Certaria documentation
Certaria automates the paperwork around ISO 27001 and leaves the judgement to you. These guides cover what you do, what Certaria does on a clock, and how to tell the difference.
Start with your first thirty daysYour people never touch the app
Staff read and acknowledge policies from a SharePoint list, needing nothing beyond your existing Microsoft 365 subscription. Only administrators need a Power Apps licence, which is what keeps the cost of an ISMS proportional to the size of the team running it.
How publishing works- Acknowledge
- Acknowledge
- Acknowledged
Six Microsoft 365 sources, read on a schedule
Most of your evidence already exists
Certaria reads Secure Score, device management, sensitivity labels, audit logging, Conditional Access and directory roles, then credits the Annex A controls each one supports. Evidence is only ever added, never withdrawn, so a failed source does not make your Statement of Applicability lurch.
What a scan readsGuides
Every workflow Certaria performs, and what it expects from you.
Start here
What to do first, in the order to do it.
- Your first thirty days An ordered path from install to a working evidence rhythm.
- Onboarding and site setup The three step wizard, and where your live policies are meant to live.
- Register the app and grant Graph consent About 15 minutes, once. Needs a Global Administrator.
- What Certaria asks of you The page to send everyone else. Written for them, not about them.
Get the foundations right
Done once, at the beginning, and revisited rarely. Everything else assumes these.
- Conditional Access baseline The protections Certaria expects your tenant to already have.
- Who can see and do what The access model, how to maintain it, and how to evidence it at audit.
- Your SharePoint site What Certaria builds there, and what is safe to change once it is.
- Import your people And why a person with no linked account silently receives nothing.
The day-to-day work
The workflows you perform repeatedly once Certaria is running.
- The Statement of Applicability The first document your auditor reads, and the decision trail behind it.
- Policies Adopt, publish, revise and review a policy, and what your people see.
- Evidence and scans What Certaria reads from your tenant, and on what schedule.
- Incidents and concerns What happens automatically at High severity, and what does not.
- Risks You judge likelihood and impact. Certaria does the arithmetic.
- Training records And the monthly check that emails people before their record lapses.
- Tasks and deadlines Where recurring work comes from, and who gets chased when.
- The registers you maintain Four places that arrive empty on purpose, and what an auditor expects.
- The compliance summary The one-page PDF for a management review, and how to schedule it.
The Certaria agent in Teams
Optional. Everything in the core works without it, so none of this is required reading unless you have bought it.
When something does not behave
Not reading material. Here when you need it.