Microsoft Defender for Cloud and NIS2/DORA: What the Compliance Dashboard Covers — and Where the Gaps Are
A fair read on Microsoft Defender for Cloud NIS2 compliance: strong first-party standards, real gating and scope limits. For security leads. With a coverage table.
Microsoft Defender for Cloud NIS2 Compliance: What the Dashboard Covers and Where the Gaps Are
Microsoft Defender for Cloud NIS2 compliance is delivered through the regulatory compliance dashboard, which maps your Microsoft Azure security posture against a first-party standards library — NIS2, DORA, ISO 27001, SOC 2, CIS, NIST — with downloadable evidence. The dashboard is genuinely strong at what it does, and it has honest limits: it is gated behind a paid plan, it covers the security pillar only, and it is thin on Microsoft 365 and Zero Trust architecture depth.
This is not a teardown. Microsoft Defender for Cloud does a real job well, and any fair assessment says so before it says anything else. The point of this piece is to draw the boundary clearly — what the regulatory compliance dashboard covers, what it does not, and why a complete compliance picture needs more than one tool doing different jobs.
Key takeaways
- The Microsoft Defender for Cloud regulatory compliance dashboard maps Azure posture to a strong first-party standards library including NIS2, DORA, ISO 27001, SOC 2, CIS, and NIST.
- The dashboard and full standards set are gated behind a paid Defender Cloud Security Posture Management (CSPM) plan — not the free tier.
- Scope is the security pillar of cloud posture, not all five pillars of the Microsoft Azure Well-Architected Framework.
- Defender for Cloud is thin on Microsoft 365 configuration and Zero Trust architecture depth; its centre of gravity is Azure infrastructure.
- The honest framing is complementary, not competitive — the dashboard and an architecture review do different jobs.
What does the Microsoft Defender for Cloud compliance dashboard do well?
The Microsoft Defender for Cloud regulatory compliance dashboard does several things genuinely well, starting with a first-party standards library that maps your Azure resources against named frameworks and produces downloadable evidence. Because it is Microsoft’s own tool reading Microsoft’s own resources, the control assessments are accurate against the Azure infrastructure they cover.
The strengths are concrete:
- A broad standards library. NIS2, DORA, ISO 27001, SOC 2, CIS Microsoft Azure Foundations Benchmark, NIST SP 800-53, PCI DSS — selectable and assessed against your subscriptions.
- Continuous assessment. Controls are re-evaluated as resources change, so the posture is current rather than a point-in-time snapshot.
- Downloadable evidence. Compliance reports export as PDF or CSV, which feeds directly into audit packages.
- Actionable findings. Each failed control links to the affected resources and a remediation path, often with automated remediation available.
- First-party accuracy. No third-party connector lag; the tool reads Azure Resource Manager natively.
For an organisation whose regulatory concern is Azure infrastructure posture, this is a strong first stop. It is accurate, current, and produces evidence an auditor accepts.
Where are the gaps in Defender for Cloud’s compliance coverage?
The gaps in Microsoft Defender for Cloud’s compliance coverage are three: it is gated behind a paid plan, it is scoped to the security pillar only, and it is shallow on the Microsoft 365 and Zero Trust surfaces. None of these is a flaw in the tool — they are boundaries of what the tool is for.
The gating. The regulatory compliance dashboard and the full standards library require the Defender Cloud Security Posture Management (CSPM) paid plan. The free tier of Microsoft Defender for Cloud gives you a secure score and recommendations, but the regulatory compliance dashboard with the full NIS2 and DORA standards is not in the free tier. Organisations sometimes assume they have compliance coverage because Defender for Cloud is “on,” when they are on the free tier and the dashboard is not enabled.
The pillar scope. Defender for Cloud assesses the security pillar of cloud posture. The Microsoft Azure Well-Architected Framework has five pillars — reliability, security, cost optimisation, operational excellence, and performance efficiency. Defender for Cloud is not a Well-Architected review; it does not assess whether your architecture is reliable, cost-appropriate, or operationally sound. The Well-Architected Framework security pillar walkthrough covers where that one pillar sits in the larger frame.
The architecture depth. Defender for Cloud assesses resource configuration, not architecture. It does not perform a Cloud Adoption Framework review of your landing zones, governance model, or subscription design. And its centre of gravity is Azure infrastructure — it is thin on Microsoft 365 configuration (Exchange Online, SharePoint sharing, Microsoft Purview) and on Zero Trust architecture maturity across the six pillars. Those surfaces are where the Microsoft 365 security posture assessment and the Azure Zero Trust maturity assessment do their work.
Covers and does not cover: a side-by-side
The clearest way to see the boundary is to lay out what the regulatory compliance dashboard covers against what it does not. The table is descriptive, not a verdict — each row is a job, and different jobs need different tools.
| Concern | Defender for Cloud covers | Defender for Cloud does not cover |
|---|---|---|
| Azure infrastructure security posture | Yes — native, continuous, accurate | — |
| NIS2 / DORA / ISO / SOC 2 standards mapping | Yes — strong first-party library (paid CSPM) | — |
| Downloadable audit evidence | Yes — PDF and CSV export | — |
| Free-tier access to the dashboard | — | No — requires paid Defender CSPM |
| Well-Architected pillars beyond security | — | No — security pillar only |
| Cloud Adoption Framework / landing-zone review | — | No — not an architecture review |
| Microsoft 365 configuration depth | Partial — limited | Exchange, SharePoint, Purview depth |
| Zero Trust maturity across six pillars | Partial — identity signals | Endpoints, data, app, network maturity scoring |
Read the right column as scope, not deficiency. A posture-management tool is not supposed to do a Cloud Adoption Framework review. The risk is not that Defender for Cloud has gaps — it is assuming it has none.
How should you use Defender for Cloud alongside an architecture review?
You should use Microsoft Defender for Cloud as the continuous posture-monitoring layer for Azure infrastructure security, and pair it with a periodic architecture review that covers the pillars, surfaces, and design questions the dashboard does not reach. The two are complementary because they operate at different altitudes and cadences.
Defender for Cloud runs continuously and shallowly — every resource, every day, security pillar. An architecture review runs periodically and deeply — the whole estate, all five Well-Architected pillars, Microsoft 365 and Zero Trust included, with judgment about design. Defender for Cloud tells you a storage account lacks encryption today. An architecture review tells you the data should not be in that storage account at all.
A sensible operating model: enable the Defender CSPM plan and use the regulatory compliance dashboard as your standing evidence source for Azure infrastructure controls; run an architecture review across the full estate periodically to cover Microsoft 365, Zero Trust maturity, and the architecture-level questions; and reconcile the two so the continuous monitoring and the periodic deep review tell a consistent story. For the DORA-specific architecture concerns, see DORA Article 11 and Azure architecture.
FAQ
Is the Defender for Cloud compliance dashboard free? No. The regulatory compliance dashboard with the full NIS2, DORA, ISO 27001, and SOC 2 standards requires the paid Defender Cloud Security Posture Management (CSPM) plan. The free tier of Microsoft Defender for Cloud provides a secure score and recommendations but not the full regulatory compliance dashboard.
Does Defender for Cloud cover all five Well-Architected pillars? No. Microsoft Defender for Cloud assesses the security pillar of cloud posture. The Microsoft Azure Well-Architected Framework also includes reliability, cost optimisation, operational excellence, and performance efficiency, which Defender for Cloud does not assess. It is a security posture tool, not a Well-Architected review.
Can Defender for Cloud assess Microsoft 365 settings? Only partially. Defender for Cloud’s strength is Azure infrastructure resources. It surfaces some identity signals but does not provide depth on Exchange Online, SharePoint and OneDrive sharing, Microsoft Teams policies, or Microsoft Purview. Those Microsoft 365 surfaces need a dedicated posture assessment or a tool such as ScubaGear.
Should I replace Defender for Cloud with an architecture review? No — they do different jobs. Microsoft Defender for Cloud provides continuous, accurate Azure infrastructure posture monitoring with downloadable evidence. An architecture review provides periodic depth across all pillars, Microsoft 365, and design questions. Use the dashboard for continuous monitoring and the review for periodic depth; they are complementary.
Where this leaves the picture
Platform Architecture Authority is built to sit alongside Microsoft Defender for Cloud, not against it — covering the Microsoft 365 configuration, the Zero Trust maturity across all six pillars, the Well-Architected pillars beyond security, and the architecture-level design questions the regulatory compliance dashboard is not built to reach, then reconciling its findings with the dashboard’s so the two agree. It is read-only and generates remediation code you apply, and a senior architect brings the design judgment neither tool holds. Microsoft Defender for Cloud is a strong tool with a clear job. The mistake is asking it to do a job it was never scoped for.
Use the dashboard for what it does well. Assess the rest deliberately.