Your M365 tenant is already generating ISO 27001 evidence.
Certaria maps your Microsoft 365 setup to ISO 27001 controls and tells you what to fix next. You run it yourself.
- Read-only scan: your data stays in your tenant
- Annex A mapped from live M365 configuration
- Read-only scan permissions
- No other vendor holds your ISMS data
- Built on Microsoft Power Platform
Talastron built Certaria for real ISO 27001 workloads on Microsoft 365.
functional requirements
Annex A categories (the ISO 27001 control groups)
minute initial scan
per year, founding-customer rate
What you already have
Your tenant already produces ISO 27001 evidence.
The configuration you already run is evidence an assessor will ask to see.
Device management
Intune policies controlling which devices access company data. That is evidence for asset management and endpoint security controls.
Access control
Conditional Access policies deciding who signs in and from where. That is evidence for access controls and identity management.
Data protection
Sensitivity labels on documents and emails. That is evidence for information classification and data handling controls.
How Certaria works
What the scan reads.
Your M365 security configuration already lines up with ISO 27001 controls. Certaria does the mapping for you.
Conditional Access is already ISO 27001 evidence.
Your policies controlling who signs in, from where, and on which devices map directly to Annex A access control requirements. Certaria reads this automatically.
See what we detectEvery gap becomes a task with a control number on it.
Certaria generates prioritised tasks based on your scan results. Each task maps to a specific ISO 27001 control. The workflow walks you through each task in Microsoft Teams, with the optional Certaria AI Agent for conversational interpretation when you enable Copilot Credits.
See the full processIt answers with your controls and your scan results in context.
An optional add-on, priced separately. A Copilot agent that understands ISO 27001 and your specific implementation. Ask about controls, get policy guidance, check your progress. All inside Microsoft Teams.
Learn moreWhat do I need for Annex A.8 access control?
Based on your scan, you already have 3 of 5 controls evidenced. You still need:
- -Access review schedule
- -Privileged access policy
Pricing
£4,490/year. Not £15,000-40,000.
The Microsoft Teams workflow from day one. The AI Agent is an optional add-on, priced separately.
Certaria Standard
Complete ISO 27001 software. AI Agent optional.
See full pricingTypical consultant
Year 1, then £5-10k ongoing
How it works
From first scan to certification.
Three steps, and you run all of them.
What's included
A complete ISMS on the platform you already pay for.
Everything here is in the £4,490 except the AI Agent, which is an optional add-on.
Readiness Scan
Reads your M365 configuration and maps it to all 14 Annex A categories. Five minutes, read-only. Initial plus monthly recurring.
AI Compliance Agent
Priced separately, with Microsoft Copilot credits on top. An in-Teams Copilot agent for ISO 27001 guidance in the context of your ISMS.
What controls am I missing?
You need 2 more: access review and privileged access.
Policy Templates
Pre-built policies deployed to SharePoint. Editable, auditor-ready.
Task Generation
Automated gap-closing tasks prioritised by impact across your team.
Evidence & Progress
Graph API collects M365 evidence automatically. Real-time dashboard tracks coverage with exportable reports.
Our story
We are certifying ourselves with it.
We built Certaria to solve our own ISO 27001 problem. Same constraints as you. A small team, and a business that could not stop for a year.
We built it to read the evidence Microsoft 365 already holds, and we are using Certaria to pursue our own certification. It is the same system we sell to you.
The scars are in the product.
Microsoft professional certifications
Azure, Data, AI, and Power Platform
Cyber Essentials Certified
UK Government-backed baseline
ISO 27001
Pursuing with Certaria.
See where you stand.
Run the free readiness scan and see how much of ISO 27001 your tenant already covers.