Continuous Compliance

Evidence that expires, findings that close, runs that diff.

Compliance here is a loop, not an audit-week scramble. Every artifact carries a capture signature and a policy expiry; every finding carries a due date measured against the next audit line; every run is diffable against the last.

82
Artifacts under policy
3
Stale
4
Due ≤30d
4
Findings in flight
Audit window closes
2026-09-30

Evidence freshness ledger

18 artifacts · 3 stale · 4 due · 11 fresh · as of 2026-08-05
StatusControlProgramArtifactTypeCapturedExpiresAction
Stale · out of policy03
Stale10.4.2PCI DSS v4.0.1Log review sign-off queueScreenshot
2026-04-18
9f41c2ea…7b03 · signed
2026-07-17
Policy 90d
StaleCC6.8SOC 2Endpoint malware policy (MDM export)Config export
2026-01-22
c58a10df…3e92 · signed
2026-07-21
Policy 180d
Stale02.eHITRUST CSF v11.8.0Security awareness completion rosterScreenshot
2026-04-29
1de7b449…a05c · signed
2026-07-28
Policy 90d
Due · ≤30 days to expiry04
Due ≤30dCC7.2SOC 2SIEM alert routing verificationAPI transcript
2026-05-14
74b0e91c…5fd8 · signed
2026-08-12
Policy 90d
Due ≤30dEDE-3.4CMS EDEConsumer consent capture UIScreenshot
2026-05-19
e2c69d05…8b17 · signed
2026-08-17
Policy 90d
Due ≤30d8.3.1PCI DSS v4.0.1MFA enforcement (identity provider)API transcript
2026-05-26
b8d3f172…4a60 · signed
2026-08-24
Policy 90d
Due ≤30d09.mHITRUST CSF v11.8.0TLS policy, edge listenersConfig export
2026-03-05
07aa54be…d9c3 · signed
2026-09-01
Policy 180d

Finding lifecycle

6 findings this period · due dates measured against 2026-09-30
FindingSeverityControlSummaryDiscovered → due → remediatedOwnerState
FND-2026-0117high
10.4.2
PCI DSS v4.0.1
Daily log review sign-offs lapsed for two batch systems
2026-06-12 2026-07-28
past due · 2026-09-30 line at risk
R.O.Open
FND-2026-0125high
02.e
HITRUST CSF v11.8.0
Awareness training completion below 95% threshold
2026-07-02 2026-08-15
M.T.Remediating
FND-2026-0121medium
CC6.8
SOC 2
MDM malware policy export older than policy window
2026-06-24 2026-08-22
D.K.Remediating
FND-2026-0131low
12.10.5
PCI DSS v4.0.1
Tabletop exercise minutes missing counsel attendee
2026-07-21 2026-09-12
D.K.Open
FND-2026-0109medium
CC7.2
SOC 2
SIEM alert routing gap for staging VPC
2026-05-20 2026-07-10 2026-07-07
A.S.Verified
FND-2026-0102low
EDE-1.7
CMS EDE
Legacy report store pending KMS migration
2026-05-06 2026-09-30
R.O.Risk accepted

Run-over-run diff

SOC 2 Type II — continuous evidence plan · CEP-SOC2-Q2
Run A
RUN-2026-0419
2026-05-02 · 52 artifacts · 5m 12s
sha256:7d3fa8c1…4b90 · key 2550ba9a7e29c0d3
Run B · 90 days later
RUN-2026-0644
2026-07-31 · 54 artifacts · 4m 57s
sha256:e91b06d4…8a27 · key 2550ba9a7e29c0d3
The diff between two signed packages is itself evidence.
@@ RUN-2026-0419RUN-2026-0644 · 54 artifacts compared @@
49 artifacts unchanged — hashes equal across both signed packages
CC6.1 · IAM password + session policy · Config export
0b4d92e7…c1535c1e8fa7…2d44✓ signed both runs
drift: Session timeout tightened 30m → 15m; lockout threshold unchanged
CC7.2 · SIEM alert routing verification · API transcript
88c31f6a…be0774b0e91c…5fd8✓ signed both runs
drift: Staging VPC alerts now route to on-call; rule count 41 → 43
CC6.7 · Data egress TLS configuration · Config export
d7a5401e…9f622e80cb5f…a714✓ signed both runs
drift: Minimum protocol raised TLS 1.2 → 1.3 on two external listeners
CC8.1 · Change advisory approval board · Screenshot
aa92d631…0f7efirst captured 2026-07-29✓ signed at capture
A1.2 · Backup restore verification run · API transcript
3fb7c025…e18afirst captured 2026-07-22✓ signed at capture
Exhibit · run-over-run drift · CEP-SOC2-Q2 · Ed25519-sealed packages