Compliance & Security

When is an M365 Health Check especially relevant?

From NIS2 to cyber insurance, from ISO 27001 to due diligence — there are concrete situations where an independent assessment adds direct value.

Note: This page describes situations where an independent Microsoft 365 assessment is often valuable. It is not legal advice and does not imply that your organisation is required to pursue NIS2, ISO 27001 or any other certification. TenantWise supports preparation — not certification itself.

In brief

🇪🇺
NIS2
Demonstrable technical security measures required for thousands of European organisations
🛡️
Cyber Insurance
Stricter technical requirements when taking out or renewing a cyber policy
📋
ISO 27001 & GDPR
Technical measures must be demonstrable — Microsoft 365 is always part of the scope

A Microsoft 365 Health Check helps organisations prepare for all of these requirements — independently and with a concrete report.

Triggers

Six reasons to get assessed now

You don't need to wait for an incident. Most organisations that book a Microsoft 365 Health Check have a concrete trigger — here are the most common ones.

🇪🇺
NIS2 — Network and Information Security Directive
Mandatory for many sectors

Since October 2024, thousands of European organisations are required to implement and demonstrate technical security measures. Microsoft 365 is at the core of most organisations' digital operations — and therefore directly within NIS2 scope.

A Health Check maps which technical measures are already in place and which are missing
The report provides demonstrable evidence of risk analysis and measures taken
Relevant for: energy, transport, digital infrastructure, financial services, healthcare, and more
🛡️
Cyber Insurance Requirements
Increasingly strict

Cyber insurers are asking more technical questions when policies are taken out or renewed. MFA, patch management, access controls and incident response are standard topics. An independent report gives your insurer concrete answers.

Insurer asking about MFA status, backup policy or access controls? The report gives direct answers
Demonstrable measures can lead to better coverage or lower premiums

Example: Your insurer asks: "Is MFA enforced for all administrators?" or "Are former employees promptly removed?" — The Health Check gives you a documented, concrete answer to exactly these questions.

📋
ISO 27001 Certification
Preparation or audit support

ISO 27001 requires demonstrable technical controls on access management, logging, device security and incident response. A Health Check directly maps to the relevant Annex A controls and gives you a baseline before the formal certification audit begins.

Maps to ISO 27001 Annex A controls: A.9 (access), A.12 (operations), A.16 (incidents)
Provides an independent baseline before your formal ISMS audit
Identifies gaps early so you have time to remediate

Example: ISO 27001 Annex A.9 requires that access to systems is granted only on a need-to-know basis. The Health Check assesses whether that's actually the case in your Microsoft 365 environment.

⚖️
GDPR — Protecting Personal Data
Legal obligation

GDPR requires organisations to implement technical and organisational measures to protect personal data. Microsoft 365 processes large volumes of personal data for most businesses — in email, Teams, SharePoint and OneDrive.

Access controls, audit logging and encryption are direct GDPR requirements the Health Check assesses
Unauthorised external access to personal data is a data breach — prevention is cheaper than notification
The report supports the mandatory risk analysis (DPIA) for M365-related processing activities
🏢
Acquisition, Merger or Investment Round
Due diligence

In M&A processes, IT security is increasingly included in due diligence. A poorly configured Microsoft 365 environment can lead to valuation adjustments or additional warranties. An independent report gives both parties clarity.

Gives buyers or investors insight into IT security posture before transaction
Identifies risks that would otherwise only become visible after the acquisition
A clean report strengthens the negotiating position of the selling party
🔍
Independent Second Opinion
IT supplier or MSP in place

Already have an IT supplier or managed service provider? An independent assessment is especially valuable then. TenantWise has no interest in selling a management contract — the only goal is an objective picture of the actual situation.

Objective assessment with no commercial interest in the outcome
Useful at contract renewal or when evaluating your current IT supplier
Gives management an independent view alongside the assessment of their own IT partner
Industries

Relevant for your industry

Some industries have specific standards or increased compliance pressure. These are the sectors where a Health Check most directly aligns with existing obligations.

See what's included in the Health Check →
🏥
Healthcare
Patient data is highly sensitive personal data requiring the highest level of protection. Mobile devices, external access and audit logging are critical areas. NEN 7510 (Netherlands) and equivalent standards require demonstrable technical measures.
NEN 7510 · GDPR · NIS2
⚖️
Legal & Notarial
Professional secrecy and confidential client files require strict controls on who has access to what. External sharing via SharePoint and Teams must be carefully restricted. Privileged access for partners deserves extra attention.
GDPR · Professional rules
💰
Financial Services
Regulators increasingly require cyber resilience. DORA (Digital Operational Resilience Act) applies to financial entities from 2025 onward. Independent assessments support compliance documentation.
DORA · NIS2 · Regulators
🏭
Logistics & Manufacturing
Operational continuity is paramount. Ransomware or Microsoft 365 downtime has direct production or delivery consequences. Shared devices and supplier access make access management especially critical.
NIS2 · Cyber insurance
🏗️
Construction & Real Estate
Growing digitalisation, project collaboration via SharePoint and Teams, and external contractors with access make access management increasingly important.
GDPR · Cyber insurance
💼
Professional Services
Accountants, consultants and HR firms process sensitive business and personal data from clients — making them an attractive target and creating clear compliance obligations.
GDPR · ISO 27001 · NIS2

Does your organisation operate in one of these sectors? Book a free discovery call →

Concrete triggers

Do any of these situations apply to you?

These are the most common concrete moments when organisations get in touch.

📧
Phishing attack or compromised account
You want to know how it happened — and what else might be exposed.
📄
Cyber insurer questionnaire
Your insurer asks technical questions you don't have concrete answers to.
🤝
New major client or tender
A client or procurement process requires demonstrable security measures.
👥
Growth or reorganisation
Rapid growth, many new people — nobody knows exactly who has access to what anymore.
🔄
Changing IT supplier
You want to know what the previous IT party left behind before moving forward.
📊
Management wants visibility
The board wants insight into IT security — without technical jargon.
💸
Licence costs seem too high
You're paying for licences but don't know whether they're all actually being used.
🏆
Preparing for certification
You're working towards a standard and want to know where you currently stand.
Get in touch

Ask a question or book a call

Fill in the form and we'll get back to you within one working day. No commitment.

Or email directly: info@tenantwise.nl

Does any of these apply to you?

Within 15 minutes you'll know whether a Microsoft 365 Health Check is relevant for your organisation. No commitment, no sales pitch.

Get in touch Back to the website