Skip to main content
Five Steps for Cloud Compliance Readiness·A practical playbook for security teamsDownload
Product Roadmap

Where ConfigCobra
is headed next.

We launched in January 2026 with full CIS Microsoft 365 automation. Here's what's shipped, what's in build, and what we're exploring — kept honest and up to date.

1 January 2026Launched

ConfigCobra is live

Continuous CIS Microsoft 365 compliance, automated end to end — from read-only connection to audit-ready evidence.

  • CIS Microsoft 365 Foundations Benchmark v5.0.0 — all 129 controls (Level 1 & Level 2)
  • Automated scan in 20–25 minutes · 90%+ of controls assessed automatically
  • Continuous scanning & drift detection with email alerts
  • CIS-certified PDF reports with timestamped tenant snapshot & remediation scripts
  • Daily / weekly / monthly scheduler across any rule sets
  • Team management, activity logs & read-only auditor seat
  • Multi-tenant ready · read-only Microsoft Graph permissions
End of Q2 2026In progress

MCP server & the latest CIS benchmark

Two major additions: an MCP server you connect to your own AI, and an upgrade to the newest CIS Microsoft 365 benchmark.

MCP server for your own AI

Shipped

Connect ConfigCobra's live compliance data to the AI you already use — Claude, ChatGPT, Cursor, or any MCP-compatible client. Ask plain-language questions, get per-user findings, and generate remediation plans.

  • Works with Claude, ChatGPT, Cursor, and any MCP client
  • Natural-language Q&A across your live assessment data
  • Plain-language remediation in your own AI workflow
Connect your AI assistant →

CIS Microsoft 365 Benchmark v6.0.1

Upgrade from v5.0.0 to the latest CIS Microsoft 365 Foundations Benchmark, with the newest controls and guidance.

  • Coverage for the newest v6.0.1 controls
  • Automatic re-mapping of existing findings
  • Clear view of what changed since v5.0.0
V5 vs V6 — what's different
Q3 2026Planned

Azure & AI — next on the platform

Three major additions landing in Q3: CIS Azure Foundations Benchmark coverage, an AI Security Audit for AI service configurations, and Sentra — our AI-Driven Auditor for your whole tenant.

CIS Azure Foundations Benchmark

Notify me

The same automated scan-to-evidence workflow, applied to your Azure cloud. One workspace covering both Microsoft 365 and Azure.

  • CIS Microsoft Azure Foundations Benchmark coverage
  • Unified posture score across Microsoft 365 and Azure
  • Azure-specific drift detection & audit-ready evidence

AI Security Audit

Notify me

Automated configuration checks for AI services — Azure OpenAI Service, Microsoft Copilot, and other AI-powered workloads — against security baselines and access-control best practices.

  • Azure OpenAI Service & Copilot configuration checks
  • Access control, data exposure, and logging baselines
  • AI-specific drift detection and remediation guidance

Sentra — AI-Driven Auditor

Notify me

An AI-Driven Auditor — not a posture dashboard. A Microsoft connector feeds your tenant data to an AI helper with a benchmark skill for each standard (CIS, NIS2, ISO 27001 and more), backed by a purpose-trained model.

  • Read-only Microsoft connector — full tenant data, queryable in plain language
  • Benchmark skills per standard — CIS, NIS2, ISO 27001, SOC 2, DORA
  • Purpose-trained model that evaluates against each standard
Under considerationExploring

Google Workspace

We're evaluating CIS-based compliance for Google Workspace. Not committed yet — your feedback helps us decide whether and when to build it.

  • CIS Google Workspace Benchmark (exploratory)
  • Cross-platform compliance for mixed Microsoft + Google estates

This roadmap reflects our current thinking and is shared for transparency. Timelines and scope may change. Items marked Exploring are not commitments.

Have something you'd like to see?

Tell us what would make ConfigCobra more useful for your team — it directly shapes what we build next.

Get in touch

Let's talk.

Whether you're evaluating ConfigCobra, running an audit, or managing a client fleet — we respond within one business day.

Free trial