The TATER Control Framework

One original control framework — 4,000+ TATER-authored controls, evaluated with automated scanning and threshold-based analysis — crosswalked to the 30+ standards your auditors ask for: CIS, CISA SCuBA, DISA STIGs, NIST, ISO 27001, SOC 2, PCI DSS, HIPAA, CMMC, UK Cyber Essentials, Australian Essential Eight and more. Collect evidence once; see exactly where each control lands in every framework. Mappings are identifier crosswalks, not certifications.

Explore

Standards at a glance

The frameworks, the coverage model, and how scoring works — drill into any topic for the full detail.

Frameworks Covered

CIS, CISA SCuBA, NIST 800-53, ISO 27001, SOC 2, HIPAA, PCI, UK Cyber Essentials, AU Essential Eight — and 20+ more. One control set, mapped to all of them.

Explore →

Unified Control Model

One control definition, evaluated by a threshold engine, mapped to every framework it satisfies at once.

Explore →

Predict the Unknown

Turn Manual-Review controls into predicted pass/fail from platform defaults, shrinking the unknown surface area.

Explore →

Federal / ATO

POA&M (OMB/eMASS), the NIST RMF 6-step tracker, SSP to OSCAL, and GCC / GCC High / DoD support.

Explore →

Compliance Scoring

How raw configuration becomes a live, per-framework compliance score you can trend over time. Licensing-aware: controls for M365 features you don’t license are auto-marked ⊘ Not Applicable from your tenant’s service plans and excluded from the compliance % — and a Commercial compliance profile can exclude federal / DISA-STIG controls for non-government orgs.

Explore →

M365 Coverage

Entra ID, Exchange, SharePoint, Teams, Defender, Purview & Power Platform — with real per-app control counts.

Explore →
CIS M365 CISA SCuBA DISA STIGs NIST 800-53 ISO 27001 SOC 2 PCI-DSS v4.0 HIPAA NIST CSF 2.0 CIS Controls v8 CIS Windows 11 CIS Windows Server CIS Chrome CIS Edge CIS Intune CIS Defender Antivirus CISA SCuBA (Google Workspace) macOS CIS AWS Foundations CIS Linux (Ubuntu/RHEL) CIS SQL Server CIS Docker CIS Kubernetes CIS Cisco IOS/NX-OS CIS Palo Alto NIST 800-171 / CMMC L2 UK Cyber Essentials AU Essential Eight ITIL 4 NIST SP 800-61 ISO/IEC 42001 NIST AI RMF EU AI Act Custom Frameworks
Compliance Frameworks

One framework, mapped to every standard your auditors care about

TATER evaluates its own control set with real configuration data — not questionnaires — then crosswalks each control to the frameworks below by identifier. A crosswalk shows where a control aligns; it is not a certification or an attestation of compliance.

Regulatory & Industry Frameworks

NIST 800-53 Rev 5

261 controls · 20 families

The gold standard for federal information security. TATER maps M365 and endpoint configurations to all 20 Rev 5 control families-from Access Control (AC) through Supply Chain Risk Management (SR)-giving you a continuous compliance posture instead of point-in-time snapshots.

ISO 27001:2022

93 Annex A controls

Complete Annex A coverage across all four themes: Organizational, People, Physical, and Technological. TATER links technical scan results to each ISO control and generates audit-ready narratives that describe your actual implementation posture.

SOC 2 Trust Services

5 trust service categories

Maps technical controls to Security, Availability, Processing Integrity, Confidentiality, and Privacy criteria. Cross-references automated scan evidence so your SOC 2 Type II audit starts with machine-verified data rather than manual screenshots.

PCI-DSS v4.0

12 requirement areas

Payment Card Industry requirements mapped to your M365 tenant and endpoint configurations. TATER evaluates network segmentation controls, encryption posture, access restrictions, and logging requirements against PCI-DSS 4.0 sections.

HIPAA Security Rule

Administrative, Physical & Technical

Safeguards for electronic protected health information (ePHI) mapped to your actual tenant configuration. Covers access controls, audit controls, transmission security, and authentication requirements from 45 CFR 164.312.

Government & Defense

CISA SCuBA Baselines

130 controls

Secure Cloud Business Applications baselines as mandated by BOD 25-01 for federal agencies. TATER evaluates the SCuBA baselines for Entra ID, Exchange Online, Defender, SharePoint, Teams, and Power BI — 73 of the 130 controls run as automated checks that match CISA's exact evaluation criteria, and the remaining 57 as Manual Review. Google Workspace is covered by its own baseline set, below.

CISA SCuBA — Google Workspace

135 controls

CISA's Secure Cloud Business Applications baselines for Google Workspace, the non-Microsoft half of BOD 25-01. Covers Gmail, Drive & Docs, Calendar, Chat, Meet, Groups, Sites, Classroom, Gemini, and Workspace-wide common controls — sharing policies, authentication requirements, DLP rules, and app access controls. Automated evaluation is in progress: 6 of these controls are checked automatically today (SPF, DKIM, DMARC and 2-Step Verification enrolment); the remaining 129 are catalogued with full guidance for manual review while automated checks are built out.

DISA STIGs

62 controls

Defense Information Systems Agency Security Technical Implementation Guides for DoD-compliant configurations. TATER ships STIG requirements for Entra ID and Intune in the cloud scan and for Windows Server and Linux on the agent — each as a Manual Review control carrying its own guidance, remediation text and evidence capture — plus the full DISA STIG Windows Server 2022 (V1R5) definition to crosswalk against.

NIST 800-171 / CMMC Level 2

110 practices · 14 families

Protection of Controlled Unclassified Information (CUI) for the Defense Industrial Base. TATER crosswalks the 110 NIST SP 800-171 security requirements — aligned to CMMC Level 2 — across all 14 control families, tying each to the M365 and endpoint checks it already evaluates so contractors can track assessment readiness continuously.

UK Cyber Essentials

23 controls · 5 technical themes

The UK NCSC baseline for essential cyber hygiene, across all five technical themes — firewalls, secure configuration, user access control, malware protection, and security update management. TATER maps each to the M365 and endpoint checks it already evaluates, so UK organisations can track Cyber Essentials readiness from live configuration.

Australian Essential Eight

27 controls · 8 mitigation strategies

The Australian Cyber Security Centre (ACSC) Essential Eight mitigation strategies — application control, patch applications, configure Office macros, user application hardening, restrict admin privileges, patch operating systems, multi-factor authentication, and regular backups. TATER crosswalks each strategy to its M365 and endpoint checks for continuous maturity tracking.

Technical Benchmarks (CIS)

CIS Microsoft 365 Foundations

141 controls

The most comprehensive automated benchmark for M365. TATER evaluates every CIS recommendation across all nine benchmark sections — Entra ID, Exchange, SharePoint, Teams, Defender, Purview, and Microsoft Fabric — automatically, on every scan.

CIS Windows 11 Enterprise

731 controls

Endpoint hardening for Windows 11 evaluated locally via the TATER Agent. Checks security policies, registry settings, audit policies, firewall rules, and service configurations against the full CIS L1 and L2 benchmark.

CIS Windows Server

580–620 controls per version

Server hardening benchmarks for Windows Server 2019, 2022, and 2025. Each version gets version-specific checks covering security options, user rights, audit subcategories, and Windows Firewall with Advanced Security profiles.

CIS Microsoft Intune

800 controls (Windows 11 + Office)

Device configuration compliance for Intune-managed endpoints. Evaluates Settings Catalog policies, device configuration profiles, and compliance policies against CIS Intune benchmarks for both Windows 11 and Microsoft 365 Apps.

CIS Google Chrome

134 controls

Browser hardening for Google Chrome evaluated via Group Policy and registry settings. Covers security, privacy, content, extensions, and network policies to ensure browsers do not become attack vectors.

CIS Microsoft Edge

285 controls

Comprehensive Edge browser benchmark including SmartScreen, InPrivate mode, password manager, telemetry, and extension controls. Evaluated locally by the TATER Agent alongside other endpoint benchmarks in a single scan pass.

CIS Microsoft Defender Antivirus

64 controls

Antimalware hardening evaluated on-device by the TATER Agent: all 17 Attack Surface Reduction rules plus cloud-delivered protection and MAPS reporting, real-time and behavior monitoring, archive and removable-drive scanning, scheduled scan and signature-update policy, quarantine handling, and blocking of potentially unwanted applications.

Infrastructure & Cloud Benchmarks (CIS)

CIS AWS Foundations v3.0

Cloud posture (CSPM)

Foundational AWS account-security controls — IAM, logging (CloudTrail / Config), monitoring, networking, and storage exposure — evaluated against the CIS AWS Foundations Benchmark v3.0 through TATER's multi-cloud posture scanning.

CIS Linux (Ubuntu / RHEL)

Endpoint hardening

Server and workstation hardening for Ubuntu and Red Hat Enterprise Linux, evaluated locally by the cross-platform TATER Agent — filesystem, service, network, logging, and access-control checks mapped to the CIS Linux benchmarks.

CIS SQL Server

Database hardening

Microsoft SQL Server configuration hardening — surface-area, authentication, authorization, auditing, and encryption settings — assessed against the CIS SQL Server benchmark.

CIS Docker

Container runtime

Container host and daemon hardening — daemon configuration, image and build files, container runtime, and Docker security operations — evaluated against the CIS Docker benchmark.

CIS Kubernetes

Orchestration security

Kubernetes control-plane and worker-node security — API server, etcd, kubelet, RBAC policies, and pod security — mapped to the CIS Kubernetes benchmark.

CIS Cisco IOS / NX-OS

Network devices

Cisco router and switch hardening — management-plane, control-plane, and data-plane configuration for IOS and NX-OS — assessed against the CIS Cisco benchmarks.

CIS Palo Alto Firewall

Perimeter security

Palo Alto Networks firewall hardening — device management, security zones and policies, logging, and threat-prevention configuration — mapped to the CIS Palo Alto Firewall benchmark.

Cross-Mapping & Emerging Frameworks

NIST CSF 2.0

6 core functions

The Cybersecurity Framework 2.0 adds Govern alongside Identify, Protect, Detect, Respond, and Recover. TATER cross-maps your existing technical controls to CSF functions and categories, providing a risk-based maturity view without duplicate evaluation.

CIS Controls v8

18 control groups

Prioritized set of safeguards organized into Implementation Groups (IG1, IG2, IG3). TATER maps your technical scan results to CIS Controls and shows which Implementation Group level your organization currently achieves across all 18 control areas.

Custom Frameworks

Build your own

Create organization-specific or industry-specific frameworks with the visual framework builder. Define custom domains, map controls with threshold logic, import/export JSON for MSP distribution, and cross-reference your custom framework to any standard framework.

Service Management & Incident Response

ITIL 4

Incident, Service Request & Problem

TATER Ops ships three ITIL 4-aligned process profiles out of the box: Incident Management (8-state lifecycle, impact/urgency/severity, business service, configuration items, per-priority SLAs), Service Request (Approval Pending + Fulfilled states, customer-visible by default), and Problem Management (root-cause analysis + Known Error states). Field-visibility templating means your team only sees the columns the chosen process requires.

NIST SP 800-61

Computer Security IR Handling

The Computer Security Incident Handling Guide lifecycle (Detected → Triage → Contained → Eradicating → Recovering → Resolved → Post-Incident Review → Closed) ships as a pre-seeded process profile with a False Positive branch and aggressive Critical SLAs (15-minute response). Use it standalone for security incident response or alongside the ITIL Incident profile for split ITSM/SecOps workflows.

AI Governance

ISO/IEC 42001 · NIST AI RMF · EU AI Act

Govern the AI tools, models, and agents your organization uses. The AI Governance pack ships an AI System Inventory (classified by EU AI Act risk tier — prohibited / high-risk / GPAI / limited / minimal) and a 22-control checklist crosswalked across ISO/IEC 42001 (clauses 4–10 + Annex A), the NIST AI RMF (Govern / Map / Measure / Manage), and the EU AI Act (risk management, data governance, transparency, human oversight, logging). AI systems link to your vendor register for third-party AI supply-chain risk, and posture rolls up into TATER Insights — answering "what AI do we use, how is each classified, and are our AI controls in place?" as the EU AI Act comes into force.

SOC 2 (Trust Services Criteria)

CC1–CC9 + Availability / Confidentiality / PI / Privacy

SOC 2 readiness without re-scanning. TATER crosswalks the Trust Services Criteria — the mandatory Common Criteria (CC1–CC9) plus the optional Availability, Confidentiality, Processing Integrity, and Privacy categories — to the M365 control checks it already evaluates (MFA, conditional access, privileged-access management, logging, DLP, device compliance, and more). A computed readiness view shows coverage per category and per criterion, citing the exact controls that evidence each one and flagging the criteria that remain auditor-attested. Surfaced in TATER Insights and queryable from the MCP server for live SOC 2 gap analysis.

Coverage matrix

Automated vs. Manual Review per framework

A practitioner-grade view of where TATER does the work for you and where Manual Review is required. Every number below is an exact count from the control catalog that ships with the product — not an estimate — and matches the per-framework counts on the cards above. "Predict the Unknown" surfaces a confidence-rated guess for unscanned manual controls, so the Manual Review column is not the whole picture.

Scanned baselines — Microsoft 365 & Google Workspace
“Automated” counts controls TATER evaluates without human input. Google Workspace automation is newer and still expanding — the figures below are what is implemented today, not what is planned.
Baseline Controls Automated Manual review Automated coverage
CIS Microsoft 365 Foundations Benchmark1411291291%
CISA SCuBA — Microsoft 365130735756%
CISA SCuBA — Google Workspace13561294%
DISA STIG — Microsoft 365 / Entra ID120120%
All scanned baselines41820821050%
Crosswalk targets — mapped by identifier, not scanned separately
Framework Framework size TATER governance controls
NIST SP 800-53 Rev 5261 controls · 20 families36
NIST SP 800-171 Rev 2 / CMMC Level 2110 practices · 14 families30
NIST CSF 2.0106 subcategories · 6 functions30
CIS Controls v8.1153 safeguards · 18 control groups40
ISO/IEC 27001:2022 Annex A93 controls · 4 themes30
PCI DSS v4.0.193 sub-requirements · 12 requirement areas30
SOC 2 Trust Services Criteria62 criteria · 5 trust service categories30
HIPAA Security Rule59 safeguards · 45 CFR 164.308–164.31632

Crosswalk frameworks are not scanned separately: their coverage is inherited from the scanned baselines above by identifier mapping, alongside the TATER governance controls listed for each. The endpoint and infrastructure benchmarks on the cards above — Windows 11 and Windows Server, Intune, Edge, Chrome, Defender Antivirus, Linux, macOS, AWS, Docker, Kubernetes, Cisco, Palo Alto, SQL Server and the DISA STIGs for Windows and Linux (the other 50 of the 62 DISA controls) — add a further 4,079 controls evaluated on-device by the TATER Agent; their pass / fail / manual outcome is decided per device at scan time, so there is no fixed catalog split to publish here. Not Applicable and Skipped are likewise per-tenant runtime outcomes driven by your licensed service plans, not catalog properties. Manual Review controls represent legitimate human-in-the-loop checks (paper policies, vendor attestations, training records) that no platform can fully automate. Predict the Unknown surfaces a TATER-generated confidence-rated guess for unscanned controls so coverage gaps are explicit instead of invisible.

Evaluation Pipeline

From raw configuration to compliance score

TATER does not rely on self-assessment questionnaires. Every control is evaluated against live configuration data collected from your tenant and endpoints.

1

Collect

TATER reads the live configuration of Microsoft 365, Exchange Online, Defender, and Intune, while the TATER Agent runs CIS benchmarks on Windows, Linux, and macOS machines.

2

Evaluate

The V2 threshold engine analyzes each data point using typed evaluators: boolean, compare, includes, excludes, count, regex, and composite (AND/OR) rules. No ambiguity-every control has a deterministic pass/fail outcome.

3

Map

Each evaluated control is cross-mapped to every framework it satisfies. One MFA control maps to NIST AC-7, ISO A.8.5, SOC CC6.1, PCI 8.3, and HIPAA 164.312(d) simultaneously. Evidence collected once serves all frameworks.

4

Report

Gap analysis breaks each framework into sections with per-section compliance percentages. AI-generated narratives, exportable reports, and trust center dashboards present results to auditors, executives, and clients.

Overlap Detection

Eliminate duplicate evidence collection

Many compliance frameworks share overlapping requirements. Enabling MFA satisfies controls in NIST AC-7, ISO 27001 A.8.5, SOC 2 CC6.1, PCI-DSS 8.3, and HIPAA 164.312(d). TATER identifies these overlaps and maps them automatically, reducing audit preparation from weeks to hours.

Cross-Framework Mapping
MFA Policy→ NIST AC-7, ISO A.8.5, SOC CC6.1
Encryption→ NIST SC-28, ISO A.8.24, PCI 3.5
Audit Logs→ NIST AU-2, ISO A.8.15, HIPAA 312(b)
Access Ctrl→ NIST AC-3, ISO A.8.3, SOC CC6.3
DLP Policy→ NIST MP-4, ISO A.8.12, PCI 3.4
Gap Analysis

Know exactly where you stand

TATER breaks each framework into its constituent sections and shows which controls map to each one, along with the current compliance percentage. Drill down from framework to section to individual control status in seconds.

NIST 800-53 Gap Analysis
AC - Access Control
92%
AU - Audit & Accountability
85%
CM - Config Management
78%
IA - Identification & Auth
95%
SC - System & Comms
88%
SI - System & Info Integrity
81%
AI-Powered

Compliance narratives that write themselves

For each standard section, TATER analyzes your linked controls, their current pass/fail status, overrides, and exceptions-then generates a narrative tailored to your actual posture. Not generic boilerplate. Your specific implementation, described accurately.

AI Narrative - NIST 800-53 AC: Access Control
Generated Narrative
The organization enforces multi-factor authentication for all privileged and standard user accounts through Microsoft Entra ID Conditional Access policies. Access reviews are conducted automatically through TATER's control testing schedule, with quarterly recertification of privileged role assignments. Legacy authentication protocols are blocked at the tenant level, and session timeout policies enforce re-authentication after 60 minutes of inactivity.
Linked Controls (6 of 14 passing)
ENT_001 Block Legacy Auth ENT_003 MFA Enforced ENT_005 Session Timeout ENT_010 Privileged Roles ENT_024 MFA Capable ENT_032 Conditional Access
Frameworks Satisfied
NIST AC-7 · ISO A.8.5 · SOC CC6.1 · PCI-DSS 8.3 · HIPAA 164.312(d) · CIS Controls 6.3
300+
Standard sections covered
30+
Frameworks crosswalked
1-Click
Generation per section
Editable
Review, revise, and save

Ready to map your compliance posture?

Get audit-ready across all frameworks in days, not months.

Launch TATER → Contact Sales