Point-in-time → continuous

The certificate says green. Reality drifted.

Existing systems arrive with patchy documentation. Digitise it into OSCAL, evidence it continuously, and the authorised posture keeps tracking reality instead of a signing-day snapshot. Drive the maturity journey and watch a static ATO drift while a continuous one stays bounded.

Drive the model

Maturity phase 3 · Continuous

Raising the phase digitises existing docs into OSCAL: grey controls become continuously evidenced.

Authorisation mode Point-in-time

A point-in-time ATO signs once. Continuous re-verifies on a cadence.

130
signing day1 year on
30 days
dailyquarterly

How often OSCAL assessment results re-verify controls.

Controls evidenced 47 / 48 machine-readable in OSCAL
Authorised posture 98% what the certificate asserts
Actual posture 46% what is really passing now
Gap (unmanaged) 52% risk the certificate hides
Since evidence refreshed 130 days last re-verification
Cadence Once, at signing re-verification rhythm

Control register

47 / 48 evidenced
Undocumented Evidenced Ageing Drifted

What this shows. Each cell is a control. Grey ones have no machine-readable evidence yet. Raise the phase and existing docs digitise into OSCAL, turning grey to teal. Then time ages them: teal to amber to red.

Authorised vs actual posture

gap 52%
Authorised posture Actual posture Unmanaged gap

What this shows. In a point-in-time ATO the authorised line stays flat at the signing-day value while reality decays: the red gap grows unbounded. In continuous mode each refresh re-verifies the aged controls, so the gap resets and stays bounded by one interval's drift.

Illustrative. Synthetic data. Concept model, not a live system. The control ordering and drift thresholds are a fixed seeded array, so the picture is identical on every load.