Compliance

Marketplace & Certification Readiness

Advanced

Selling through Microsoft AppSource, and meeting the certifications our customers expect, sets a clear bar we must build to. We must not rush to meet it at the end. Readiness is earned over time: secure architecture, evidence, privacy, accessibility, and tested operations, all in place and ready to show. Treat the certification checklist as a design input from day one.

Certification (AppSource publisher requirements, SOC 2 / ISO 27001-style controls, and the security baselines enterprise customers demand) is really an external audit of everything in these guidelines. You meet the bar by doing the work properly all along: authenticated and authorised endpoints, secrets in a vault, data in the right region, evidence trails, penetration testing, accessibility, and disaster recovery. You must also be able to show it on request.

The Finperiti audit made the cost of leaving this late very clear. The verdict was "AppSource NO-GO" with nine certification blockers: unauthenticated endpoints, forgeable webhooks, open CORS, secrets in config, wrong data region, unevidenced AI Act obligations, and end-of-life dependencies. We now have a guideline for every one of those. This topic is the standing checklist that keeps us over the bar at all times, instead of failing an assessment.

Build to the bar continuously

Don't let blockers accumulate

Self-review checklist

Why it matters: Certification and marketplace listing are gates to the customers and revenue the business is built on, and they fail on the exact issues these guidelines prevent. Building to the bar over time, and keeping the evidence, turns certification from a high-risk, last-minute project into a formality. It also means a customer's security questionnaire is something we can answer truthfully and at once.