- Documentation
- Run your ISMS
The compliance summary
The one-page PDF of where your ISMS stands, how to send it on a schedule, and why the emailed copy is the last one you produced.
Audience: ISMS Admin, and anyone preparing for a management review.
Where: the Certaria app produces the summary and keeps it. The Audit Pack container on your SharePoint site is yours to fill.
What it is: a one-page PDF showing where your ISMS stands across five headline measures. It is the artefact you take to a management review, and the one you send upward when someone asks how compliance is going.
What is on it
Section titled “What is on it”| Measure | What it shows |
|---|---|
| Certification status | Where you are against ISO 27001:2022 |
| Control implementation | A single percentage across the Annex A controls |
| Last internal audit | The date, or that none has been recorded |
| Last management review | The date, or that none has been recorded |
| Last readiness scan | The scan date and your Microsoft Secure Score |
It carries your organisation name, the date it was produced, and a closing paragraph naming the Microsoft 365 sources the figures came from: Secure Score, Intune device compliance, Entra Conditional Access, Purview sensitivity labels, and the Unified Audit Log.
Producing one
Section titled “Producing one”Generate a summary from within Certaria. The finished document is kept against your organisation settings, so you can download or email it again later without producing it afresh.
That storage behaviour is deliberate, and it has one consequence worth knowing.
The email arrives branded with your organisation name, with the PDF attached, to the recipients you choose. It only sends email and never changes your records.
Sending on a schedule
Section titled “Sending on a schedule”Certaria can produce and send a summary on a recurring basis. It checks once a day whether one is due, then generates and emails it to the recipients you nominated.
A monthly or quarterly cadence matched to your management review meeting is usually the right choice: the summary then exists before the meeting rather than being produced during it.
Using it at a management review
Section titled “Using it at a management review”ISO 27001 Clause 9.3 requires management review at planned intervals, with defined inputs. The summary covers part of that, and the logged send history evidences that the reviews were fed. It does not replace the meeting, the minutes, or the decisions taken.
A workable pattern:
- Schedule the summary to arrive a few days before the review.
- Review it alongside the open risks, overdue tasks and any incidents since last time.
- Record the decisions as tasks with owners, so the next review can see what happened to them.
Assembling material for an auditor
Section titled “Assembling material for an auditor”Your ISMS site has an Audit Pack container, visible to administrators only, for the material you assemble ahead of an audit. Certaria does not fill it for you. What belongs there is what your auditor asked for, which varies more than any product can predict.
Typical contents: the current Statement of Applicability, recent compliance summaries, the acknowledgement register, incident and corrective action history, and evidence of management review.
Common failure modes
Section titled “Common failure modes”| Symptom | Cause | Fix |
|---|---|---|
| The emailed PDF shows old figures | Email sends the last generated copy | Generate first, then send |
| No scheduled summaries arrive | Scheduled sending is off until a schedule is set | Set one under Settings |
| The summary looks thin | It reflects the state of your ISMS, which early on is genuinely thin | Compare successive summaries rather than judging one in isolation |
| Recipients did not receive it | The address list, or their mail filtering | Check the send log first: it records what was sent and to whom |
- The Statement of Applicability, the other document an auditor asks for
- Tasks and deadlines
- Exporting your data, for a full snapshot rather than a summary