TENOVIA
Book a demo

Insight

CIS Google Workspace audit: the benchmark everyone ignores because CIS labels it manual

CIS declares all 89 of its Google Workspace recommendations manual. That single label is why most Workspace domains never get a serious configuration review.

Published 31 juillet 2026 4 min read

A CIS Google Workspace audit runs into a quirk of the framework straight away. The Center for Internet Security publishes a v1.3.0 benchmark of 89 recommendations, 73 at level 1 and 16 at level 2. However, every one of them carries the same label: manual assessment. As a result, CIS provides no automated procedure, no script, no command.

That label has a consequence few people have measured. In short, it created a blind spot.

What manual produces in the field

A Google Workspace audit is performed by hand today. A consultant opens the admin console, walks the screens one by one, and then writes down what appears. Count three hours for a simple domain, and a full day for a structured one with several organisational units.

The result then carries three weaknesses. Moreover, they only show up when somebody from outside looks at it.

It depends on who did the looking. Two consultants do not walk the same screens in the same order, and they do not notice the same inherited settings. Across 89 control points spread over a dozen sections, attention therefore drops well before the end.

It cannot be replayed. Six months later, nobody can say whether a gap was fixed or whether the first pass simply missed it. In addition, the before-and-after comparison rests on screenshots and memory.

It produces no evidence. A table filled in by hand does not count as a probative item. Consequently, in front of an ISO 27001 auditor, a client demanding NIS2 supply chain assurances, or a regulator, it reads as a statement rather than a finding.

The market’s blind spot

The Microsoft 365 benchmark ships with automated procedures. The market therefore picked them up: tools, public repositories, service offerings, all of it exists.

The Google Workspace benchmark has none. The market consequently followed that absence. Organisations running Workspace end up with a solid baseline, aligned with the same regulatory expectations as its Microsoft counterpart, and no industrial way to verify they meet it.

This is not a scoping detail. In fact, it covers tens of thousands of European organisations, many of them small and mid-sized businesses and public bodies, hosting their email, their documents and their identity directory there.

The manual label describes a document, not a platform

This is the point that changes everything. CIS documents audit procedures, and it has not published any for Google Workspace. That says nothing, however, about what the platform itself can return.

Google does expose a domain’s configuration state through application interfaces, read-only. The work is not finding those interfaces. Rather, it is establishing, recommendation by recommendation, which one returns the exact setting the benchmark asks you to observe, and how to judge it. That mapping exercise is long, and the absence of CIS procedures is precisely what discouraged it.

Out of the 89 recommendations, 79 therefore become automatically measurable. The remaining 10 rest on organisational decisions. They stay attested through a reasoned answer from the operator, traced on the same footing as the rest.

What an automated finding brings

It is time-stamped. Every collection carries a timestamp, and the gap between two collections reads directly. That is indeed what an auditor asks for when they want to know not whether a measure was decided, but whether it held.

It is identically repeatable. The same setup run three months later returns the same data shape. Comparison therefore becomes mechanical.

It is non-intrusive. No write, no agent installed, no script executed on the domain. Furthermore, the domain administrator sees the access granted, and revokes it in a single action once collection is done.

For an organisation under NIS2 or DORA, those three properties separate a compliance statement from compliance evidence.

The question to ask before any CIS Google Workspace audit

If you run Google Workspace and somebody offers you a security audit, one question settles it: against which benchmark, and by what method of observation.

An audit that amounts to a console walkthrough produces a document. By contrast, an audit that produces a time-stamped, repeatable, defensible state produces evidence. The difference stays invisible when you read the report. It becomes visible the day somebody challenges it.

Tenovia covers all 89 recommendations of CIS Google Workspace v1.3.0, read-only, with no script executed on the audited domain. Finally, the detail sits on the CIS coverage for Google Workspace page.