Skip to content

The compliance summary

The one-page PDF of where your ISMS stands, how to send it on a schedule, and why the emailed copy is the last one you produced.

Audience: ISMS Admin, and anyone preparing for a management review.

Where: the Certaria app produces the summary and keeps it. The Audit Pack container on your SharePoint site is yours to fill.

What it is: a one-page PDF showing where your ISMS stands across five headline measures. It is the artefact you take to a management review, and the one you send upward when someone asks how compliance is going.

MeasureWhat it shows
Certification statusWhere you are against ISO 27001:2022
Control implementationA single percentage across the Annex A controls
Last internal auditThe date, or that none has been recorded
Last management reviewThe date, or that none has been recorded
Last readiness scanThe scan date and your Microsoft Secure Score

It carries your organisation name, the date it was produced, and a closing paragraph naming the Microsoft 365 sources the figures came from: Secure Score, Intune device compliance, Entra Conditional Access, Purview sensitivity labels, and the Unified Audit Log.

Generate a summary from within Certaria. The finished document is kept against your organisation settings, so you can download or email it again later without producing it afresh.

That storage behaviour is deliberate, and it has one consequence worth knowing.

The email arrives branded with your organisation name, with the PDF attached, to the recipients you choose. It only sends email and never changes your records.

Certaria can produce and send a summary on a recurring basis. It checks once a day whether one is due, then generates and emails it to the recipients you nominated.

A monthly or quarterly cadence matched to your management review meeting is usually the right choice: the summary then exists before the meeting rather than being produced during it.

ISO 27001 Clause 9.3 requires management review at planned intervals, with defined inputs. The summary covers part of that, and the logged send history evidences that the reviews were fed. It does not replace the meeting, the minutes, or the decisions taken.

A workable pattern:

  1. Schedule the summary to arrive a few days before the review.
  2. Review it alongside the open risks, overdue tasks and any incidents since last time.
  3. Record the decisions as tasks with owners, so the next review can see what happened to them.

Your ISMS site has an Audit Pack container, visible to administrators only, for the material you assemble ahead of an audit. Certaria does not fill it for you. What belongs there is what your auditor asked for, which varies more than any product can predict.

Typical contents: the current Statement of Applicability, recent compliance summaries, the acknowledgement register, incident and corrective action history, and evidence of management review.

SymptomCauseFix
The emailed PDF shows old figuresEmail sends the last generated copyGenerate first, then send
No scheduled summaries arriveScheduled sending is off until a schedule is setSet one under Settings
The summary looks thinIt reflects the state of your ISMS, which early on is genuinely thinCompare successive summaries rather than judging one in isolation
Recipients did not receive itThe address list, or their mail filteringCheck the send log first: it records what was sent and to whom