Your route to certification
From landing on this page to a certified app – here's how it works and what happens after you submit the form.
You're here
Microsoft has pointed you to Claranet, its independent assessor, to get your app certified.
Submit the form
Tell us about your application. One of our team will be in touch quickly with your next steps.
Prerequisite check & call
We confirm you have the prerequisites in place to start, then book you in – so no one pays for a process they can't yet begin.
Statement of work
We scope the assessment from your pre-call and send a fixed-price statement of work to sign. Nothing chargeable starts until it's signed.
Workshop & assessment
Your paid engagement opens with the half-day kick-off workshop, then we review your evidence against the framework in two phases, with a pause to close gaps. Penetration testing is scoped and runs where it's needed.
Certified
On a pass, we recommend your app to Microsoft. You receive the Microsoft 365 certified badge and a branding pack. If you do not meet the criteria on first attempt, we will provide advice on the steps you need to take to be compliant
Microsoft appointed independent assessor for Microsoft 365 Certification
6.5 days of consultancy, assessment, and reporting
12 months certification validity, with annual recertification
2 phases assess, then validate – with a pause to remediate
Assessment options
Choose the assessment that fits where you are. Every option is scoped to your app.
Bolt-ons
BOLT-ON
Extra-time bolt-on
Additional consultancy days when a submission needs more time. Includes reporting time.
BOLT-ON
Pentest day rate
Penetration testing by the Claranet Offensive Security Team, aligned to the OWASP Top 10 and SANS Top 25. A current penetration test is required for certification, scoped separately after the workshop.
What you receive
Consultancy findings
How you receive your findings:
Virtual consultancy – A live working session held over screen sharing, supported by a standalone report that outlines each control domain, highlighting where you meet the requirements and where improvements are needed. Our consultants will guide you through the findings, answer your questions, and discuss the recommended next steps.
Assessment outcome
Our final determination of whether your application meets the required security benchmarks. Where you've passed, that includes our certification recommendation; where the outcome is a fail, we set out the further support available to get you there.
Penetration test report
Where you buy testing from us, a report from the Claranet Offensive Security Team detailing the scope, findings, and severity ratings.
Certification and branding pack
On a successful outcome, the certified badge and a Microsoft branding pack for the commercial marketplace, plus trust evidence you can share with IT administrators.
What is the Microsoft 365 App Compliance Assessment?
The independent audit behind Microsoft 365 Certification
Claranet is Microsoft's appointed independent assessor for Microsoft 365 Certification. We assess your application and hosting environment against the security controls of Microsoft's certification framework – spanning application security, operational security, and data handling, security, and privacy – and provide the consultancy to review and report on where you meet the requirements and where you fall short.
We deliver the service in two consultancy phases separated by a short, agreed pause. After the half-day kick-off workshop and scoping, we review your security controls and set out your current position. The pause gives you time to gather further evidence and make changes where you need to focus your attention. We then review your updated evidence and award a clear pass or fail outcome – with a follow-up report where you've chosen virtual consultancy.
On a successful outcome, your application is awarded Microsoft 365 Certification and the certified badge, and you receive a branding pack that marks it as compliant and approved in the Microsoft commercial marketplace. Certification is valid for 12 months.
Why it's worth it?
Certification isn't just a badge – it's a commercial advantage that earns back the investment.
-
Enhanced visibility, filtering, and discovery across Microsoft 365 storefronts and admin centres – so customers find your app
-
Trust evidence you can share with IT administrators, speeding up their security reviews and shortening your sales cycle
-
The certified badge marks your app as compliant and approved in the commercial marketplace
-
For some apps, certification is the prerequisite to run inside a customer's Microsoft tenant
-
An independent assessment from Microsoft's appointed assessor – the badge is awarded on our recommendation
-
A clear pass or fail readiness outcome, with prioritised recommendations for each control domai
Before you start
Some controls are mandatory hard fails – you can't begin the process without them. Before you commit, it's worth checking you already have:
- Anti-malware or application control
- Patch management
- Quarterly vulnerability scanning
- Multi-factor authentication on remote and administrative access
- Encryption of data in transit using TLS 1.2 or above
- Strong encryption of data at rest
- A complete GDPR privacy notice
- No unresolved critical or high-severity penetration test or vulnerability scan findings
These are the prerequisites to start, not the full bar to pass. Certification means meeting Microsoft's scored thresholds across all three security domains – many more controls than the hard fails above. You can see the full control set on Microsoft's certification framework overview. Not sure where you stand? Our gap analysis, or the scoping workshop itself, will tell you.
Ready to get your app certified?
Send us your details and one of our specialists will be in touch with your next steps.



