ISO 27001:2022 Software

ISO 27001 compliance software built for Microsoft 365

All 93 ISO 27001:2022 controls mapped to your M365 tenant. Automated evidence collection, approval workflows and audit-ready reports — so you can focus on closing gaps, not gathering paperwork.

14-day free trial

Everything you need for ISO 27001 audit readiness

From initial gap analysis to maintaining your certificate — Certvik automates the operational work so your team can focus on improving security.

All 93 controls mapped

Every ISO 27001:2022 control is pre-mapped and scored automatically against your Microsoft 365 environment. No manual assessment needed to get started.

Instant gap analysis

Connect your M365 tenant and immediately see which controls pass, which have gaps, and what to prioritise. Certvik gives you actionable findings, not a raw score.

Automated evidence collection

Evidence is pulled from your M365 environment on a schedule. No more chasing screenshots or exporting reports manually.

Approval workflows

Evidence is reviewed and approved through a structured workflow. Your auditor receives clean, timestamped documentation — not a folder dump.

Scheduled reassessments

Controls have review dates. Certvik sends reminders to the right people before deadlines — so nothing slips between audits.

Compliance roadmap

A prioritised action plan showing you exactly what to fix and in what order to achieve certification as efficiently as possible.

Audit-ready reports

Generate Word and PDF compliance reports on demand — formatted for auditors, executives or enterprise customers. No manual compilation needed.

Downloadable Word templates

Every ISO 27001:2022 control comes with a downloadable Word (.docx) template — basic and detailed variants — giving you a head start on the policy and procedure documentation your auditor expects.

M365 coverage mapped to frameworks

Reads from your M365 environment

Entra ID / MFAConditional AccessIntuneDefenderSharePointExchange
Control areaISO 27001SOC 2
Access control & MFA
Authentication policy
Device compliance
Threat detection
Data access governance
Email & comms security
Privileged access
Audit logging
Full coverage Partial coverage Not applicable

See it in action

Explore the dashboard, controls tracking, and evidence management — exactly as your team will use it.

ISO 27001 compliance dashboard in Certvik
app.certvik.com
Certvik

Compliance Dashboard

Contoso Ltd · Last scan: Today 02:00 UTC

SM

Compliance Score

74%

+6 pts this month

Secure Score

61%

Microsoft benchmark

MFA Coverage

88%

22 / 25 users

Open Findings

5

2 high severity

Score breakdown

88%Identity
61%Devices
74%Data

Active findings

high

MFA not enforced for 3 admin accounts

Enable MFA via Conditional Access

high

Guest access unrestricted in SharePoint

Restrict external sharing to verified domains

medium

14 devices not enrolled in Intune

Enforce device compliance policy

medium

Audit log retention below 90 days

Extend retention to 180 days in Purview

low

2 inactive accounts enabled over 90 days

Disable or remove stale accounts

Scan history

9 Jun 2026, 02:00
74%+2
2 Jun 2026, 02:00
72%+1
26 May 2026, 02:00
71%-3
19 May 2026, 02:00
74%+6

Why ISO 27001 programmes stall — and how Certvik fixes it

Real frustrations from security practitioners, and what we do differently.

The problem

"We implemented all the controls but nearly failed the audit because nothing was documented."

How Certvik solves it

Certvik scans your M365 tenant and records the state of each security control with a timestamp and a control reference — so when an auditor asks for evidence that a control was active, you have a dated, structured record to show them. It won't write your policies or fill out documents for you, but it does capture the technical evidence trail that auditors need for your M365-based controls.

The problem

"Evidence collection is a nightmare — it lives in twelve different places and someone has to chase it all down before every audit."

How Certvik solves it

Certvik pulls evidence directly from your M365 environment on a schedule. MFA status, Conditional Access policies, audit logs, device compliance — all collected automatically with timestamps and control references attached.

The problem

"We passed our surveillance audit in January. By March half our settings had drifted and we had no idea."

How Certvik solves it

Continuous scanning detects configuration drift between audit cycles and alerts you the moment a previously-compliant control falls out of configuration. You're not relying on a once-a-year snapshot.

The problem

"We're transitioning from ISO 27001:2013 to 2022 and have no idea which of the 11 new controls we actually satisfy."

How Certvik solves it

Certvik is built on ISO 27001:2022 throughout. Connect your tenant and immediately see which of the 11 new controls (cloud services, threat intelligence, data masking and more) your M365 environment already satisfies — and which have gaps.

The problem

"Microsoft Secure Score says we're at 72% but our auditor said that tells them nothing about ISO 27001 compliance."

How Certvik solves it

Your auditor is right — Secure Score doesn't map to ISO 27001 control language. Certvik takes the same M365 configuration data and maps it to specific ISO 27001:2022 clause and control references that auditors actually use.

What is ISO 27001?

ISO 27001 is the international standard for information security management systems (ISMS). It provides a framework of 93 controls covering people, processes and technology that organisations use to protect sensitive information.

Certification is increasingly required by enterprise customers, government contracts, and regulations such as NIS2 in the EU. For fast-growing technology companies, ISO 27001 is often the first formal compliance requirement they encounter.

Getting certified involves a formal audit by an accredited certification body. Maintaining the certificate requires annual surveillance audits and a three-year full recertification cycle — which is where Certvik's continuous monitoring and reassessment scheduling becomes most valuable.

What makes Certvik different

Most compliance platforms treat Microsoft 365 as one of many integrations. Certvik is built specifically for M365-first organisations — which means the control mapping, evidence collection, and gap analysis are all designed around how M365 actually works.

Where generic platforms give you a checklist to fill in, Certvik reads your M365 configuration directly via the Microsoft Graph API and maps it to ISO 27001:2022 control language automatically. The result is a gap analysis that reflects your real environment on day one, not a template you have to manually populate.

Certvik helps with audit preparation and readiness. It is not a substitute for working with a qualified ISO 27001 consultant or certification body — but it significantly reduces the manual work that used to make compliance programmes slow and expensive.

Common questions about ISO 27001

Do I need an ISO 27001 consultant to use Certvik?

Certvik handles the operational side — evidence collection, scheduling, approvals and documentation. Most companies still work with a consultant for gap assessment advice and audit preparation, but Certvik significantly reduces the hours they need to spend on your account.

How long does ISO 27001 certification take?

Typically 3–12 months depending on your starting point and company size. Certvik's gap analysis and automation can compress this significantly by eliminating the manual work that usually takes the most time.

Does Certvik work with any certification body?

Yes. Certvik produces documentation and evidence packs that meet the requirements of all major ISO 27001 certification bodies. Your auditor works directly from the reports Certvik generates.

What Microsoft 365 data does Certvik access?

Certvik reads security configuration data — things like MFA status, Conditional Access policies, audit logs and device compliance. It never reads your emails, documents or personal data.

Is Certvik ISO 27001 software or a consultancy?

Certvik is software. It automates the operational work — evidence collection, scheduling, approvals, and reporting. Most organisations still work with an external consultant for ISMS design and audit preparation, but Certvik handles the work that used to consume most of those billable hours.

How does Certvik differ from Microsoft Secure Score?

Microsoft Secure Score measures your security posture against Microsoft's own recommendations. It does not map to ISO 27001 control language. Certvik takes the same underlying M365 configuration data and maps it to the specific ISO 27001:2022 clauses and controls that your auditor uses.

Does Certvik help with ISO 27001:2022 specifically?

Yes. Certvik is built on ISO 27001:2022 throughout, including the 11 new controls introduced in the 2022 revision. If you are transitioning from the 2013 standard, Certvik helps you identify which new controls your M365 environment already satisfies.

How long before we're audit-ready?

The gap analysis is immediate on connection. Building a full evidence pack and closing critical gaps typically takes weeks rather than months when collection and scheduling are automated. Timeline depends on your starting point — Certvik helps you see it clearly from day one.

Free resource

Free ISO 27001 Evidence Checklist

See the types of evidence auditors commonly expect when reviewing ISO 27001 controls — policies, access reviews, MFA records, risk treatment, and approval records.

Want a structured review first?

Book a Microsoft 365 Security & Compliance Assessment — an expert review of your tenant delivered as a written report.

Book Assessment

Get your ISO 27001 gap analysis today

Connect your Microsoft 365 tenant and see exactly where you stand against all 93 controls. Free for 14 days.

ISO 27001 add-on: +$299/month after trial

Not ready for software yet? Book a Microsoft 365 Security Assessment