ISO 27001 compliance Microsoft 365

ISO 27001 audits a year of operation. A screenshot shows a day.

Certification runs on a three-year cycle - a stage 1 and stage 2 audit, then annual surveillance audits, then recertification - and the surveillance question is always the same: show that the controls operated all year, not that they exist this week. 1Security measures the tenant-side Annex A controls continuously - access rights, logging, supplier relationships, label protection - captures a dated snapshot every Monday, and exports a per-framework evidence pack, so the year is already on record when the audit is booked.

The scenario

Certification was the project. Staying certified is the job.

ISO/IEC 27001:2022 asks for a running information security management system, backed by 93 Annex A controls across four themes and a Statement of Applicability that says which ones you claim. Stage 2 checks that the design exists. The annual surveillance audit checks that it operated - and this is where programs bleed, because evidence assembled the week before the audit proves the control existed that week. The auditor asks for March.

Here is the arithmetic that makes the tenant side tractable: across eleven frameworks - ISO/IEC 27001 next to NIS2, GDPR, DORA and the EU AI Act - the obligations collapse into 15 shared requirements, 11 of them measured directly from tenant data and only four attested documents. The Annex A controls that live in Microsoft 365 are exactly the measurable ones: access rights (A.5.18), privileged access (A.8.2), logging and monitoring (A.8.15, A.8.16), supplier and cloud relationships (A.5.19, A.5.23). One fix moves ISO 27001, NIS2 and SOC 2 in the same pass.

And if you are not certified yet, the same evaluation answers the earlier question. Frameworks you have not adopted are measured anyway and shown with their own readiness percentage, so how close the tenant already is to certifiable is visible before anyone commits to the project - with deliberately conservative statuses, because not evaluated never counts as a pass. ISO/IEC 42001, the AI management sibling standard, sits in the same eleven and is scored by the same pass.

The walkthrough

From Statement of Applicability to evidence pack, on screens.

Each beat is a screen with a filter and an artifact at the end, not a workshop.

  1. 01

    Open the ISO 27001 framework view

    The Compliance screen scores the tenant against ISO/IEC 27001 control by control, in the order of the standard itself, each citing the shared requirements that satisfy it - with chips like "NIS2 ×2" showing what else a fix moves. The worklist orders every open requirement by how many articles it unlocks, and articles that changed since the last snapshot say what they changed from.

  2. 02

    Evidence the supplier controls

    A.5.19 and A.5.23 ask how supplier and cloud relationships are governed. The Apps screen lists every OAuth app and integration with publisher, access channel and the admin who consented it. The Domains screen lists every external organisation seen in guests, shared files and mail, with its configured standing next to observed activity and contradictions flagged.

  3. 03

    Answer access and logging from measurement

    Open a requirement panel and the verdict comes with its numbers: dormant accounts against the 90-day window for A.5.18, sign-ins outside Conditional Access for A.8.2, log ingestion freshness and open critical anomaly episodes for A.8.15 and A.8.16, restricted files without a protecting label for the data controls. Next-step links land on the screen where each number lives.

  4. 04

    Hand the auditor a dated year

    Snapshots of the whole status document are captured every Monday and on demand, so "show me the state in March" has a real answer instead of a reconstruction. The per-framework evidence pack exports as a dated document and is served over the read-only REST API - the same artifact for the certification body, the internal audit and the board.

What makes it work

Three parts of the platform behind the ISO 27001 answer.

The same 15 requirements score NIS2, GDPR, DORA and the EU AI Act in the same pass - one fix moves every framework that cites it.

  • Compliance monitoring

    Eleven frameworks measured continuously from tenant data, with snapshots, a worklist and a per-framework evidence pack.

    Explore the feature
  • Security score

    Microsoft Secure Score beside the observed score, each control cross-referenced to the ISO 27001 articles it moves - so hardening work and audit evidence are the same list.

    Explore the feature
  • Label coverage

    Which restricted files actually carry a protecting sensitivity label - the measured half of the information-protection controls, counted file by file.

    Explore the feature

FAQ

Common questions.

Does this get us ISO 27001 certified?

No - certification is issued by an accredited body after its own audit, and the ISMS covers people and processes beyond any tool. What 1Security does is evidence the Microsoft 365 slice of it continuously: the tenant-side Annex A controls as measured statuses with dated history, which is the material the surveillance audit spends most of its time on.

How much of Annex A does this actually cover?

The controls that are observable in the tenant: access rights, privileged access, logging and monitoring, supplier and cloud relationships, and information protection through labels. Physical controls, HR processes and systems outside Microsoft 365 need their own evidence sources. The evidence pack is honest about what it covers.

Do we need E5 licenses for this?

No. The measurement, the retained history and the evidence pack run on the standard read-only connection and the licenses you already own. Where a specific remediation does need a premium Microsoft SKU, the product says so on the action itself instead of letting you find out mid-fix.

We are mid-certification. Is this still useful?

That is the best moment to start. The snapshots begin accumulating the day the tenant is connected, so by the time stage 2 or the first surveillance audit arrives there is a dated record of the controls operating - and the worklist tells you which open gaps close the most articles before the auditor finds them.

What about ISO 42001?

ISO/IEC 42001, the AI management system standard, is one of the eleven frameworks the same evaluation scores - fed by the AI-side requirements like an accountable person per agent and captured agent instructions. If AI governance is on your certification roadmap, the readiness percentage is already on the screen.

Walk into the surveillance audit with the year already recorded.

Connect read-only and the ISO 27001 control statuses, the worklist and the first evidence pack land the same day - and every Monday after that adds to the record.

Or keep assembling the binder the week before the audit.