CIS Benchmark as a Cyber Insurance Requirement: What SMB Carriers Now Expect
By Jonathan Fykes, CTO · Published · Last updated
TL;DR
- The CIS Microsoft 365 Foundations Benchmark v3 is the standard most cyber insurance carriers now reference by name on 2026 renewal questionnaires. Maintained by the Center for Internet Security, it sorts controls into Implementation Group 1 (basic), Group 2 (intermediate), and Group 3 (advanced).
- For a 30-person business, the practical bar is all of IG1 plus roughly 60 to 70 percent of IG2. Most of IG3 is overkill at SMB scale and you will not be penalized for skipping it.
- The benchmark covers eight sections: account and authentication, application permissions, data management, Exchange Online, auditing, storage, mobile device management, and Microsoft Teams. Carriers focus on roughly 12 to 15 specific recommendations across those eight sections.
- Carriers almost never verify alignment up front. They rely on attestation. The verification happens after a claim, when forensics audits whether the controls you said were in place actually were. That is when overstated answers become claim disputes.
- Honest CIS alignment looks like a self-assessment, a named control owner, an annual review, and a dated report. "Aligned with CIS" is the answer that passes. "Compliant with CIS" without a third-party audit is the answer that gets you in trouble.
You sat down to fill out the 2026 renewal application and the cover sheet referenced "CIS Microsoft 365 Foundations Benchmark v3" by name. It might have been a footnote next to the MFA question. It might have been a whole section asking which of the eight benchmark domains you have implemented. Either way, the framework that did not appear on your 2023 questionnaire is suddenly load-bearing on your 2026 one.
You are not alone in noticing the shift. Brokers report that 2026 is the year CIS went from "an underwriter sometimes mentions it" to "an underwriter sometimes requires it." This guide explains what the benchmark actually is, why carriers landed on it, which of its recommendations they actually ask about, and how to answer the questionnaire in a way that holds up after a claim.
What the CIS Microsoft 365 Foundations Benchmark actually is
The benchmark is a public document. You can download it from cisecurity.org. It is currently at version 3, last updated in mid-2025, and it lists somewhere around 120 specific configuration recommendations for a Microsoft 365 tenant. Each recommendation has a number, a description, the rationale for the control, the audit procedure (how you verify it is set), and the remediation procedure (how you set it).
The Center for Internet Security writes and maintains it. CIS is an independent nonprofit that has published security benchmarks since 2000. They write benchmarks for Windows, Linux, AWS, Azure, Kubernetes, and dozens of other platforms. The benchmarks are written by working groups that include practitioners, vendors, and academic researchers, and the M365 working group includes Microsoft engineers as contributors.
That last detail matters to underwriters. CIS is not Microsoft marketing. It is not an MSP's internal opinion. It is a third-party document with a public methodology, a versioned change log, and a community process for handling disputes. When a carrier asks "are you aligned with CIS," they are asking a question with a specific, externally verifiable answer.
Why carriers converged on CIS rather than something else
Cyber insurance underwriters spent years asking custom questions. Each carrier had its own list. The lists overlapped at the obvious controls (MFA, backups, patch cadence) but diverged everywhere else. Brokers complained. Insureds complained. And underwriters noticed something more concerning: the custom questions were hard to defend in court when a claim got disputed.
If a carrier asks "do you have strong access controls" and pays out a claim, they are arguing about what "strong" means. If they ask "are you aligned with CIS Microsoft 365 Foundations Benchmark Implementation Group 1," they are pointing at a document. The shift to a referenced standard gives the underwriter a defensible posture for both pricing and claim adjudication.
CIS won the convergence over a few alternatives for practical reasons. NIST Cybersecurity Framework 2.0 is excellent for risk management but does not give you specific tenant settings. ISO 27001 is too heavy for SMB scope and requires a third-party audit. CISA's Secure Cloud Business Applications baseline is solid but newer and less established. The CIS benchmark is mature, free, control-specific, and aligns to NIST CSF and ISO 27001 in a published mapping document. For an underwriter writing SMB business, it is the practical choice. The deeper comparison between CIS and CISA's baseline lives in a separate breakdown of which framework a carrier actually wants to see.
The eight sections of the benchmark and what each one covers
Knowing the benchmark in shape rather than in detail helps you read your questionnaire. Carriers tend to ask one or two questions per section, not 120 questions across the whole document. Here is the lay of the land.
1. Account and authentication policies
Roughly 20 recommendations covering how users sign in. MFA enforcement, Conditional Access, password policy, sign-in risk policies, named admin accounts, break-glass account handling, and the rule that legacy authentication protocols are blocked entirely. This is the section carriers ask about hardest because it is where credential-stuffing attacks land.
2. Application permissions
OAuth consent settings, third-party app registrations, restrictions on what users can authorize without admin approval, and the inventory of apps that already have tenant-wide consent. The control most often missed here is restricting user consent to verified publishers, which closes the OAuth consent phishing path.
3. Data management
SharePoint and OneDrive sharing settings, external sharing controls, sensitivity labels, data loss prevention policies, and retention. The benchmark recommends that "Anyone" links be disabled tenant-wide, that external sharing default to "specific people," and that sensitivity labels be applied to documents marked Confidential or higher.
4. Email security and Exchange Online
Anti-phishing policies, Safe Links, Safe Attachments, anti-spam, anti-malware, transport rules for blocking executable attachments, and the trio carriers always ask about: SPF, DKIM, and DMARC at p=reject for every sending domain. About 25 of the benchmark's recommendations live here, and email security is the second-most-asked area on insurance forms.
5. Auditing
Unified audit log enabled, mailbox auditing on for every user, retention configured beyond the default, and alerting policies for the high-risk operations (mass deletes, mailbox forwarding rule creation, new admin role assignments). The benchmark wants 365 days of retention. Most SMB plans only give you 90 days without an add-on.
6. Storage
OneDrive retention, SharePoint default sharing levels, version history, and the recycle bin behavior. Smaller section, less hotly asked, but easy points if you happen to have it set right.
7. Mobile device management
Intune enrollment policies, device compliance requirements, conditional access tied to compliant device, and rules for BYOD. This is one of the sections SMBs miss most often because they did not buy the licensing or never built the policies.
8. Microsoft Teams
Guest access controls, external federation, meeting policies, app permission policies inside Teams, and channel email handling. Newer section in v3. Carriers are starting to ask about it but the questions are still narrower than the email or auth sections.
Implementation Groups: IG1, IG2, and IG3 in plain English
The benchmark sorts every recommendation into one of three Implementation Groups. The split is the most useful concept in the document because it tells you what is mandatory, what is reasonable, and what is overkill at your size.
Implementation Group 1 (IG1) is the basic cyber hygiene every business should have, regardless of size or industry. About 60 of the benchmark's recommendations sit in IG1. Block legacy auth, enforce MFA, enable the audit log, set DMARC, restrict OAuth consent, configure Safe Links. None of it requires advanced tooling. For a 30-person business, IG1 is the floor. If you cannot answer "yes" to all of IG1, you have work to do regardless of insurance.
Implementation Group 2 (IG2) adds intermediate controls for businesses with sensitive data or regulatory exposure. Sensitivity labels, DLP policies, compliant-device Conditional Access, mailbox audit retention beyond 90 days, named admin separation with Privileged Identity Management. About 40 recommendations. For most SMBs, the practical bar is IG1 fully plus 60 to 70 percent of IG2 — the parts that match your actual data sensitivity.
Implementation Group 3 (IG3) is the advanced tier for organizations with mature security programs, in-house SOC capability, and regulatory frameworks that demand it. Just-in-time admin access, custom Sentinel detections, deep app governance, advanced eDiscovery. About 20 recommendations. Almost always overkill for a 30-person business. Carriers do not penalize SMBs for skipping IG3.
If you only do one thing after reading this section: stop thinking of CIS as a single bar to clear and start thinking of it as a tiered set. Your insurance answer is "we are fully aligned to IG1 and partially aligned to IG2, with IG3 controls applied where they apply." That sentence, with documentation behind it, is the answer carriers want.
The 12 to 15 controls insurance questionnaires actually ask about
Carriers do not audit your tenant against all 120 recommendations. They cherry-pick the dozen or so that correlate with claim frequency. If you target these, you cover most of what a 2026 questionnaire is actually asking.
- MFA enforced for all users via Conditional Access. Not "MFA available." Enforced. The full breakdown of how carriers ask the MFA question is in the MFA cyber insurance requirement deep-dive.
- Legacy authentication blocked. Both at the Conditional Access layer and at the Exchange Online authentication policy layer. Cross-network walk-through: how to block legacy authentication in Microsoft 365.
- Conditional Access requiring compliant device for admin role activations. Admins should not be able to elevate from a personal laptop with no security baseline.
- Named admin separation. Daily-driver accounts hold no admin roles. Each admin has a separate cloud-only account used only for admin work.
- Unified audit log enabled and retained. Default retention is 90 days. The benchmark wants 365 days. The carrier wants enough retention that forensics has data to work with.
- Mailbox auditing on for every user. Not just admins. Every mailbox.
- SPF, DKIM, and DMARC configured. DMARC at p=reject for the primary sending domain is the answer that passes. p=none gets flagged.
- Defender for Office 365 anti-phishing policies. Impersonation protection on the executive accounts. Safe Links and Safe Attachments in block mode, not audit.
- Sensitivity labels for Confidential data. Not labeling everything. Labeling the documents that would actually hurt if they leaked.
- OAuth consent restricted. User consent limited to verified publishers, with admin approval required for new app registrations.
- External sharing restricted. "Anyone" links disabled tenant-wide for SharePoint and OneDrive.
- Mobile device management for BYOD. Either Intune-enrolled or app-protection-policy-protected. The carrier does not want personal phones with full mailbox access and no compliance posture.
- Phishing simulation program. At least quarterly, with completion tracking and remediation for repeat clickers.
- Vendor risk reviews. Annual review of vendors with M365 access, SOC 2 reports collected for those processing sensitive data.
- IR plan tabletop in the last 12 months. The plan itself satisfies one question. The dated tabletop satisfies the second one most carriers now ask.
The full carrier-side mapping of these to questionnaire wording lives in the cyber insurance requirements 2026 reference, which walks through what passes versus what gets flagged on each question.
The seven CIS controls SMBs miss most often
Across the gap analyses we see, the same shortlist of misses keeps showing up. None of these are advanced. They are the ones that get skipped because they take governance work, not just a settings change.
1. Audit log retention beyond 90 days. Default M365 retention is 90 days. By the time a breach is noticed, 90 days is gone. The fix is either an E5 plan, the Audit add-on, or shipping logs to a SIEM with longer retention.
2. Named admin separation. Most SMBs run on a single admin account that is also the owner's daily mailbox. That account is the highest-value target in the tenant and it sits exposed to phishing every minute it is signed in.
3. Mobile device management for BYOD. Personal phones with native mail apps connected to corporate mailboxes, no compliance posture, no remote wipe. The benchmark wants either Intune enrollment or App Protection Policies. Most SMBs have neither.
4. Sensitivity labels for Confidential data. Either nobody set them up, or somebody set up 12 labels and nobody applies them.
5. Phishing simulation program. "We did one in 2023" is not a program. The benchmark and the carriers both want quarterly cadence with results tracked.
6. Vendor risk reviews. A list of M365-connected vendors, an annual look at each one, and a folder of SOC 2 reports. The work is light. The discipline is the part that lapses.
7. IR plan tabletop in the last 12 months. The written plan often exists. The dated exercise rarely does.
The first three are M365 settings work. The last four are governance work, and that is where outside help typically pays for itself. The full evidence-collection workflow lives in the cyber insurance compliance checklist for the questionnaire side, and the deployment-side walk-through is at how a small business actually implements the CIS M365 benchmark.
How carriers verify CIS alignment (mostly: they do not)
This is the part of the conversation people get wrong. Almost no SMB-segment carrier verifies CIS alignment up front. Underwriting is fast, premiums are tight, and a per-policy audit would cost more than the policy. So they accept attestation. You sign that the controls are in place. They price based on your answers.
The verification happens after a claim. When a ransomware incident triggers a payout, the carrier sends a forensics vendor in. That vendor reconstructs what was actually configured at the time of the incident: which Conditional Access policies were on, whether legacy auth was blocked, what the audit log shows, whether MFA was actually enforced for the compromised user. The forensics report goes back to the carrier's claims team. Gaps between what you attested and what was actually there are where claim disputes live.
Three patterns we see in disputed claims, all stemming from CIS-adjacent answers:
Attested MFA enforcement, actual partial enforcement. A user had MFA registered but the Conditional Access policy excluded their group "for testing." Forensics finds the exclusion and the carrier reduces the payout citing material misrepresentation.
Attested audit log retention, actual default 90 days. The breach was in the tenant for 130 days before discovery. The carrier asked for sign-in logs from before the dwell-time window. They were already gone. Settlement reduced because root cause cannot be established.
Attested IR plan with tabletop, actual document never exercised. The plan exists but the response in real time was ad hoc. Carrier flags as failure to follow stated incident procedures and disputes business interruption coverage.
The takeaway: do not over-claim. The audit happens at claim time, when you cannot fix anything. The post-breach version of this same lesson is in the deeper walk-through on CIS Benchmark versus Microsoft Secure Score and what each score actually proves.
CIS vs CISA vs NIST CSF vs ISO 27001 in one paragraph each
Knowing which framework matters when keeps you from wasting time on the wrong certification.
CIS Microsoft 365 Foundations Benchmark. Control-specific tenant settings. The framework most SMB cyber carriers reference by name in 2026. Free to download, self-assessable, mappable to NIST CSF and ISO 27001. If you do one framework alignment exercise, do this one.
CISA Secure Cloud Business Applications (SCuBA). CISA's M365 baseline, written for federal agencies and contractors. Heavy overlap with CIS at the control level, slightly different scoring, slightly different priorities. If you sell to federal or you are in a regulated supply chain, your auditor may ask for CISA. Most commercial SMB carriers do not.
NIST Cybersecurity Framework 2.0. Risk management framework, not a control list. The five functions (Identify, Protect, Detect, Respond, Recover) are the right way to organize a security program but NIST CSF will not tell you which Conditional Access policy to deploy. Use it to structure governance. Use CIS for the settings.
ISO 27001. An information security management system standard. Requires a third-party certification audit. Heavy lift, expensive, and a multi-year process to reach certification. Useful if you sell into European markets or enterprise customers who require it. Almost no SMB cyber carrier asks for ISO 27001 — it is a customer-contract requirement, not a renewal-questionnaire one.
For a 30-person business in 2026, the right answer is: align to CIS, organize the program around NIST CSF, ignore ISO 27001 unless a customer specifically asks, watch CISA in case it becomes relevant.
How to claim CIS alignment honestly on a renewal questionnaire
The wording matters. Carriers and their lawyers parse the difference between "compliant" and "aligned with" carefully. So should you.
"Compliant with CIS" implies a third-party audit that confirms every applicable recommendation is implemented. Without that audit, you cannot defend the word "compliant" in a claim dispute. Use it only if you have an actual attestation from a qualified assessor.
"Aligned with CIS Microsoft 365 Foundations Benchmark Implementation Group 1, with partial alignment to Implementation Group 2" is the answer most SMBs can defend. It is honest, it is specific, and it gives the carrier the framework reference they want without overstating your posture.
Four things make an alignment claim defensible after a claim:
- A self-assessment dated within the last 12 months. A simple spreadsheet listing each applicable CIS recommendation, the IG it is in, the current setting in your tenant, and the date verified. This is the artifact that proves you did the work.
- A named control owner. One person responsible for the benchmark inside your business. That can be your IT vendor, an outside consultant, or you. The point is somebody owns it.
- An annual review. Each year, somebody checks whether the controls drifted, whether new recommendations got added in the latest benchmark version, and whether your scope changed.
- A documented scope statement. Which recommendations apply to you and which do not. If you do not have Microsoft Teams turned on for external federation, the federation recommendations are out of scope. Document that, do not pretend.
Together those four pieces are what a forensics vendor will look for when they reconstruct your security posture after an incident. Have them on hand and the alignment claim holds. Do not have them and the claim becomes a liability.
What changes for 2027 and beyond
The benchmark is not static. CIS publishes new versions roughly every 12 to 18 months, and carriers update their questionnaires on a similar cadence. Three shifts are visible on the horizon.
First, phishing-resistant MFA is moving from IG2 best practice to IG1 baseline. Push notifications and SMS are losing favor because adversary-in-the-middle phishing kits defeat both. Expect FIDO2 or Windows Hello for admin accounts to be a standard 2027 questionnaire item.
Second, Microsoft Teams is getting more attention. The 2026 benchmark added Teams as a full section. Carriers are catching up on the questions. By 2027, expect questions about guest access, external federation, and app permission policies to be standard.
Third, AI-related controls are starting to appear. Copilot governance, Azure OpenAI access, and data exposure to AI services are all topics CIS is actively working on for the next benchmark version. Carriers will follow.
None of this changes the playbook. Align to the current benchmark, document your scope, review annually, and the benchmark version updates become small course corrections rather than fire drills.
Frequently asked questions
Does my carrier require CIS, or just reference it?
Read the questionnaire wording. "Aligned with" or "consistent with" is a reference, and a partial answer is acceptable as long as you disclose what is missing. "Compliant with" or "must implement" is a requirement, and a no answer typically gets either a non-renewal or a sub-limit. Most 2026 SMB-segment carriers reference rather than require, but the trend line is moving toward requirement language for accounts above 50 employees.
Do I need to hit every recommendation in the benchmark?
No. You need to hit every recommendation that applies to your scope, document the ones that do not apply, and disclose any in-scope gaps with a remediation date. IG1 is the floor for everyone. IG2 should be partially in place at SMB scale. IG3 is generally out of scope unless you are in a regulated industry with specific drivers. The full list of which controls actually show up on questionnaires is in the cyber insurance requirements FAQ.
Who can perform a CIS self-assessment for an SMB?
Your IT vendor can do the M365 settings side. They run through the benchmark, document each setting, and produce a dated report. The governance pieces (vendor risk, IR plan tabletop, control ownership) usually need internal involvement or a fractional CISO arrangement because they are not settings questions. A CIS-accredited assessor produces a stronger artifact, but for SMB-scale insurance purposes a vendor-produced dated report is generally accepted.
How long does it take to go from no CIS alignment to defensible alignment?
For a 30-person business with reasonable existing M365 hygiene, four to eight weeks. The settings changes take a few days of actual work. The governance side (writing the IR plan, documenting vendor risk, getting a tabletop on the calendar) takes the longer tail. The deployment-side timeline lives in the implementation walk-through on the deployment site.
If we are aligned to CIS, do we still need NIST CSF?
You do not need a separate NIST CSF program. You may still benefit from organizing your security program around the five NIST functions because it gives you a structure for governance reporting that CIS alone does not provide. The two work well together: CIS tells you what to configure, NIST CSF tells you how to think about the program around it.
Find Out Where Your Tenant Stands Against CIS
Our free tenant assessment shows which CIS-aligned controls are already in place and which gaps need to be closed before your next renewal.
Check My Risk