Compliance Evidence and Audit Readiness Retainer
Compliance Evidence and Audit Readiness Retainer is monthly compliance operations for one agreed framework — the HIPAA Security Rule, CMMC and NIST SP 800-171, SOC 2, CIS Controls v8.1, or your cyber-insurance carrier's control requirements — run on the Microsoft 365 and Azure controls you already own. Every month IT Partner refreshes the evidence behind each control from Entra ID, Purview, Defender, Intune, and Azure; checks the tenant for drift against the baseline your readiness assessment left; works the policy review calendar; drafts answers to security questionnaires within a defined monthly allowance; and keeps an audit binder in your own SharePoint that is ready on any day, not just audit week. It costs a flat $950 per month per tenant with no long-term contract; additional frameworks are quoted. We are Microsoft 365 engineers, not auditors: this retainer produces the evidence, and the auditor, assessor, or carrier reaches their own conclusion.
What this engagement is
The dangerous part of compliance is not the assessment; it is the eleven months after it. A readiness assessment closes with a gap report, a roadmap, and a tenant that — for one week — matches the documentation. Then a Conditional Access policy gets switched to report-only during a rollout and never switched back. The access-control policy passes its annual review date unread. Entra ID sign-in logs, kept for 30 days on P1 and P2 licensing, quietly age out of the evidence window nobody exported. A customer's security questionnaire arrives the week before renewal, and the person who answered it last year has left. By the time the auditor, the C3PAO, the carrier, or the customer asks for proof, the organization is reconstructing evidence rather than producing it. That scramble is the cost this retainer removes — and, increasingly, it is the shape auditors reject: a SOC 2 Type II report samples evidence across an observation period that commonly runs six to twelve months, CMMC Level 2 requires the score and affirmation to be kept current, HIPAA expects its documentation to be maintained and retained for years, and a cyber-insurance application is an attestation your organization signs. This retainer is the monthly operating layer for one agreed framework. Evidence refresh: on a fixed schedule we pull the artifacts that prove each control from where they actually live — Conditional Access and MFA registration state, role and privileged-access assignments, Purview audit-log searches, DLP and retention policy state, Compliance Manager improvement-action status, Secure Score, Defender Vulnerability Management exposure, Defender for Office 365 policies, Intune device compliance and encryption, Azure Policy and Defender for Cloud regulatory-compliance results, backup and restore-test records — and file each one, dated, against the control it evidences. Drift check: the live tenant is compared with the baseline your assessment left; every difference is raised for a decision, reverted or approved into the baseline, and recorded either way. Policy calendar: every policy has an owner and a review date, we send the review pack showing what changed technically since the last signature, and we file the approval. Questionnaire support: when a customer, carrier, or auditor sends a questionnaire or an evidence-request list, we draft the technical answers from the binder within the monthly allowance recorded in your service order, and you review and sign. Audit binder: all of it lives in a SharePoint site in your tenant, organized by control identifier, with an index an auditor can navigate unassisted — and it is yours to keep if the retainer ends. The boundaries are drawn plainly. IT Partner is not an auditor, a CPA firm, a C3PAO, or a certification body; nothing here is an attestation, and no page of ours will ever promise a compliance outcome — that decision belongs to the third party making it, and the binder is honest about what is not done as well as what is. Security-program leadership — the risk register, policy governance, strategy, executive reporting — is the Virtual CISO service, and this retainer is deliberately the operational layer below it: the vCISO decides what the program requires, and this retainer produces the evidence that it is happening. Legal questions about applicability, contracts, and breach obligations belong to counsel. Remediation of gaps is quoted as fixed-price project work you can take anywhere. What you get from us is the Microsoft side done properly, by a practice that holds Microsoft's Solutions Partner designation for Security, has been a Microsoft partner since 2006, and fills in the same cyber-insurance questionnaires itself every year — our own insured status is verifiable on our insurer's live page.
Success criteria
What you receive
How the work unfolds
We take the outputs of your readiness assessment as the starting point, build the control-to-evidence map for the agreed framework, record the tenant's control state as the baseline, create the audit binder in a SharePoint site in your tenant, verify what your licensing surfaces — audit-log retention, Entra log retention, Compliance Manager templates — and record the scope boundary, policy calendar, questionnaire allowance, and report recipients in the service order. If the assessment is older than the tenant's last major change, the first cycle re-verifies the baseline before anything is filed against it.
On the schedule in the control-to-evidence map, we collect the artifacts from Entra ID, Purview, Defender, Intune, and Azure and file each one, dated and attributed, against its control. Artifacts with short retention windows — Entra sign-in logs, audit-log searches — are exported every cycle so the evidence exists when the observation period is examined.
The live tenant is compared with the baseline; every difference is raised with a recommendation, reverted or approved into the baseline with your decision, and recorded. Policies reaching their review date receive a review pack showing what changed since the last signature; approvals are recorded and signed versions filed.
Questionnaires and evidence-request lists received through the intake are drafted from the binder within the allowance and returned for your review and signature. The month closes with the compliance report and the review call, where drift decisions are confirmed, open roadmap items are assigned, and the next cycle's calendar is set.
When the window opens, the binder is exported in the requested format, the evidence-request list is answered from it, and — by agreement — an IT Partner engineer attends the walkthroughs that concern the Microsoft 365 or Azure controls. The retainer continues through the window; findings that need remediation are scoped as fixed-price work.
Prerequisites
Who does what
IT Partner
- Build and maintain the control-to-evidence map and the audit binder for the agreed framework's Microsoft 365 and Azure scope.
- Run the monthly evidence refresh, file every artifact dated and attributed, and export short-retention logs every cycle.
- Run the monthly drift check, raise every difference with a recommendation, execute approved reversions, and record every decision.
- Operate the policy review calendar: review packs ahead of each date, approvals recorded, signed versions filed, overdue reviews escalated.
- Draft questionnaire and evidence-request answers from the binder within the allowance, with the supporting artifact attached to each answer, and say before starting when a request will exceed the allowance.
- Watch the agreed framework, its regulator, and your carrier's requirements for changes that affect the Microsoft portion, and surface them with a recommended action.
- Deliver the monthly compliance report, hold the review call, and support the audit or renewal window with binder exports and evidence-request responses.
Your team
- Own the compliance decisions — drift approvals, policy sign-offs, risk acceptances, and attestations are yours; we recommend, execute with approval, and record.
- Review and sign questionnaire answers and attestations; IT Partner drafts and evidences, but never signs or submits on your behalf.
- Route changes to in-scope controls through the agreed intake so they are approved into the baseline rather than discovered as drift.
- Keep the named compliance owner current, attend the monthly review call, and act on escalations — overdue policy reviews, roadmap items, findings that need remediation.
- Maintain the Microsoft licensing the evidence depth depends on, and supply evidence for the non-Microsoft systems in the framework's scope for filing in the binder.
- Engage your auditor, assessor, carrier, or counsel directly; we support their evidence requests, they remain your relationship.
What's not included
Limitations & technical notes
Frequently asked questions
What does the Compliance Evidence and Audit Readiness Retainer include each month?
A complete cycle for one agreed framework on your Microsoft 365 and Azure controls: a scheduled evidence refresh filed against each control, a drift check of the live tenant against your baseline with every difference decided and recorded, the policy review calendar worked with review packs and filed approvals, security-questionnaire support within the allowance in your service order, a framework watch, a continuously maintained audit binder in your own SharePoint, and a monthly compliance report with a review call. The price is a flat $950 per month with no long-term commitment.
Is this 'compliance as a service'?
It is the honest version of it. The market uses that phrase for anything from a dashboard subscription to a fractional compliance officer. This retainer is specifically the recurring labor between assessments: collecting evidence, catching drift, running the policy calendar, answering questionnaires, and keeping the binder current — continuous evidence instead of an annual scramble. What it is not is an auditor, a certification, or a promise about the outcome, and we say that on every page rather than in the small print.
Which frameworks can the retainer cover?
One agreed framework per retainer, chosen from the HIPAA Security Rule, CMMC and NIST SP 800-171, SOC 2, CIS Controls v8.1, or the control requirements in your cyber-insurance carrier's application. Each has its own control-to-evidence map — the artifacts an OCR investigator, a C3PAO, a SOC 2 auditor, a CIS self-assessment, and an underwriter each expect are related but not identical. Other frameworks we assess, such as ISO 27001, NIST CSF, FINRA and SEC 17a-4, and ISO/IEC 42001, can be quoted after we review how much of their evidence your existing map already produces.
We need two frameworks — HIPAA and SOC 2, say. How does that work?
The fee covers one framework; the second is quoted, not doubled. Overlap between frameworks is real — MFA enforcement, audit logging, access reviews, encryption at rest, and vulnerability management evidence the same way for most of them — so we review the existing control-to-evidence map, identify the controls the second framework adds, and quote the increment. The binder then carries both mappings against one set of artifacts.
Where is the line between this retainer and the vCISO?
The vCISO owns the security program: strategy, the risk register, policy governance, incident-readiness planning, security metrics, and executive reporting — the decisions about what the program requires. This retainer is the operational layer below it: the evidence that the Microsoft controls the program calls for exist and keep operating, month after month. Run together, the vCISO sets the policy calendar's content and this retainer runs it; the vCISO decides a drift finding's risk treatment and this retainer records it. If you have no security leadership at all, the vCISO is the first conversation, and this retainer is the second.
Are you auditors? Will you certify us?
No, and no — and any Microsoft partner who answers differently should be asked which accreditation they hold. IT Partner is not a CPA firm, a C3PAO, an ISO certification body, or an assessor. SOC 2 reports come from licensed CPA firms, CMMC certification from an authorized C3PAO, ISO certificates from accredited bodies, and there is no such thing as HIPAA or CIS certification at all. What we do is make sure that when those parties examine your Microsoft 365 and Azure controls, the evidence is complete, current, and honest, and that the people answering their questions have it in front of them.
Do we need a readiness assessment before starting the retainer?
Yes — the retainer starts from a baseline, and the assessment is what produces one: the gap report, the roadmap or plan of action, and a documented control state to check drift against. IT Partner's HIPAA, CIS Controls v8.1, CMMC and NIST 800-171, SOC pre-audit, and Cyber Insurance Readiness assessments each end in exactly that; an equivalent assessment done elsewhere works too. Starting a retainer without one would mean filing evidence against controls nobody has defined, which is how binders end up telling comforting stories rather than true ones.
Do we need Microsoft 365 E5 or Purview Compliance Manager?
No. The retainer runs on Business Premium and E3 tenants; licensing changes evidence depth, not whether the program works. Compliance Manager's Data Protection Baseline is included with Microsoft 365, and we use Compliance Manager's automatically tested improvement actions as an input where they help; the regulatory templates for HIPAA, NIST SP 800-171, CIS, and SOC 2 are premium templates Microsoft licenses separately, with a limited number included in E5-family suites at the time of writing. Audit (Premium) extends audit-log retention from 180 days to one year by default. We verify what your tenant surfaces at onboarding, tell you plainly what a license would add, and quote any Microsoft purchase at Microsoft's published list price — never inside this fee.
Why does the binder live in our SharePoint rather than in Compliance Manager or your portal?
Three reasons. Auditors and assessors want exportable artifacts organized by their control identifiers, not a vendor dashboard they cannot navigate. A binder in your tenant is covered by your retention and access controls, which is itself evidence. And because it is yours: if you stop the retainer, every artifact, narrative, and report stays exactly where it is. Compliance Manager remains a useful input — we record improvement-action status and use its automated tests where licensed — but the system of record is the one you own.
What counts as questionnaire support, and what is the allowance?
Questionnaire support is drafting the technical answers, with the supporting artifact attached, for documents addressed to your organization: customer due-diligence questionnaires such as SIG and CAIQ or bespoke ones, cyber-insurance applications and renewals, and evidence-request lists from auditors and assessors. The allowance is recorded in your service order at onboarding, sized to your customer and carrier load, and reported against every month. A request that will exceed it is flagged before we begin and quoted at our published cloud engineer hourly rate or as a fixed package — no silent absorption, no surprise invoice. You review and sign every answer; we never submit on your behalf.
What happens when the drift check finds a change?
It is raised with a recommendation, not silently fixed. If someone switched a Conditional Access policy to report-only, shortened a retention policy, or added a global administrator, you decide: revert to the baseline, or approve the change into it. Reverting a baseline setting is executed with your approval as part of the cycle; designing a new control or a larger change is scoped as project work. Either way the decision is recorded in the binder, which is what an auditor asking 'how do you manage change?' actually wants to see.
Do you write our policies?
No — we review and evidence the ones you have. The calendar gives every policy an owner and a review date; ahead of each date we prepare a pack showing what changed technically since the last signature, and after the review we file the approval and the signed version. Writing a new policy set, or restructuring one, is the vCISO's work or a separately scoped engagement, because a policy is a management commitment and should be authored by the people who own it.
What about our EHR, ERP, or systems outside Microsoft?
Every framework reaches beyond Microsoft 365 — HIPAA's risk analysis is organization-wide, a CMMC boundary may include on-premises assets, SOC 2 covers HR and vendor management. The binder is structured for the whole framework so the auditor sees one coherent picture, and we file the evidence you supply for non-Microsoft controls in their place. What we collect ourselves is the Microsoft 365 and Azure evidence; we do not operate or extract from other platforms, and we say so instead of implying coverage we do not have.
Will the binder satisfy our auditor, assessor, or insurer?
It is built for exactly that audience — organized by their control identifiers, dated, attributed, and exportable — and clients use it to answer evidence-request lists without a reconstruction week. What we will not do is promise their verdict. An auditor may want a sample we did not anticipate, a C3PAO applies the assessment guide as they read it, a carrier's underwriting is their business. The retainer makes the evidence complete and honest; the conclusion is theirs, and we will never tell you otherwise to close a sale.
How do SOC 2 observation periods, CMMC affirmations, and insurance renewals change the rhythm?
They are why the rhythm is monthly. A SOC 2 Type II report tests controls across an observation period that commonly runs six to twelve months, so the auditor samples evidence from throughout it — an artifact that exists only in audit week fails the sample. CMMC Level 2 keeps a score and an affirmation current in SPRS, and the plan of action has deadlines. A cyber-insurance renewal is an annual attestation whose questions rarely get easier. The monthly cycle means that whichever window opens, the last twelve months of evidence already exist.
What happens in the first month?
Onboarding: we import your readiness assessment's outputs as the baseline, build the control-to-evidence map for the agreed framework, record the tenant's control state, verify what your licensing surfaces, create the binder in your SharePoint, and record the scope, policy calendar, questionnaire allowance, and report recipients in the service order. If the tenant has changed materially since the assessment, the first cycle re-verifies the baseline before anything is filed against it. The regular monthly cycle starts in the second month.
How does billing work, and can we stop?
A flat $950 per month per tenant for one framework, invoiced monthly, with no long-term contract: stop any month, and all we ask is payment of previously approved invoices. The binder, the control-to-evidence map, the policy calendar, and every monthly report live in your SharePoint and stay there — the retainer was built so that leaving it costs you nothing but the labor it was doing.