Skip to main content

Your M365 tenant is already generating ISO 27001 evidence.

Certaria maps your Microsoft 365 setup to ISO 27001 controls and tells you what to fix next. You run it yourself.

  • Read-only scan: your data stays in your tenant
  • Annex A mapped from live M365 configuration
Run Your Free Scan See how it works

Five-minute scan · read-only · nothing leaves your tenant

  • Read-only scan permissions
  • No other vendor holds your ISMS data
  • Built on Microsoft Power Platform

Talastron built Certaria for real ISO 27001 workloads on Microsoft 365.

Meet the team How it works Pricing

0

functional requirements

0

Annex A categories (the ISO 27001 control groups)

0min

minute initial scan

£0

per year, founding-customer rate

What you already have

Your tenant already produces ISO 27001 evidence.

The configuration you already run is evidence an assessor will ask to see.

Device management

Intune policies controlling which devices access company data. That is evidence for asset management and endpoint security controls.

Access control

Conditional Access policies deciding who signs in and from where. That is evidence for access controls and identity management.

Data protection

Sensitivity labels on documents and emails. That is evidence for information classification and data handling controls.

How Certaria works

What the scan reads.

Your M365 security configuration already lines up with ISO 27001 controls. Certaria does the mapping for you.

Access & Identity

Conditional Access is already ISO 27001 evidence.

Your policies controlling who signs in, from where, and on which devices map directly to Annex A access control requirements. Certaria reads this automatically.

See what we detect
Access Control Scan 4 found
MFA enforced for all users
Sign-in risk policy active
Device compliance required
Legacy auth blocked
Gap-Closing Tasks
Create Information Security Policy Ready
Enable audit log retention (90d) Ready
Document asset inventory process Pending
Set up sensitivity labels Pending
Guided Implementation

Every gap becomes a task with a control number on it.

Certaria generates prioritised tasks based on your scan results. Each task maps to a specific ISO 27001 control. The workflow walks you through each task in Microsoft Teams, with the optional Certaria AI Agent for conversational interpretation when you enable Copilot Credits.

See the full process
Optional AI Agent add-on

It answers with your controls and your scan results in context.

An optional add-on, priced separately. A Copilot agent that understands ISO 27001 and your specific implementation. Ask about controls, get policy guidance, check your progress. All inside Microsoft Teams.

Learn more
Certaria Agent

What do I need for Annex A.8 access control?

Based on your scan, you already have 3 of 5 controls evidenced. You still need:

  • -Access review schedule
  • -Privileged access policy

Pricing

£4,490/year. Not £15,000-40,000.

The Microsoft Teams workflow from day one. The AI Agent is an optional add-on, priced separately.

RECOMMENDED

Certaria Standard

£4,490 /year

Complete ISO 27001 software. AI Agent optional.

See full pricing

Typical consultant

£25k

Year 1, then £5-10k ongoing

40-80 hours of your time

How it works

From first scan to certification.

Three steps, and you run all of them.

What's included

A complete ISMS on the platform you already pay for.

Everything here is in the £4,490 except the AI Agent, which is an optional add-on.

Core Feature

Readiness Scan

Reads your M365 configuration and maps it to all 14 Annex A categories. Five minutes, read-only. Initial plus monthly recurring.

Coverage by category 6/14 detected
Optional add-on

AI Compliance Agent

Priced separately, with Microsoft Copilot credits on top. An in-Teams Copilot agent for ISO 27001 guidance in the context of your ISMS.

What controls am I missing?

You need 2 more: access review and privileged access.

Policy Templates

Pre-built policies deployed to SharePoint. Editable, auditor-ready.

Task Generation

Automated gap-closing tasks prioritised by impact across your team.

Evidence & Progress

Graph API collects M365 evidence automatically. Real-time dashboard tracks coverage with exportable reports.

Our story

We are certifying ourselves with it.

We built Certaria to solve our own ISO 27001 problem. Same constraints as you. A small team, and a business that could not stop for a year.

We built it to read the evidence Microsoft 365 already holds, and we are using Certaria to pursue our own certification. It is the same system we sell to you.

The scars are in the product.

Talastron
0+

Microsoft professional certifications

Azure, Data, AI, and Power Platform

Cyber Essentials Certified

UK Government-backed baseline

ISO 27001

Pursuing with Certaria.

In progress

See where you stand.

Run the free readiness scan and see how much of ISO 27001 your tenant already covers.

Your Scan Result
Complete
Access Control 72%
Asset Management 58%
Cryptography 40%
Physical Security 25%
Operations Security 65%
Communications 80%
37% coverage
Ready to close the gaps