Microsoft + ClaudeOne partner for the cloud you run and the AI you put on top of it.
Avalon Web ServicesMicrosoft · Claude · Security

Compliant, certified, and able to prove it are three different things

Compliant, certified, and we have evidence get used as if they are one claim, and the difference shows the moment a customer or auditor asks for proof. Compliant is something you say about your own controls, unchecked by anyone outside your organisation. Certified is something a named, accredited body says, against a defined scope, on a specific date — and Microsoft's own SOC 2 and ISO/IEC 27001 certifications cover Microsoft's cloud services, not how your organisation configured its tenant. We have evidence is backed today by something dated and exportable: observed control state plus the attestations no tool can see for itself. No software makes anyone compliant or certified; it can only produce that third kind of proof.

Written by
Arif Ali Mughal
Published
Reading time
8 min

01 / 11

A question the billing company cannot answer with a certificate

Consider a fictional 60-person healthcare billing company. A hospital system it processes claims for sends a one-line security questionnaire: prove you are HIPAA compliant. Someone on the billing company's side wants to type yes and move on. The honest answer is longer, because HIPAA compliant, SOC 2 certified, and we can show you our controls are three different sentences, and the hospital's one-line question could reasonably mean any of them.

This mix-up is not the billing company's fault. The three words get used interchangeably in sales decks and RFP answers, and most of the time nobody calls it out. It gets called out here, because the difference is the entire reason evidence-based reporting exists as something separate from a badge on a website.

02 / 11

Three words, three different claims

Strip the marketing off each word and what is left is three different kinds of claim, made by three different parties.

  • Compliant — a first-party claim. You are saying your own controls meet a standard; nobody outside your organisation has checked it.
  • Certified — a third-party claim. A named, accredited body examined a defined scope against a named standard and dated the result.
  • We have evidence — what you can hand over today: a description of your observed technical state plus the attestations no tool can see, both dated.
COMPLIANT, CERTIFIED, OR EVIDENCED COMPLIANT A CLAIM YOU MAKE You assert your own controls meet a named standard. True the moment you say it; no outside party attested it. Shelf life: until something changes, or someone checks. CERTIFIED A THIRD PARTY'S CLAIM An accredited body audits a named scope, on a stated date. ISO does not certify; the accredited body does. Shelf life: set by the audit cycle, then reassessed. WE HAVE EVIDENCE WHAT YOU CAN PROVE TODAY A dated export of observed state, plus the attestations no tool can observe on its own. Anyone holding it can Shelf life: as current as the last collection cycle. The middle two are claims about the past. Evidence is the only one you can hand over today. Read from Microsoft Learn, ISO.org, AICPA/Journal of Accountancy and HHS.gov on 20 September 2026.
Compliant and certified both describe a point already behind you: a self-assessment, or somebody else's audit of a defined scope on a stated date. Evidence is the only one of the three built to be handed over the moment it is asked for, because it is dated and checkable by whoever receives it, rather than remembered or taken on trust.

03 / 11

What compliant actually claims

Compliant is a self-assessment, and there is nothing wrong with making one — organisations do it constantly, often correctly. What changes the sentence's weight is who is saying it and to whom. Said internally, to your own leadership, it is a working judgement your own team stands behind and can revise. Said externally, to a customer who cannot see inside your tenant, it is asking them to accept a claim nobody outside your walls has verified.

None of this is unique to healthcare, or Microsoft 365. It is why compliant, said with no named assessor and no date attached, tells a reader almost nothing about what was actually checked, or when — our reading of the word, not a rule written into any standard we found.

04 / 11

What certified actually requires

Certified means a specific, checkable thing happened: an accredited body examined a defined scope against a named standard and put its own name on the result. ISO is explicit that it is not that body. On its own certification page, ISO states plainly that it does not perform certification or issue certificates, and that certification is performed by external certification bodies, thus a company or organization cannot be certified by ISO. ISO's own definition of certification is written assurance (a certificate) that the product, service or system in question meets specific requirements — assurance from the certifying body, not from the standards organisation whose name is on the document.

ISO/IEC 27001:2022, the current edition, is the world's best-known standard for information security management systems (ISMS), and ISO describes certification against it as one way to demonstrate to stakeholders and customers that you are committed and able to manage information securely and safely. Two details carry the weight here: the certificate names a scope — which systems, sites, and processes were actually examined, not automatically your whole organisation — and it carries a date, because a management system audited in one year is not the same system running today.

Certification bodies also do not hand over a certificate and disappear; keeping one current typically requires further audits over time, part of why the date matters as much as the scope. We are describing how this generally works, not quoting a specific interval from ISO's own pages, because ISO's certification page does not publish one.

05 / 11

What a SOC 2 report actually is

SOC 2 is not one document; it is one of two possible documents, and the difference matters more than the shared name suggests. A Type 1 report, in the AICPA's own description, focuses on a description of a service organization's system and on the suitability of the design of its controls as of one specified date. A Type 2 report contains the same opinions as a type 1 report with the addition of an opinion on the operating effectiveness of the controls, tested across a stated period. A Type 1 says the controls were designed sensibly on one day; a Type 2 says they actually operated that way for months.

Both are produced by an outside accounting firm, never by the organisation being examined. Microsoft's own SOC 2 Type 2 report, for example, states it is based on rigorous comprehensive third-party examinations... conducted by an independent AICPA accredited CPA firm, covering named services including Azure, Microsoft Defender XDR, Microsoft Intune, and Office 365, among more than twenty others. That named list is the report's actual boundary. A vendor who says we have a SOC 2 without naming the systems and the period is asking you to take the boundary on faith.

06 / 11

Why Microsoft's own certifications stop at Microsoft's edge

This is the point that trips up the most people, because it sounds like it should transfer, and it does not. Microsoft's own shared-responsibility guidance states that in any cloud model, you always retain the following responsibilities: Data... Endpoints... Accounts... Access management. A software-as-a-service tenant's configuration, and the identities inside it, belong to the customer, regardless of what Microsoft has certified about its own platform.

Microsoft's own compliance pages say this about their own certifications, not as a footnote but as the scope statement. On ISO/IEC 27001, Microsoft states: You're responsible, however, for engaging an assessor to evaluate the controls and processes within your own organization and your implementation for ISO/IEC 27001 compliance. Microsoft being certified tells a customer that Microsoft's own infrastructure and processes were examined. It says nothing about whether that customer turned on multifactor authentication or left a legacy protocol open. That gap is exactly what the billing company's hospital customer needs answered, and no certificate Microsoft holds answers it for them.

07 / 11

A benchmark is a baseline, not a certificate

CIS Benchmarks are a third vocabulary entirely, and folding them into certification talk is its own common mistake. CIS describes its benchmarks as prescriptive configuration recommendations built through the consensus-based effort of cybersecurity experts globally — a checklist for configuring a product securely, not an examination of whether any particular organisation did so. There is no CIS auditor who certifies a tenant against the benchmark; you, or a tool, check your own settings against the published list.

The list itself also moves, which matters for anyone citing a version number. As of 20 September 2026, CIS's own site lists Microsoft 365 Foundations (7.0.0) as the current benchmark. Any reference naming an earlier version — v3.1, for instance, which still circulates in vendor documentation — is describing a baseline CIS has since revised. That is not a scandal; benchmarks get updated as products change. It does mean a version number is a fact with a short shelf life, worth checking against CIS's own page rather than repeating from memory — including ours.

08 / 11

HIPAA has no certification, and HHS says so directly

Healthcare gets a special complication, because HIPAA has no certification at all, not a weak one, none. HHS's own guidance answers this directly: No, there is no standard or implementation specification that requires a covered entity to 'certify' compliance.

HHS goes further: HHS does not endorse or otherwise recognize private organizations' 'certifications' regarding the Security Rule, and such certifications do not absolve covered entities of their legal obligations under the Security Rule. Read literally, the exact request the billing company received, prove you are HIPAA compliant, cannot be answered with a certificate, because the agency that enforces HIPAA has stated no such certificate exists in any form it recognises. What can be answered is what controls are in place, when they were last checked, and what evidence backs that observation. That is a longer answer than a badge, and it is the true one.

09 / 11

What a tool can add, and what it cannot

Somewhere in this picture sits software, because few organisations track their own control state entirely by hand. Microsoft's own Purview Compliance Manager is a useful example of how a vendor describes this honestly. Microsoft calls it a solution that helps you automatically assess and manage compliance across your multicloud environment, offering over 360 regulatory templates and detailed step-by-step guidance on suggested improvement actions, rolled into a risk-based compliance score to help you understand your compliance posture. Read closely, none of that says the tool makes an organisation compliant, and none of it claims certification. It assesses, tracks, and scores progress toward standards the organisation chose to measure itself against.

That is the honest description of what any tool in this category can contribute, regardless of vendor. It can assess, track, and produce a dated record. It cannot certify anything, and it cannot make an organisation compliant — those are claims only an accredited body, or your own leadership, can make. What a tool can hand over is the third item on this list: evidence, dated and checkable by someone who was not in the room when it was collected.

10 / 11

The three words, side by side

Put next to each other, the practical differences are about who is speaking, what backs the claim, and how long it stays true before someone should look again.

Who can truthfully say itWhat backs itShelf lifeWhat a tool can add
CompliantYou, about your own controlsYour own assessment, self-attestedUntil something changesRuns assessments, flags gaps
CertifiedAn accredited certification bodyAn audit against a named standardSet by the audit cycle, then re-checkedFeeds the audit evidence, not the seal
We have evidenceAnyone holding a dated exportObserved state plus recorded attestationsAs current as the last collectionThis is what it produces

11 / 11

Where to start

Before answering any question that uses compliant, certified, or evidence as if they were interchangeable, ask which one the other side actually needs. A customer's security questionnaire, a cyber-insurance renewal, and a regulator's inquiry are not asking the same question, even when they reuse the same word. Write down, today, what you could actually hand over if asked this afternoon: a control description, a certificate with its scope and date, or a dated export. If the honest answer is none of the three, that gap, not a badge, is this week's priority.

Disclosure: this is a category we sell into. Avalon CloudSec is a continuous Microsoft 365 and Azure security and compliance assurance platform, run as a managed service by Avalon Web Services LLC, and it maps observed technical state and recorded attestations to named frameworks including HIPAA, NIST CSF 2.0, and ISO/IEC 27001:2022, exportable as an immutable, point-in-time PDF snapshot with a SHA-256 integrity hash. It produces technical evidence, not certification or compliance: it cannot examine your organisation the way an accredited body does, and it cannot see the controls no tool can observe, which is why recorded attestations sit alongside the automated checks rather than replacing them. If you need proof today rather than a badge next quarter, email support@awservices.org.

Microsoft, Microsoft 365, Azure, Entra, Intune and Defender are trademarks of the Microsoft group of companies. Avalon CloudSec is an independent service and is not endorsed by Microsoft.

Primary sources

Want us to run this for you?

Start here

Tell us what'skeeping you upat night.

Most engagements start with a Cloud Health Check — one week, full audit, top-10 findings, 90-day roadmap. Many turn into a longer engagement; either way, you walk away with a prioritized plan you own.