All 93 ISO 27001:2022 controls mapped to your M365 tenant. Automated evidence collection, approval workflows and audit-ready reports — so you can focus on closing gaps, not gathering paperwork.
14-day free trial
From initial gap analysis to maintaining your certificate — Certvik automates the operational work so your team can focus on improving security.
Every ISO 27001:2022 control is pre-mapped and scored automatically against your Microsoft 365 environment. No manual assessment needed to get started.
Connect your M365 tenant and immediately see which controls pass, which have gaps, and what to prioritise. Certvik gives you actionable findings, not a raw score.
Evidence is pulled from your M365 environment on a schedule. No more chasing screenshots or exporting reports manually.
Evidence is reviewed and approved through a structured workflow. Your auditor receives clean, timestamped documentation — not a folder dump.
Controls have review dates. Certvik sends reminders to the right people before deadlines — so nothing slips between audits.
A prioritised action plan showing you exactly what to fix and in what order to achieve certification as efficiently as possible.
Generate Word and PDF compliance reports on demand — formatted for auditors, executives or enterprise customers. No manual compilation needed.
Every ISO 27001:2022 control comes with a downloadable Word (.docx) template — basic and detailed variants — giving you a head start on the policy and procedure documentation your auditor expects.
M365 coverage mapped to frameworks
Reads from your M365 environment
Entra ID / MFAConditional AccessIntuneDefenderSharePointExchange| Control area | ISO 27001 | SOC 2 |
|---|---|---|
| Access control & MFA | ||
| Authentication policy | ||
| Device compliance | ||
| Threat detection | ||
| Data access governance | ||
| Email & comms security | ||
| Privileged access | ||
| Audit logging |
Explore the dashboard, controls tracking, and evidence management — exactly as your team will use it.

Compliance Dashboard
Contoso Ltd · Last scan: Today 02:00 UTC
Compliance Score
74%
+6 pts this month
Secure Score
61%
Microsoft benchmark
MFA Coverage
88%
22 / 25 users
Open Findings
5
2 high severity
Score breakdown
Active findings
MFA not enforced for 3 admin accounts
Enable MFA via Conditional Access
Guest access unrestricted in SharePoint
Restrict external sharing to verified domains
14 devices not enrolled in Intune
Enforce device compliance policy
Audit log retention below 90 days
Extend retention to 180 days in Purview
2 inactive accounts enabled over 90 days
Disable or remove stale accounts
Scan history
Real frustrations from security practitioners, and what we do differently.
The problem
"We implemented all the controls but nearly failed the audit because nothing was documented."
How Certvik solves it
Certvik scans your M365 tenant and records the state of each security control with a timestamp and a control reference — so when an auditor asks for evidence that a control was active, you have a dated, structured record to show them. It won't write your policies or fill out documents for you, but it does capture the technical evidence trail that auditors need for your M365-based controls.
The problem
"Evidence collection is a nightmare — it lives in twelve different places and someone has to chase it all down before every audit."
How Certvik solves it
Certvik pulls evidence directly from your M365 environment on a schedule. MFA status, Conditional Access policies, audit logs, device compliance — all collected automatically with timestamps and control references attached.
The problem
"We passed our surveillance audit in January. By March half our settings had drifted and we had no idea."
How Certvik solves it
Continuous scanning detects configuration drift between audit cycles and alerts you the moment a previously-compliant control falls out of configuration. You're not relying on a once-a-year snapshot.
The problem
"We're transitioning from ISO 27001:2013 to 2022 and have no idea which of the 11 new controls we actually satisfy."
How Certvik solves it
Certvik is built on ISO 27001:2022 throughout. Connect your tenant and immediately see which of the 11 new controls (cloud services, threat intelligence, data masking and more) your M365 environment already satisfies — and which have gaps.
The problem
"Microsoft Secure Score says we're at 72% but our auditor said that tells them nothing about ISO 27001 compliance."
How Certvik solves it
Your auditor is right — Secure Score doesn't map to ISO 27001 control language. Certvik takes the same M365 configuration data and maps it to specific ISO 27001:2022 clause and control references that auditors actually use.
ISO 27001 is the international standard for information security management systems (ISMS). It provides a framework of 93 controls covering people, processes and technology that organisations use to protect sensitive information.
Certification is increasingly required by enterprise customers, government contracts, and regulations such as NIS2 in the EU. For fast-growing technology companies, ISO 27001 is often the first formal compliance requirement they encounter.
Getting certified involves a formal audit by an accredited certification body. Maintaining the certificate requires annual surveillance audits and a three-year full recertification cycle — which is where Certvik's continuous monitoring and reassessment scheduling becomes most valuable.
Most compliance platforms treat Microsoft 365 as one of many integrations. Certvik is built specifically for M365-first organisations — which means the control mapping, evidence collection, and gap analysis are all designed around how M365 actually works.
Where generic platforms give you a checklist to fill in, Certvik reads your M365 configuration directly via the Microsoft Graph API and maps it to ISO 27001:2022 control language automatically. The result is a gap analysis that reflects your real environment on day one, not a template you have to manually populate.
Certvik helps with audit preparation and readiness. It is not a substitute for working with a qualified ISO 27001 consultant or certification body — but it significantly reduces the manual work that used to make compliance programmes slow and expensive.
Certvik handles the operational side — evidence collection, scheduling, approvals and documentation. Most companies still work with a consultant for gap assessment advice and audit preparation, but Certvik significantly reduces the hours they need to spend on your account.
Typically 3–12 months depending on your starting point and company size. Certvik's gap analysis and automation can compress this significantly by eliminating the manual work that usually takes the most time.
Yes. Certvik produces documentation and evidence packs that meet the requirements of all major ISO 27001 certification bodies. Your auditor works directly from the reports Certvik generates.
Certvik reads security configuration data — things like MFA status, Conditional Access policies, audit logs and device compliance. It never reads your emails, documents or personal data.
Certvik is software. It automates the operational work — evidence collection, scheduling, approvals, and reporting. Most organisations still work with an external consultant for ISMS design and audit preparation, but Certvik handles the work that used to consume most of those billable hours.
Microsoft Secure Score measures your security posture against Microsoft's own recommendations. It does not map to ISO 27001 control language. Certvik takes the same underlying M365 configuration data and maps it to the specific ISO 27001:2022 clauses and controls that your auditor uses.
Yes. Certvik is built on ISO 27001:2022 throughout, including the 11 new controls introduced in the 2022 revision. If you are transitioning from the 2013 standard, Certvik helps you identify which new controls your M365 environment already satisfies.
The gap analysis is immediate on connection. Building a full evidence pack and closing critical gaps typically takes weeks rather than months when collection and scheduling are automated. Timeline depends on your starting point — Certvik helps you see it clearly from day one.
Free resource
See the types of evidence auditors commonly expect when reviewing ISO 27001 controls — policies, access reviews, MFA records, risk treatment, and approval records.
Want a structured review first?
Book a Microsoft 365 Security & Compliance Assessment — an expert review of your tenant delivered as a written report.
Connect your Microsoft 365 tenant and see exactly where you stand against all 93 controls. Free for 14 days.
ISO 27001 add-on: +$299/month after trial
Not ready for software yet? Book a Microsoft 365 Security Assessment