CIS vs CISA M365 Baseline Comparison: Which One Should an SMB Pick?

By , CTO · Published · Last updated

TL;DR

  • CIS and CISA SCuBA are two different baselines aiming at the same Microsoft 365 tenant. The controls overlap by roughly 85 percent. The framing, the audience, and the tooling are what differ.
  • CIS Microsoft 365 Foundations Benchmark is community-developed, organized into Implementation Groups 1, 2, and 3, and is the baseline private-sector carriers and auditors reference by name on questionnaires.
  • CISA SCuBA is federal-origin, prescriptive, organized per product (Entra, Exchange, SharePoint, Teams, Defender, Power Platform), and ships with a free assessment tool called ScubaGear.
  • For an SMB with no federal scope, the answer is CIS. For an SMB serving federal or SLTT clients, use SCuBA as the harder bar and claim CIS alignment for everything else.
  • NIST CSF is not a configuration baseline. It is a risk-management framework that sits on top. Carriers asking about NIST CSF alignment expect to see CIS or SCuBA underneath, not instead.

If you have spent any time looking at how to secure your Microsoft 365 tenant, two acronyms keep showing up: CIS and SCuBA. They both promise a checklist. They both reference the same M365 admin centers. They both have control numbers, pass-fail criteria, and people who will sell you a service to deploy them. So which one is the right answer for a 30-person business with a renewal questionnaire on the calendar?

The short version is at the top of the page. The longer version walks through what each baseline actually is, where they overlap, where they meaningfully diverge, and how to pick without doing twice the work. This is written for the owner or CFO who has to answer the form, not the IT consultant who has to deploy it.

What the CIS Microsoft 365 Foundations Benchmark actually is

The Center for Internet Security has been publishing technology configuration benchmarks since 2000. The Microsoft 365 Foundations Benchmark is one of several hundred CIS benchmarks covering everything from Windows Server to AWS to Kubernetes. Two things make CIS the de facto private-sector reference.

First, the benchmarks are written by a consensus community of practitioners. Microsoft engineers, MSP technicians, security consultants, and academics propose changes, argue them out on the CIS WorkBench, and ship a new version every 12 to 18 months. There is no single vendor agenda baked in.

Second, CIS organizes its controls into Implementation Groups. IG1 is the baseline every organization should hit, IG2 adds controls for businesses handling sensitive data, and IG3 is for organizations that face advanced adversaries and have the staffing to defend against them. For a 30-person business, IG1 plus a few IG2 controls is usually the right ceiling. You are not trying to defend against a nation-state. You are trying to not get ransomwared and to pass a questionnaire.

Each control is specific. It tells you the M365 admin portal where the setting lives, the value it should be set to, the audit procedure that proves it, and the rationale. The benchmark for M365 contains roughly 70 controls covering Entra ID, Exchange Online, SharePoint, Teams, Defender, and tenant-wide configuration.

Carriers reference CIS by name on questionnaires more often than any other framework. Brokers know it. Auditors know it. The compliance person at your client knows it. That recognition matters when the form asks "describe the security baseline you have deployed" and you have ten lines of free-form text to answer.

What CISA SCuBA actually is

SCuBA stands for Secure Cloud Business Applications. It is a project run by the Cybersecurity and Infrastructure Security Agency, the federal agency under the Department of Homeland Security that, among other things, tells federal civilian agencies how to defend their networks. SCuBA started in 2022 in the wake of the SolarWinds incident and was meant to give federal agencies a prescriptive baseline for the SaaS platforms they were rapidly adopting.

The output is two things bundled together. The first is a set of configuration baseline documents, one per Microsoft 365 product: Entra ID, Exchange Online, SharePoint and OneDrive, Teams, Defender, and Power Platform. The second is ScubaGear, an open-source PowerShell tool that connects to your tenant, reads the live configuration, and produces a pass-fail report against the baselines.

SCuBA differs from CIS in three ways that matter in practice. It is more prescriptive, with less "your call" room on individual controls. It is more current, with updates landing every few months rather than every year and a half. And it is product-organized rather than topic-organized. If you want to know everything you should turn on inside Entra ID, you read one document. The CIS benchmark is organized by control category, so Entra controls are sprinkled across several sections.

SCuBA was designed for federal agencies and for state, local, tribal, and territorial governments, collectively called SLTT. Federal contractors with cloud-hosted regulated data are the next obvious audience. Outside that audience, adoption is growing because the tooling is free and the prescriptions are tight, but it is not the framework a typical commercial cyber insurance carrier asks about by name.

Where the two baselines actually agree

Before getting into where CIS and SCuBA differ, it is worth being honest about how much they overlap. The controls cover roughly the same M365 surface area. Both want MFA enforced on all users. Both want legacy authentication blocked. Both want Conditional Access policies separating admin sessions from regular user sessions. Both want audit log retention enabled, anti-phishing policies turned on, and external sharing constrained.

If you deploy either baseline thoroughly, you will satisfy 80 to 90 percent of the other one as a side effect. The disagreements are at the edges, and they are mostly about how prescriptive the wording is.

Side-by-side: how each baseline handles the questions you will be asked

Here is how the two baselines handle the M365 controls that show up most often on questionnaires and audits.

Control area CIS approach SCuBA approach
MFA enforcementAll users via Conditional Access; phishing-resistant for admins recommendedAll users; phishing-resistant required for highly privileged roles
Conditional Access scopeBlock legacy auth, require MFA, baseline policy setNamed device-compliance policies for admins, explicit risk-based policies for users, named exclusion accounts
Legacy authenticationBlock via Conditional AccessBlock via CA plus Exchange Online authentication policy as backstop
Anti-phishingDefender for O365 anti-phishing on, impersonation protection enabledSpecific Safe Links and Safe Attachments policy values, named impersonation list, action verbs prescribed
Audit log retentionUnified audit log on, retention period set to organizational requirementUnified audit log on, minimum retention 180 days, sign-in logs forwarded to SIEM
External sharingSharePoint and OneDrive external sharing limited to specific domains or guest accountsSame plus per-link expiration, anonymous link disabled tenant-wide
Mobile device managementIntune compliance policies recommended; light on specificsIntune compliance with named policies, app protection policies on managed apps
Power PlatformLimited coverage in current benchmark versionDedicated Power Platform baseline with DLP policy specifics
TeamsExternal access, federation, and meeting policies covered in detailExternal access covered, meeting policy specifics tighter, anonymous join policies prescribed

The pattern is consistent across the comparison. CIS gives you the goal and a recommended setting. SCuBA gives you the goal, a recommended setting, the policy name to use, and the named exception list. If you are deploying without much M365 expertise, SCuBA's prescriptiveness is helpful. If you have an experienced administrator who wants room to fit policies to the business, CIS is more comfortable.

Where each baseline maps onto a real use case

The right pick depends on who is asking the question. Here is how the audiences sort out in practice.

Cyber insurance attestation. CIS, every time. Carriers have referenced CIS in questionnaires for years. The phrasing on most 2026 forms is some version of "do your controls map to the CIS Microsoft 365 Foundations Benchmark." Saying "yes, IG1 with selected IG2 additions, last assessed [date]" is the answer that closes the question. The full breakdown of how this lands on the form is in our piece on CIS Benchmark as a cyber insurance requirement.

SMB audit and questionnaire defense. CIS again. When a client sends a security questionnaire as part of a procurement process, they almost never reference SCuBA, but they regularly reference CIS or NIST CSF. Producing a CIS-formatted assessment report is a standard deliverable that auditors recognize. The format and what it should contain is covered in CIS M365 benchmark reports for auditors.

Federal contractor or SLTT client. SCuBA is the higher bar, so use SCuBA. Federal agencies are required to align to SCuBA under CISA's Binding Operational Directive 25-01, and that requirement flows downhill to contractors handling federal data. SLTT entities are increasingly adopting SCuBA voluntarily because the tooling is free and the prescriptions are clear. If you have federal scope, deploy SCuBA, then claim CIS alignment for the commercial questionnaire. The two are not contradictory.

Mixed-portfolio SMB serving both commercial and government clients. Pick SCuBA as primary, map to CIS for the commercial side. SCuBA is stricter than CIS on most overlapping controls, so if you pass SCuBA you pass CIS for the same control. Going the other direction does not always work; a CIS-aligned tenant may fail a SCuBA-specific control like a named device-compliance policy for admins.

Greenfield deployment with limited budget. CIS, IG1 only. The entire point of IG1 is "this is the floor for any organization." Hit the floor. Add IG2 controls as the business grows or sensitive data shows up. The walk-through for actually deploying it is on the sister site at implementing the CIS M365 Benchmark for small business.

How NIST CSF fits in (and why it is a different category)

If your insurance broker, auditor, or client mentions the NIST Cybersecurity Framework, do not mistake it for a competitor to CIS or SCuBA. NIST CSF is a risk-management framework. It organizes security into six Functions: Govern, Identify, Protect, Detect, Respond, Recover. Inside each Function are Categories and Subcategories that name what an organization should be doing, not what specific setting to flip.

NIST CSF does not tell you to require MFA. It tells you the organization should "manage authentication." That is a goal statement, and it is intentional. NIST CSF is supposed to work whether you are running an M365 tenant, a Google Workspace tenant, a fleet of Linux servers, or a mainframe in a closet.

Where CIS and SCuBA fit is underneath NIST CSF. They are configuration baselines that map up to specific NIST CSF Subcategories. When the CSF says "manage authentication," CIS or SCuBA are the documents that tell you exactly which Conditional Access policies and authentication methods satisfy that Subcategory inside M365. NIST CSF gives you the structure to talk to the board about your security posture. CIS or SCuBA give you the configuration evidence.

So when a carrier asks about NIST CSF alignment, the right answer is some version of "yes, our controls map to NIST CSF 2.0; the underlying configuration baseline is CIS Microsoft 365 Foundations Benchmark IG1." That answer satisfies both the framework question and the baseline question in one sentence.

Where CIS and SCuBA actually disagree

The 15 percent of controls that differ are usually about how much room the baseline gives you. SCuBA tightens the screws on Conditional Access in particular. The SCuBA Entra baseline calls out specific policy names, requires device-compliance gating for admin sessions, and prescribes a named break-glass account exclusion list. CIS asks for the same outcomes but leaves the implementation choices to the administrator.

SCuBA also goes deeper on Defender for Office 365, with specific values for Safe Links time-of-click protection, Safe Attachments dynamic delivery, and impersonation protection coverage. CIS covers the same controls but at the level of "enable this feature." If you are deploying without senior M365 expertise, SCuBA's specificity reduces decisions. If you have someone who knows the tenant well, the extra prescription can feel rigid.

Going the other direction, CIS has broader coverage of Microsoft Teams and SharePoint sharing controls than SCuBA does today. CIS also includes Power Platform guidance that SCuBA addressed later. Both baselines are catching up to each other on the parts they covered first, so the gap is narrowing each release cycle.

Practically, the differences mean that an organization aligned to SCuBA passes CIS controls almost automatically. An organization aligned to CIS passes most SCuBA controls but may fail on the named-policy prescriptions and on a few Defender for O365 specifics. The asymmetry is intentional. SCuBA was designed as a stricter overlay, not a parallel track.

The "doing both" trap

A pattern shows up in client conversations: the IT consultant suggests "let us deploy CIS Level 1 and SCuBA together to cover all the bases." On the surface that sounds thorough. In practice it creates work without buying much extra security.

The 85 percent overlap means the work splits roughly into three buckets. The shared controls get done once and counted twice. The CIS-only controls add a small amount of unique work. The SCuBA-only controls add more, mostly in the form of named policies and stricter Conditional Access rules. The total time spent is maybe 30 percent more than picking one baseline. The total documentation overhead is closer to double, because every control needs to be cross-walked between the two and the evidence collected against each.

For an SMB without a federal requirement, that overhead does not produce commensurate security gain. The marginal SCuBA controls are not bad controls. They are the same controls the IT team would consider deploying anyway as the program matured. Calling them out as a separate framework exercise creates calendar pressure and audit noise without changing the technical posture much.

The cleaner approach: pick CIS as primary because that is what carriers and auditors recognize. Map a handful of high-value SCuBA-specific controls onto the deployment plan as discrete items, especially the named Conditional Access policies for admins and the tighter Defender for O365 settings. Do not run two parallel attestation processes.

The decision tree, written out

If you want one paragraph to bring to your IT vendor or your broker, here it is.

If your business has zero federal or SLTT scope and your driver is cyber insurance and commercial procurement, deploy CIS Microsoft 365 Foundations Benchmark IG1 and document against it. If your business handles federal data, contracts with federal agencies, or serves SLTT clients with security requirements, deploy CISA SCuBA as primary and claim CIS alignment for the commercial side. If your business is mixed but commercial leans heavily, default to CIS and adopt the SCuBA-specific Conditional Access prescriptions as enhancements. In all three cases, communicate posture to executives and customers using the NIST CSF Functions as the structure, with CIS or SCuBA as the configuration evidence underneath.

The same decision applies in reverse for breach response. After an incident, the recovery posture has to align to whatever baseline the questionnaire and contract referenced before the incident, not whatever baseline is fashionable that month. Recovery walk-through for the CIS path is in post-breach CIS M365 benchmark recovery.

What carriers actually do with this on the form

Two patterns show up consistently in 2026 questionnaires. The first is a free-form text field asking the applicant to "describe your security configuration baseline." Naming CIS Microsoft 365 Foundations Benchmark IG1 with a recent assessment date is the answer that closes that field cleanly. SCuBA can also be named here, with a one-line note that it is the federal baseline and that controls also map to CIS. Either approach passes; CIS-only is the more common answer.

The second is a multi-part question on which Conditional Access policies are deployed and how legacy authentication is handled. This is where the practical difference between the two baselines starts to matter. Both baselines block legacy auth and require MFA. SCuBA's named-policy structure makes the answer easier to write because the policies have predictable names. CIS-aligned tenants can answer the same question, but the administrator has to translate from generic control numbers to the actual policy names in their tenant. This is a documentation problem, not a security problem.

The third pattern, which is newer and worth flagging, is questions about how the baseline is verified. Carriers increasingly want to know whether the assessment is automated, manual, or done by a third party. ScubaGear is free, runs in PowerShell, and produces a report. CIS-CAT Pro is a paid CIS Foundations assessment tool, and many CIS-aligned tenants use a combination of Microsoft Secure Score, Defender for Cloud, and manual review instead. The carrier is not insisting on a specific tool, but they want a credible answer to "how often do you check." Quarterly is a defensible cadence; annual is the floor.

If the questionnaire is forcing comparisons between baselines, the cross-walk to Microsoft's native scoring is covered in CIS Benchmark vs Microsoft Secure Score. That comparison closes a different gap that comes up on the same forms.

Common questions

If I am a 20-person business with no federal clients, do I need to know SCuBA at all?

Not really. Knowing it exists is enough. If a carrier or a vendor asks the question, you can say "we follow CIS Microsoft 365 Foundations Benchmark IG1, which covers the same control surface as SCuBA for our license tier." That answer is accurate and complete. You do not need to do parallel work.

Can I use ScubaGear even if my baseline of record is CIS?

Yes, and a lot of administrators do. ScubaGear is a free assessment tool that reads your tenant configuration and reports against SCuBA. Because of the heavy overlap, most of the findings are also valid CIS findings. Treat the SCuBA-specific items as enhancements, not failures, and do not let the report's framing suggest you are out of compliance with a baseline you never claimed.

Does my insurance carrier care which version of the CIS benchmark I am on?

They care that it is reasonably current. Being one version behind is normal. Being three versions behind starts to look like the assessment is stale. The current version as of this writing is the v3 series for M365, and the benchmark refresh cadence is roughly 12 to 18 months. An assessment dated within the last 12 months against the current or previous version is the safe answer.

How does this compare to NIST 800-53 or CMMC?

NIST 800-53 is a federal control catalog with hundreds of controls covering everything a federal information system might need. CMMC is the cybersecurity certification framework for the defense industrial base. Neither is an M365 configuration baseline. They are higher-altitude frameworks that, like NIST CSF, map down to specific configurations. If you are subject to CMMC, your M365 tenant configuration is one input into the CMMC assessment, and the practical baseline used to configure that tenant is usually a tightened CIS or SCuBA deployment.

What if my IT vendor recommends doing both baselines together?

Ask them which questionnaire or contract the second baseline answers. If there is a specific federal client, SLTT contract, or compliance requirement that names SCuBA, the answer is genuine and the work is justified. If the answer is "to be thorough," push back. The 85 percent overlap means the second baseline mostly buys documentation overhead. Pick one as primary, deploy it well, and treat the other as a reference. The full post-deployment checklist is in the cyber insurance compliance checklist.

Get the free Insurance Readiness Checklist

No spam. Unsubscribe anytime.

See Where Your Tenant Stands Against the CIS Benchmark

Our free risk assessment checks your Microsoft 365 tenant against the controls insurance carriers care about most.

Check My Tenant Risk