inforcer Achieves CIS Benchmark Certification
Summary:
inforcer has been certified by the Center for Internet Security (CIS) for aligning its Microsoft 365 policy baselines with the consensus-based standards in the CIS Microsoft Intune for Windows 11 Benchmark. CIS Benchmarks are widely used as system-hardening standards supporting regulatory frameworks including FISMA, FedRAMP, PCI DSS, NIST, and HIPAA. This certification provides third-party validation for inforcer's 365 Manager, which allows MSPs to efficiently configure multiple tenants against CIS and other chosen security baselines from a single dashboard.
|
What you'll Learn |
|
|
Benefits for MSPs |
|
|
Required Next Steps |
|
Scope and Limitation Statement
This certification confirms that inforcer's Microsoft 365 and Intune for Windows 11 policy baselines align with CIS's consensus-based hardening standards. It doesn't cover non-Windows or non-Microsoft 365 environments, which have their own compliance processes.
Versioned Specifics
- Certification announced: November 24, 2025
- Certifying body: Center for Internet Security (CIS)
- Benchmark covered: CIS Microsoft Intune for Windows 11 Benchmark
- Referenced regulatory frameworks: FISMA, FedRAMP, PCI DSS, NIST, HIPAA
London, 24th November 2025 - inforcer has been certified by the Center for Internet Security, Inc. (CIS®) to compare the configuration status of Microsoft 365 policy baselines against the consensus-based best practice standards contained in the Microsoft Intune for Windows 11 Benchmark.
Organizations that leverage inforcer can now ensure that the configurations of their critical assets align with the CIS Benchmarks™ consensus-based guidelines.
“Achieving CIS Benchmark Certification is a significant milestone for inforcer and our partners. This recognition demonstrates inforcer’s commitment to empowering MSPs and their customers to strengthen their Microsoft 365 and Intune environments, simplify compliance, and proactively address today’s evolving cyber threats,” said Matthé Smit, Chief Product Officer of inforcer.
“Cybersecurity challenges are mounting daily, which makes the need for standard configurations imperative. By certifying its product with the Center for Internet Security inforcer has demonstrated its commitment to actively solve the foundational problem of ensuring standard configurations are used throughout a given enterprise,” said Curtis Dukes, CIS Executive Vice President of Security Best Practices & Automation Group.
The CIS Benchmarks program is a trusted, independent authority that facilitates the collaboration of public and private industry experts to achieve consensus on practical and actionable solutions. CIS Benchmarks are recommended as industry-accepted system hardening standards and are used by many organizations in meeting regulatory compliance regimes, including FISMA, FedRAMP, PCI DSS, NIST, HIPPA, and other security requirements.
About CIS
The Center for Internet Security, Inc. (CIS®) makes the connected world a safer place for people, businesses, and governments through our core competencies of collaboration and innovation. We are a community-driven nonprofit, responsible for the CIS Controls® and CIS Benchmarks™, globally recognized best practices for securing IT systems and data. We lead a global community of IT professionals to continuously evolve these standards and provide products and services to proactively safeguard against emerging threats. Our CIS Hardened Images® provide secure, on-demand, scalable computing environments in the cloud. CIS is home to the Multi-State Information Sharing and Analysis Center® (MS-ISAC®), the trusted resource for cyber threat prevention, protection, response, and recovery for U.S. State, Local, Tribal, and Territorial government entities, and the Elections Infrastructure Information Sharing and Analysis Center® (EI-ISAC®), which supports the rapidly changing cybersecurity needs of U.S. elections offices. To learn more, visit CISecurity.org or follow us on Twitter: @CISecurity.
About inforcer
inforcer is a purpose-built platform for Managed Service Providers (MSPs) to automate, monitor, and manage Microsoft 365 and Intune environments at scale. The platform enables MSPs to standardize security and compliance policies across all tenants, detect and remediate policy drift, and deliver consistent, secure customer experiences. With powerful automation, reporting, and integration features, inforcer helps MSPs reduce manual effort, minimize risk, and unlock new opportunities for advanced services -including AI and security offerings. Trusted by MSPs globally, inforcer empowers service providers to deliver scalable, secure, and innovative solutions for modern cloud environments.
FAQs
What does inforcer's CIS Benchmark certification mean?
It means inforcer has been certified by the Center for Internet Security to compare Microsoft 365 policy baseline configurations against the consensus-based standards in the CIS Microsoft Intune for Windows 11 Benchmark — an independent validation, not a self-assessment.
What is the CIS Benchmarks program?
CIS Benchmarks are consensus-based, industry-accepted system hardening standards developed by public and private security experts through the Center for Internet Security, a community-driven nonprofit. They're widely referenced in meeting regulatory frameworks like FISMA, FedRAMP, PCI DSS, NIST, and HIPAA.
Does CIS Benchmark certification affect my MSP’s compliance obligations?
It doesn't change your compliance obligations directly, but it does mean the Microsoft 365 and Intune baseline policies inforcer offers are independently validated against a recognized hardening standard, which can support your own compliance documentation and customer conversations.
Do I need to do anything to benefit from this certification?
No. This certification applies to inforcer's existing baseline policy configurations, so customers already using inforcer's standardized baselines are covered without any action required.
Who verified inforcer's certification?
Curtis Dukes, CIS Executive Vice President of Security Best Practices & Automation Group, is quoted confirming the certification in the announcement.
Share this
You may also like
These related stories

inforcer partner, Infinity Group, named 2025 Microsoft Dynamics Business Central Partner of the Year

Microsoft Teams Copilot removes default transcription
