The control library carries an entry for every one of the 93 controls in ISO/IEC 27001:2022 Annex A and for all five Cyber Essentials technical themes, together with 21 of the 39 outcomes in NCSC CAF v4 and six of the ten measures in Article 21(2) of NIS2. Each entry names the control, what would satisfy it for a cloud-first SME, and the record that answers it.
Forty-seven configuration assertions run against connected tenants in six families — authentication, privilege, sharing and guests, mail flow, data and secrets, logging. Each one writes an evidence record rather than lighting a tile on a dashboard, and fourteen baseline policy documents drafted to the Annex A themes cover the controls no scan can reach.
Those two things together are the product: a mapping precise enough to argue with, and a record trail dated and referenced enough to hand to somebody who is paid to doubt it.