Point-in-time → continuous
Existing systems arrive with patchy documentation. Digitise it into OSCAL, evidence it continuously, and the authorised posture keeps tracking reality instead of a signing-day snapshot. Drive the maturity journey and watch a static ATO drift while a continuous one stays bounded.
Drive the model
Raising the phase digitises existing docs into OSCAL: grey controls become continuously evidenced.
A point-in-time ATO signs once. Continuous re-verifies on a cadence.
How often OSCAL assessment results re-verify controls.
What this shows. Each cell is a control. Grey ones have no machine-readable evidence yet. Raise the phase and existing docs digitise into OSCAL, turning grey to teal. Then time ages them: teal to amber to red.
What this shows. In a point-in-time ATO the authorised line stays flat at the signing-day value while reality decays: the red gap grows unbounded. In continuous mode each refresh re-verifies the aged controls, so the gap resets and stays bounded by one interval's drift.
Illustrative. Synthetic data. Concept model, not a live system. The control ordering and drift thresholds are a fixed seeded array, so the picture is identical on every load.