Microsoft 365 security guide

Cyber Essentials and Microsoft 365: what to prepare

Cyber Essentials Microsoft 365 preparation starts with the cloud services and devices in scope, who implements the relevant controls, and the evidence supporting your answers. Microsoft 365, sometimes still called Office 365, is only part of the picture. Reviewing a tenant alone does not establish compliance for the whole organisation.

Published · Last reviewed · By CyberProva

Run your free Microsoft 365 security assessment

No card required · Optional read-only Microsoft 365 connection

How does Microsoft 365 fit the five control areas?

Cyber Essentials covers firewalls, secure configuration, security update management, user access control and malware protection. Microsoft 365 is particularly relevant to accounts, access and secure configuration; your devices and other services also matter.

  • Define the assessment boundary with your Certification Body.
  • Identify cloud services used to store or process organisational information.
  • Document which controls your organisation, provider and cloud supplier implement.

What should you prepare in Microsoft 365?

Collect evidence that answers the assessment questions for your actual users and services, rather than relying on a generic provider statement.

  • An account list, privileged-role review and leaver process.
  • MFA configuration and documented exceptions.
  • Evidence of secure settings and the handling of unsupported access methods.
  • Device protection and update evidence for the wider scope.

What can a readiness review do?

A readiness review helps find evidence gaps and agree remediation before a certification application. Keep preparation and formal certification separate.

  • Use the current scheme requirements, not an old questionnaire.
  • Ask the Certification Body about scope and interpretation.
  • Retain the evidence and dates supporting your submitted answers.

Make the answer provable

Evidence to request

  • The agreed scope and cloud-service inventory.
  • Access and MFA evidence for in-scope accounts.
  • Device update and protection records supplied by your IT team.

How CyberProva helps

CyberProva helps organise selected checks and supporting evidence across the five technical control areas. Its findings support preparation; CyberProva is not a Certification Body and does not issue Cyber Essentials or Cyber Essentials Plus certificates.

See what a Microsoft 365 security assessment should cover →

See exactly what CyberProva checks · Learn how CyberProva assesses security · Review Microsoft permissions

Common questions

Can Microsoft 365 settings alone get us certified?

No. Certification concerns the agreed organisational scope and the scheme requirements. Other devices, services and controls can be relevant.

Is a CyberProva assessment Cyber Essentials Plus?

No. Cyber Essentials Plus involves the scheme's independent technical testing. Arrange certification through a Certification Body.

Official guidance

Use these sources with your IT provider when reviewing the controls described above.

From assumptions to evidence

See what needs attention in your organisation

Start with a free CyberProva assessment. Review the findings, identify evidence gaps and agree priorities with your IT team.

Free includes 3 lifetime core assessments. Report exports and advanced features require a paid plan.

Run your free assessment →