Continuous Compliance
Evidence that expires, findings that close, runs that diff.
Compliance here is a loop, not an audit-week scramble. Every artifact carries a capture signature and a policy expiry; every finding carries a due date measured against the next audit line; every run is diffable against the last.
82
Artifacts under policy
3
Stale
4
Due ≤30d
4
Findings in flight
Audit window closes
2026-09-30
Evidence freshness ledger
18 artifacts · 3 stale · 4 due · 11 fresh · as of 2026-08-05
| Status | Control | Program | Artifact | Type | Captured | Expires | Action |
|---|---|---|---|---|---|---|---|
| Stale · out of policy03 | |||||||
| Stale | 10.4.2 | PCI DSS v4.0.1 | Log review sign-off queue | Screenshot | 2026-04-18 9f41c2ea…7b03 · signed | 2026-07-17 Policy 90d | |
| Stale | CC6.8 | SOC 2 | Endpoint malware policy (MDM export) | Config export | 2026-01-22 c58a10df…3e92 · signed | 2026-07-21 Policy 180d | |
| Stale | 02.e | HITRUST CSF v11.8.0 | Security awareness completion roster | Screenshot | 2026-04-29 1de7b449…a05c · signed | 2026-07-28 Policy 90d | |
| Due · ≤30 days to expiry04 | |||||||
| Due ≤30d | CC7.2 | SOC 2 | SIEM alert routing verification | API transcript | 2026-05-14 74b0e91c…5fd8 · signed | 2026-08-12 Policy 90d | |
| Due ≤30d | EDE-3.4 | CMS EDE | Consumer consent capture UI | Screenshot | 2026-05-19 e2c69d05…8b17 · signed | 2026-08-17 Policy 90d | |
| Due ≤30d | 8.3.1 | PCI DSS v4.0.1 | MFA enforcement (identity provider) | API transcript | 2026-05-26 b8d3f172…4a60 · signed | 2026-08-24 Policy 90d | |
| Due ≤30d | 09.m | HITRUST CSF v11.8.0 | TLS policy, edge listeners | Config export | 2026-03-05 07aa54be…d9c3 · signed | 2026-09-01 Policy 180d | |
Finding lifecycle
6 findings this period · due dates measured against 2026-09-30
| Finding | Severity | Control | Summary | Discovered → due → remediated | Owner | State |
|---|---|---|---|---|---|---|
| FND-2026-0117 | high | 10.4.2 PCI DSS v4.0.1 | Daily log review sign-offs lapsed for two batch systems | 2026-06-12 → 2026-07-28 past due · 2026-09-30 line at risk | R.O. | Open |
| FND-2026-0125 | high | 02.e HITRUST CSF v11.8.0 | Awareness training completion below 95% threshold | 2026-07-02 → 2026-08-15 | M.T. | Remediating |
| FND-2026-0121 | medium | CC6.8 SOC 2 | MDM malware policy export older than policy window | 2026-06-24 → 2026-08-22 | D.K. | Remediating |
| FND-2026-0131 | low | 12.10.5 PCI DSS v4.0.1 | Tabletop exercise minutes missing counsel attendee | 2026-07-21 → 2026-09-12 | D.K. | Open |
| FND-2026-0109 | medium | CC7.2 SOC 2 | SIEM alert routing gap for staging VPC | 2026-05-20 → 2026-07-10 → 2026-07-07 | A.S. | Verified |
| FND-2026-0102 | low | EDE-1.7 CMS EDE | Legacy report store pending KMS migration | 2026-05-06 → 2026-09-30 | R.O. | Risk accepted |
Run-over-run diff
SOC 2 Type II — continuous evidence plan · CEP-SOC2-Q2
Run A
RUN-2026-0419
2026-05-02 · 52 artifacts · 5m 12s
sha256:7d3fa8c1…4b90 · key 2550ba9a7e29c0d3
SEALED7d3fa8c1 · 2026-05-02
Run B · 90 days later
RUN-2026-0644
2026-07-31 · 54 artifacts · 4m 57s
sha256:e91b06d4…8a27 · key 2550ba9a7e29c0d3
SEALEDe91b06d4 · 2026-07-31
The diff between two signed packages is itself evidence.
@@ RUN-2026-0419 → RUN-2026-0644 · 54 artifacts compared @@
49 artifacts unchanged — hashes equal across both signed packages
CC6.1 · IAM password + session policy · Config export
0b4d92e7…c1535c1e8fa7…2d44✓ signed both runs
drift: Session timeout tightened 30m → 15m; lockout threshold unchanged
CC7.2 · SIEM alert routing verification · API transcript
88c31f6a…be0774b0e91c…5fd8✓ signed both runs
drift: Staging VPC alerts now route to on-call; rule count 41 → 43
CC6.7 · Data egress TLS configuration · Config export
d7a5401e…9f622e80cb5f…a714✓ signed both runs
drift: Minimum protocol raised TLS 1.2 → 1.3 on two external listeners
CC8.1 · Change advisory approval board · Screenshot
—aa92d631…0f7efirst captured 2026-07-29✓ signed at capture
A1.2 · Backup restore verification run · API transcript
—3fb7c025…e18afirst captured 2026-07-22✓ signed at capture