Skip to content

Certaria documentation

Certaria automates the paperwork around ISO 27001 and leaves the judgement to you. These guides cover what you do, what Certaria does on a clock, and how to tell the difference.

Start with your first thirty days

Your people never touch the app

Staff read and acknowledge policies from a SharePoint list, needing nothing beyond your existing Microsoft 365 subscription. Only administrators need a Power Apps licence, which is what keeps the cost of an ISMS proportional to the size of the team running it.

How publishing works

Most of your evidence already exists

Certaria reads Secure Score, device management, sensitivity labels, audit logging, Conditional Access and directory roles, then credits the Annex A controls each one supports. Evidence is only ever added, never withdrawn, so a failed source does not make your Statement of Applicability lurch.

What a scan reads

Guides

Every workflow Certaria performs, and what it expects from you.

Get the foundations right

Done once, at the beginning, and revisited rarely. Everything else assumes these.

The day-to-day work

The workflows you perform repeatedly once Certaria is running.

The Certaria agent in Teams

Optional. Everything in the core works without it, so none of this is required reading unless you have bought it.

When something does not behave

Not reading material. Here when you need it.