Compliant, certified, and able to prove it are three different things
Compliant, certified, and we have evidence get used as if they are one claim, and the difference shows the moment a customer or auditor asks for proof. Compliant is something you say about your own controls, unchecked by anyone outside your organisation. Certified is something a named, accredited body says, against a defined scope, on a specific date — and Microsoft's own SOC 2 and ISO/IEC 27001 certifications cover Microsoft's cloud services, not how your organisation configured its tenant. We have evidence is backed today by something dated and exportable: observed control state plus the attestations no tool can see for itself. No software makes anyone compliant or certified; it can only produce that third kind of proof.
01 / 11
A question the billing company cannot answer with a certificate
Consider a fictional 60-person healthcare billing company. A hospital system it processes claims for sends a one-line security questionnaire: prove you are HIPAA compliant. Someone on the billing company's side wants to type yes and move on. The honest answer is longer, because HIPAA compliant, SOC 2 certified, and we can show you our controls are three different sentences, and the hospital's one-line question could reasonably mean any of them.
This mix-up is not the billing company's fault. The three words get used interchangeably in sales decks and RFP answers, and most of the time nobody calls it out. It gets called out here, because the difference is the entire reason evidence-based reporting exists as something separate from a badge on a website.
02 / 11
Three words, three different claims
Strip the marketing off each word and what is left is three different kinds of claim, made by three different parties.
- Compliant — a first-party claim. You are saying your own controls meet a standard; nobody outside your organisation has checked it.
- Certified — a third-party claim. A named, accredited body examined a defined scope against a named standard and dated the result.
- We have evidence — what you can hand over today: a description of your observed technical state plus the attestations no tool can see, both dated.
03 / 11
What compliant actually claims
Compliant is a self-assessment, and there is nothing wrong with making one — organisations do it constantly, often correctly. What changes the sentence's weight is who is saying it and to whom. Said internally, to your own leadership, it is a working judgement your own team stands behind and can revise. Said externally, to a customer who cannot see inside your tenant, it is asking them to accept a claim nobody outside your walls has verified.
None of this is unique to healthcare, or Microsoft 365. It is why compliant, said with no named assessor and no date attached, tells a reader almost nothing about what was actually checked, or when — our reading of the word, not a rule written into any standard we found.
04 / 11
What certified actually requires
Certified means a specific, checkable thing happened: an accredited body examined a defined scope against a named standard and put its own name on the result. ISO is explicit that it is not that body. On its own certification page, ISO states plainly that it does not perform certification or issue certificates, and that certification is performed by external certification bodies, thus a company or organization cannot be certified by ISO. ISO's own definition of certification is written assurance (a certificate) that the product, service or system in question meets specific requirements — assurance from the certifying body, not from the standards organisation whose name is on the document.
ISO/IEC 27001:2022, the current edition, is the world's best-known standard for information security management systems (ISMS), and ISO describes certification against it as one way to demonstrate to stakeholders and customers that you are committed and able to manage information securely and safely. Two details carry the weight here: the certificate names a scope — which systems, sites, and processes were actually examined, not automatically your whole organisation — and it carries a date, because a management system audited in one year is not the same system running today.
Certification bodies also do not hand over a certificate and disappear; keeping one current typically requires further audits over time, part of why the date matters as much as the scope. We are describing how this generally works, not quoting a specific interval from ISO's own pages, because ISO's certification page does not publish one.
05 / 11
What a SOC 2 report actually is
SOC 2 is not one document; it is one of two possible documents, and the difference matters more than the shared name suggests. A Type 1 report, in the AICPA's own description, focuses on a description of a service organization's system and on the suitability of the design of its controls as of one specified date. A Type 2 report contains the same opinions as a type 1 report with the addition of an opinion on the operating effectiveness of the controls, tested across a stated period. A Type 1 says the controls were designed sensibly on one day; a Type 2 says they actually operated that way for months.
Both are produced by an outside accounting firm, never by the organisation being examined. Microsoft's own SOC 2 Type 2 report, for example, states it is based on rigorous comprehensive third-party examinations... conducted by an independent AICPA accredited CPA firm, covering named services including Azure, Microsoft Defender XDR, Microsoft Intune, and Office 365, among more than twenty others. That named list is the report's actual boundary. A vendor who says we have a SOC 2 without naming the systems and the period is asking you to take the boundary on faith.
06 / 11
Why Microsoft's own certifications stop at Microsoft's edge
This is the point that trips up the most people, because it sounds like it should transfer, and it does not. Microsoft's own shared-responsibility guidance states that in any cloud model, you always retain the following responsibilities: Data... Endpoints... Accounts... Access management. A software-as-a-service tenant's configuration, and the identities inside it, belong to the customer, regardless of what Microsoft has certified about its own platform.
Microsoft's own compliance pages say this about their own certifications, not as a footnote but as the scope statement. On ISO/IEC 27001, Microsoft states: You're responsible, however, for engaging an assessor to evaluate the controls and processes within your own organization and your implementation for ISO/IEC 27001 compliance. Microsoft being certified tells a customer that Microsoft's own infrastructure and processes were examined. It says nothing about whether that customer turned on multifactor authentication or left a legacy protocol open. That gap is exactly what the billing company's hospital customer needs answered, and no certificate Microsoft holds answers it for them.
07 / 11
A benchmark is a baseline, not a certificate
CIS Benchmarks are a third vocabulary entirely, and folding them into certification talk is its own common mistake. CIS describes its benchmarks as prescriptive configuration recommendations built through the consensus-based effort of cybersecurity experts globally — a checklist for configuring a product securely, not an examination of whether any particular organisation did so. There is no CIS auditor who certifies a tenant against the benchmark; you, or a tool, check your own settings against the published list.
The list itself also moves, which matters for anyone citing a version number. As of 20 September 2026, CIS's own site lists Microsoft 365 Foundations (7.0.0) as the current benchmark. Any reference naming an earlier version — v3.1, for instance, which still circulates in vendor documentation — is describing a baseline CIS has since revised. That is not a scandal; benchmarks get updated as products change. It does mean a version number is a fact with a short shelf life, worth checking against CIS's own page rather than repeating from memory — including ours.
08 / 11
HIPAA has no certification, and HHS says so directly
Healthcare gets a special complication, because HIPAA has no certification at all, not a weak one, none. HHS's own guidance answers this directly: No, there is no standard or implementation specification that requires a covered entity to 'certify' compliance.
HHS goes further: HHS does not endorse or otherwise recognize private organizations' 'certifications' regarding the Security Rule, and such certifications do not absolve covered entities of their legal obligations under the Security Rule. Read literally, the exact request the billing company received, prove you are HIPAA compliant, cannot be answered with a certificate, because the agency that enforces HIPAA has stated no such certificate exists in any form it recognises. What can be answered is what controls are in place, when they were last checked, and what evidence backs that observation. That is a longer answer than a badge, and it is the true one.
09 / 11
What a tool can add, and what it cannot
Somewhere in this picture sits software, because few organisations track their own control state entirely by hand. Microsoft's own Purview Compliance Manager is a useful example of how a vendor describes this honestly. Microsoft calls it a solution that helps you automatically assess and manage compliance across your multicloud environment, offering over 360 regulatory templates and detailed step-by-step guidance on suggested improvement actions, rolled into a risk-based compliance score to help you understand your compliance posture. Read closely, none of that says the tool makes an organisation compliant, and none of it claims certification. It assesses, tracks, and scores progress toward standards the organisation chose to measure itself against.
That is the honest description of what any tool in this category can contribute, regardless of vendor. It can assess, track, and produce a dated record. It cannot certify anything, and it cannot make an organisation compliant — those are claims only an accredited body, or your own leadership, can make. What a tool can hand over is the third item on this list: evidence, dated and checkable by someone who was not in the room when it was collected.
10 / 11
The three words, side by side
Put next to each other, the practical differences are about who is speaking, what backs the claim, and how long it stays true before someone should look again.
| Who can truthfully say it | What backs it | Shelf life | What a tool can add | |
|---|---|---|---|---|
| Compliant | You, about your own controls | Your own assessment, self-attested | Until something changes | Runs assessments, flags gaps |
| Certified | An accredited certification body | An audit against a named standard | Set by the audit cycle, then re-checked | Feeds the audit evidence, not the seal |
| We have evidence | Anyone holding a dated export | Observed state plus recorded attestations | As current as the last collection | This is what it produces |
11 / 11
Where to start
Before answering any question that uses compliant, certified, or evidence as if they were interchangeable, ask which one the other side actually needs. A customer's security questionnaire, a cyber-insurance renewal, and a regulator's inquiry are not asking the same question, even when they reuse the same word. Write down, today, what you could actually hand over if asked this afternoon: a control description, a certificate with its scope and date, or a dated export. If the honest answer is none of the three, that gap, not a badge, is this week's priority.
Disclosure: this is a category we sell into. Avalon CloudSec is a continuous Microsoft 365 and Azure security and compliance assurance platform, run as a managed service by Avalon Web Services LLC, and it maps observed technical state and recorded attestations to named frameworks including HIPAA, NIST CSF 2.0, and ISO/IEC 27001:2022, exportable as an immutable, point-in-time PDF snapshot with a SHA-256 integrity hash. It produces technical evidence, not certification or compliance: it cannot examine your organisation the way an accredited body does, and it cannot see the controls no tool can observe, which is why recorded attestations sit alongside the automated checks rather than replacing them. If you need proof today rather than a badge next quarter, email support@awservices.org.
Microsoft, Microsoft 365, Azure, Entra, Intune and Defender are trademarks of the Microsoft group of companies. Avalon CloudSec is an independent service and is not endorsed by Microsoft.
Primary sources
- Microsoft — Shared responsibility in the cloud
- Microsoft — System and Organization Controls (SOC) 2 Type 2, Microsoft Compliance offering
- Microsoft — ISO/IEC 27001 Information Security Management Standards, Microsoft Compliance offering
- Microsoft — Microsoft Purview Compliance Manager overview
- AICPA / Journal of Accountancy — Explaining the 3 faces of SOC, June 2016
- ISO — Certification
- ISO — ISO/IEC 27001:2022, Information security management systems
- CIS — CIS Benchmarks overview
- CIS — CIS Microsoft 365 Benchmarks
- HHS — Are we required to certify our organization's compliance with the standards? (HIPAA FAQ 2003)