-seeded process profile with a False Positive branch and aggressive Critical SLAs (15-minute response). Use it standalone for security incident response or alongside the ITIL Incident profile for split ITSM/SecOps workflows.
Govern the AI tools, models, and agents your organization uses. The AI Governance pack ships an AI System Inventory (classified by EU AI Act risk tier — prohibited / high-risk / GPAI / limited / minimal) and a 22-control checklist crosswalked across ISO/IEC 42001 (clauses 4–10 + Annex A), the NIST AI RMF (Govern / Map / Measure / Manage), and the EU AI Act (risk management, data governance, transparency, human oversight, logging). AI systems link to your vendor register for third-party AI supply-chain risk, and posture rolls up into TATER Insights — answering "what AI do we use, how is each classified, and are our AI controls in place?" as the EU AI Act comes into force.
SOC 2 readiness without re-scanning. TATER crosswalks the Trust Services Criteria — the mandatory Common Criteria (CC1–CC9) plus the optional Availability, Confidentiality, Processing Integrity, and Privacy categories — to the M365 control checks it already evaluates (MFA, conditional access, privileged-access management, logging, DLP, device compliance, and more). A computed readiness view shows coverage per category and per criterion, citing the exact controls that evidence each one and flagging the criteria that remain auditor-attested. Surfaced in TATER Insights and queryable from the MCP server for live SOC 2 gap analysis.
A practitioner-grade view of where TATER does the work for you and where Manual Review is required. Every number below is an exact count from the control catalog that ships with the product — not an estimate — and matches the per-framework counts on the cards above. "Predict the Unknown" surfaces a confidence-rated guess for unscanned manual controls, so the Manual Review column is not the whole picture.
Crosswalk frameworks are not scanned separately: their coverage is inherited from the scanned baselines above by identifier mapping, alongside the TATER governance controls listed for each. The endpoint and infrastructure benchmarks on the cards above — Windows 11 and Windows Server, Intune, Edge, Chrome, Defender Antivirus, Linux, macOS, AWS, Docker, Kubernetes, Cisco, Palo Alto, SQL Server and the DISA STIGs for Windows and Linux (the other 50 of the 62 DISA controls) — add a further 4,079 controls evaluated on-device by the TATER Agent; their pass / fail / manual outcome is decided per device at scan time, so there is no fixed catalog split to publish here. Not Applicable and Skipped are likewise per-tenant runtime outcomes driven by your licensed service plans, not catalog properties. Manual Review controls represent legitimate human-in-the-loop checks (paper policies, vendor attestations, training records) that no platform can fully automate. Predict the Unknown surfaces a TATER-generated confidence-rated guess for unscanned controls so coverage gaps are explicit instead of invisible.
TATER does not rely on self-assessment questionnaires. Every control is evaluated against live configuration data collected from your tenant and endpoints.
TATER reads the live configuration of Microsoft 365, Exchange Online, Defender, and Intune, while the TATER Agent runs CIS benchmarks on Windows, Linux, and macOS machines.
The V2 threshold engine analyzes each data point using typed evaluators: boolean, compare, includes, excludes, count, regex, and composite (AND/OR) rules. No ambiguity-every control has a deterministic pass/fail outcome.
Each evaluated control is cross-mapped to every framework it satisfies. One MFA control maps to NIST AC-7, ISO A.8.5, SOC CC6.1, PCI 8.3, and HIPAA 164.312(d) simultaneously. Evidence collected once serves all frameworks.
Gap analysis breaks each framework into sections with per-section compliance percentages. AI-generated narratives, exportable reports, and trust center dashboards present results to auditors, executives, and clients.
Many compliance frameworks share overlapping requirements. Enabling MFA satisfies controls in NIST AC-7, ISO 27001 A.8.5, SOC 2 CC6.1, PCI-DSS 8.3, and HIPAA 164.312(d). TATER identifies these overlaps and maps them automatically, reducing audit preparation from weeks to hours.
TATER breaks each framework into its constituent sections and shows which controls map to each one, along with the current compliance percentage. Drill down from framework to section to individual control status in seconds.
For each standard section, TATER analyzes your linked controls, their current pass/fail status, overrides, and exceptions-then generates a narrative tailored to your actual posture. Not generic boilerplate. Your specific implementation, described accurately.