Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Compliance

Continuous compliance

Continuous compliance is the operating model in which an organization’s controls are verified against current evidence on a defined cadence throughout the year, across every framework it answers to, so that its compliance status is known at any moment rather than reconstructed before an audit. The controls are mapped once to the requirements of each framework (ISO 27001, NIS2, DORA, SOC 2), evidence is collected and reviewed as it is produced, and a control whose evidence has aged past its cadence is treated as a gap.

What the annual sprint costs

The traditional cycle collects evidence in the weeks before the audit, from screenshots and exports that describe the state of that week. The rest of the year is a blind spot: a control can fail in February and be discovered in November. The sprint also repeats for every framework, because each auditor asks for the same access-review evidence in a different form. Continuous compliance spreads the work across the year and does it once for all frameworks.

Map once, prove once

The mechanism is a single control set mapped to the requirements of every applicable framework: an access-review control satisfies an ISO 27001 Annex A control, a NIS2 risk-management measure and a SOC 2 criterion at the same time. Evidence is attached to the control, not to the framework, with a cadence, an owner and a review. Adding a framework then means mapping requirements to existing controls and writing only the missing ones, not rebuilding the program.

What the regulations changed

NIS2 requires policies to assess the effectiveness of cybersecurity risk-management measures; DORA requires financial entities to keep their ICT risk framework documented, reviewed and audited regularly. Both turn “compliant on the audit day” into an insufficient answer: the question becomes whether the organization can demonstrate that its measures operate at any date the supervisor picks. Continuous compliance is the operating model that can answer yes.

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.