Services / Continuous Operations
Compliance Scanning & Monitoring
Your certified controls, re-tested continuously.
The problem
You passed the audit in March. It is now October, and you have added two cloud accounts, six SaaS tools and eleven engineers. Nobody knows whether the controls you were certified on are still operating. You will find out in March.
The method.
Instrument the certified control set
Take the Statement of Applicability and the SOC 2 control matrix as the definitive list, and determine for each control whether it can be tested automatically, tested with evidence collection, or only attested. Most control sets are largely automatable. The point is to know which is which, and to stop pretending an attested control is a monitored one.
Run technical checks against the environment
Cloud configuration assessment across every account, subscription and region against a hardened security baseline; identity configuration (MFA enforcement, conditional access, privileged role assignment, key age); encryption at rest and in transit; logging enabled and retained; backup job success; endpoint agent coverage. Checks run on a schedule, and every result is retained with a timestamp.
Collect the evidence artifacts automatically
The screenshots, exports and reports that the auditor will ask for are captured as the control runs, dated and filed against the control reference. This removes the two-week evidence scramble that precedes every audit, and it produces evidence of operation over time, which is what a Type II opinion requires.
Alert on regression, not on state
A permanent list of 400 findings is noise. What matters is change: a control that was passing and is now failing, a new account created outside the baseline, a bucket that became public this week, an MFA policy that was relaxed. Regression is what gets reported, with the diff.
Report to the standard, not to the tool
Findings are expressed in the language of the framework (Annex A control, TSC criterion, GDPR article), so the report goes straight to the auditor, the customer or the board without translation.
What is continuous compliance monitoring?
Continuous compliance monitoring is the ongoing automated testing of the controls an organisation has been certified against, together with automatic collection of the evidence those controls produce. Instead of confirming once a year that MFA is enforced, logging is retained and cloud configuration meets the security baseline, the checks run continuously and any regression is reported when it occurs.
Can compliance monitoring replace an audit?
No. Certification requires an accredited certification body or a CPA firm; no monitoring platform can issue a certificate. What continuous monitoring changes is the state the auditor finds: controls that have demonstrably operated throughout the period, with dated evidence already collected, instead of a fortnight of scrambling to reconstruct them.
What percentage of security controls can be monitored automatically?
Technical controls (encryption, MFA enforcement, logging, cloud configuration, backup success, agent coverage) are largely automatable. Organisational controls (management review, risk acceptance, supplier assessment, awareness training) are evidenced rather than scanned, and process controls such as access reviews and change approval sit in between: their execution can be verified from the systems of record even though the judgement inside them is human.