Continuous compliance monitoring: what to check between annual assessments
A certification is a statement about one day. Everything it asserts starts drifting the next morning, and some of it drifts within a week. This is what to check, how often, and why.
Written by Apexward Assure editorial team
Reviewed by Apexward Assure product team
Last reviewed: 30 August 2026
An assessment is a photograph, not a guarantee
When you pass Cyber Essentials on 27 April 2026, what you have demonstrated is that on or around that date, the controls in scope were in place. The certificate does not claim anything about 27 July. Your customers, however, read it as a standing statement, and the contract you signed on the strength of it usually contains a clause requiring you to maintain those controls throughout the term.
The gap between those two things is where most incidents at small suppliers happen. Nothing was deliberately switched off. People joined, a laptop was bought outside the usual process, a contractor kept an account, a subdomain outlived the project it was created for. Continuous assurance is not a grander form of auditing. It is the much duller practice of checking a short list of things often enough that drift is measured in days rather than months.
What actually drifts, and how quickly
Controls do not decay at the same rate. The ones tied to people and to time move fastest, because headcount and calendars change without anyone filing a change request. A useful monitoring programme spends most of its attention there and much less on the controls that only move when somebody deliberately changes them.
Identity and access
- MFA coverage across all accounts. Weekly. This is the single fastest drifting control in a growing company. A new starter is created on Monday, uses the account on Tuesday, and enrols in MFA when prompted, or does not. Break-glass accounts, service accounts and shared mailboxes are the usual permanent gaps. Measure coverage as a percentage and watch the denominator as well as the numerator.
- Leaver accounts disabled. Weekly, and on every leaver. The dangerous case is not the leaver everybody knew about, it is the contractor whose engagement quietly ended. Reconcile active accounts against your current payroll and contractor list rather than against a memory of who left.
- Privileged role membership. Monthly. Administrative access accumulates. Somebody is made a Global Administrator for an afternoon to fix a mail flow rule and stays one for three years. Count the admins each month and require a reason for each one; if the number only ever goes up, the control is not working.
- Full access review. Quarterly. A line-by-line review with system owners, covering standard access as well as privileged. Quarterly is proportionate for most 20 to 200 person organisations and is what an assessor expects to see minuted.
Devices
- Enrolled device count against headcount. Weekly. The devices that fail your controls are the ones your management tool cannot see. If you have 84 people and 71 managed devices, the interesting number is 13.
- Operating system and application patch currency. Weekly. Cyber Essentials expects high and critical patches applied within 14 days, which means a monthly check is already too slow to catch a breach of it. Report the oldest outstanding patch, not the average.
- Disk encryption and screen lock. Monthly. Slower moving, but a new device build or a policy exception can silently exclude a group.
- Unsupported operating systems. Monthly. This one drifts by calendar rather than by action: a version that was supported at your last assessment reaches end of life without anything on your estate changing.
External exposure
- TLS certificate expiry. Weekly, with alerts at 30 and 7 days. Certificates are the most predictable outage in existence and still cause them.
- Domain registration expiry. Monthly. Losing a domain is worse than losing a certificate, and the renewal notice goes to whichever inbox registered it in 2019.
- DNS records and subdomains. Monthly. Look for records pointing at services you no longer run. A CNAME to a decommissioned platform is a subdomain takeover waiting for somebody to notice before you do.
- Internet-facing services and open ports. Monthly. Compare against the list you declared in scope. Anything new should have arrived through a change, not a surprise.
Resilience and third parties
- Backup jobs completing. Weekly. A failing job that nobody reads the alert for is functionally the same as no backup.
- Restore test. Quarterly. Restore something real, record how long it took and who did it. This is the evidence assessors most often find missing, because completing backups feel like proof and are not.
- Third-party and supplier access. Quarterly. Guest accounts, integrations with API tokens, support tooling with standing access to your systems. Reconcile against live contracts.
- Key supplier certifications. Annually, with expiry dates recorded. Their certificate expiring is your problem if you relied on it in a customer answer.
Point-in-time assessment and continuous assurance answer different questions
A point-in-time assessment answers “did this organisation meet the standard when examined?”. Continuous assurance answers “how long has this control been true, and when was it last not?”. The second is a stronger claim, and it is increasingly the one customers ask for in security reviews, because a certificate tells them nothing about the nine months since it was issued.
The practical benefit is smaller and more immediate than the philosophical one. If you check MFA coverage weekly, the drift you find is one or two accounts and takes ten minutes to fix. If you check it annually, the drift you find is a fortnight of remediation immediately before an assessment, done badly, by people who have other work.
Running this without a tool
You can do all of it manually. Build a checklist with four columns: the check, the frequency, the person, and the date it last ran. Put the weekly items in one recurring calendar entry on a Monday morning, the monthly ones on the first working day, and the quarterly ones in the same week as your access review. Record the result each time, including “no change”, because a run of dated results is itself the evidence that the control is monitored.
Two habits make the difference. Record the number rather than a tick, so you can see a trend rather than a state. And set a tolerance in advance for each check, for example “MFA coverage below 100 per cent is investigated the same day”, so that a finding produces an action rather than a discussion about whether it matters.
Where a platform earns its place
The reason this is usually automated is not that the checks are hard but that they are repetitive, and repetitive manual work is the first thing dropped when a quarter gets busy. Apexward Assure runs continuous checks against the tools you already have connected, such as Microsoft 365, GitHub, GitLab and Xero, records each result as dated evidence mapped to the controls it supports, and tracks expiry so that certificates and reviews surface before they lapse. That turns the checklist above from something you remember to do into something you respond to. The platform is free, so seeing what your own drift looks like through the monitoring module costs nothing but the time to connect a tenant.