Would you pass Cyber Essentials today?
ComplianceGuard scores your Microsoft 365 tenant against the current Cyber Essentials and Cyber Essentials Plus control set, live, from signal Microsoft already has — Entra, Intune, and Defender. It exports an evidence pack the assessor will accept. It is entirely read-only: it cannot change anything in your tenant.
Before you start
You need a Microsoft 365 admin account with the Global Administrator or Privileged Role Administrator role. It is required for the one-time consent that lets ComplianceGuard read your directory, device, policy and endpoint state. Every permission granted is read-only.
1 · Subscribe on Azure Marketplace
Open the ComplianceGuard listing, click Get it now, sign in with your Microsoft 365 admin, choose a plan, and confirm. Azure redirects you to our landing page.
| Plan | Includes | Price | Trial |
|---|---|---|---|
| CE Ready | Up to 50 users, Cyber Essentials scorecard & evidence pack | £49 / month | 14 days free |
| CE + CE Plus Ready | Up to 250 users, adds CE Plus readiness checks and auditor role | £129 / month | 14 days free |
| MSP Multi-tenant | Unlimited tenants under one licence, MSP dashboard | £299 / month | 14 days free |
2 · Activate
On the landing page you will see your plan. Enter your contact email and company name, then click Activate & grant admin consent. Microsoft will show you the read-only permissions ComplianceGuard needs:
Directory.Read.All,User.Read.All,Policy.Read.All,RoleManagement.Read.Directory— read your directory, users, policies, and privileged-role assignments.DeviceManagementConfiguration.Read.All,DeviceManagementManagedDevices.Read.All— read your Intune device inventory and configuration profiles.SecurityEvents.Read.All— read Defender for Endpoint state.AuditLog.Read.All,Reports.Read.All— read the D30 activity reports the scorecard cross-references.
3 · Wait for the first sync
ComplianceGuard runs a full sync on boot and then nightly at 02:45 UTC. Within a couple of minutes of activation your scorecard populates with the overall score, five domain sub-scores, and a control-by-control table showing pass, fail, warn, or not-applicable. The first evidence pack is generated at the end of the first sync.
4 · Read the scorecard
Left nav → Scorecard. One number from 0 to 100, five domain scores, a boolean “would you pass today”. Any red control in the CE control set turns the boolean red — that mirrors how an assessor scores CE.
Left nav → Controls. Sorted with fails at the top. Each row shows:
- The Cyber Essentials control ID it maps to.
- The evidence — the raw Microsoft payload the check derived from, timestamped.
- The remediation — one paragraph pointing you at the exact Intune, Entra or Defender blade where you fix it.
5 · Export the evidence pack
Left nav → Evidence. A fresh PDF is generated after every nightly sync. It is sectioned to mirror the IASME questionnaire — for each question the assessor asks, the pack cites the ComplianceGuard control that answers it, the evidence blob, and the timestamp. Download and upload straight to IASME.
Roles
| Role | Can do |
|---|---|
| Viewer | Scorecard, controls, evidence packs. |
| Admin | Everything Viewer sees, plus manage users and settings. |
| Auditor | Read-only scoped to the current evidence pack and the controls that back it. Designed for external CE assessors. |
Any user in your tenant who signs in gets viewer by default. Owners assign the other roles under Settings → Users.
Common questions
Can ComplianceGuard fail my audit for me by mistake? No. It scores against the same signals your assessor will ask you to demonstrate; if your scorecard says pass, an assessor asking for the same evidence will reach the same conclusion.
Where is my data stored? Azure UK South only.
How long is data kept? Control results retained for the life of the subscription. Evidence packs retained 90 days on CE Ready, forever on CE Plus Ready and MSP. Append-only audit log retained for the life of the subscription.
How does billing work? Azure bills you a flat monthly plan fee. It counts toward your MACC. Change plan in the Azure portal and ComplianceGuard picks up the new plan within an hour.
How do I cancel? Unsubscribe in the Azure portal. Sync stops within the hour. Data is deleted 30 days after cancellation.
Does the assessor accept the evidence pack? The pack is structured against the current IASME Cyber Essentials questionnaire. Assessors accept it as supporting evidence for each question it maps to. It does not replace the questionnaire itself — you still submit that.
Help
Email support@tensorsoftai.io. Response times are on the support page. Live status at complianceguard.tensorsoftai.io/healthz.
Tensor AI