Skip to content
Secantra
ArticleDORANIS2ISO 27001EvidenceRecencyControlsPostureAudit

Evidence recency: why "twelve months" is not a rule, and what to measure instead

4 min read · Published 26 Aug 2026 · Secantra editorial

The rule everybody quotes

“Evidence must be less than twelve months old.” It is on checklists, in audit prep guides, in the tribal knowledge of every compliance team. It is also not written anywhere in DORA, NIS2 or ISO/IEC 27001. What the frameworks ask for is that controls operate — continually, effectively, and demonstrably — and that the organisation reviews its measures on a defined cadence. Twelve months is a folk convention derived from the annual audit cycle, and it fails in both directions.

A penetration-test report from ten months ago is fresh by the folk rule and stale for a system that has shipped forty releases since. A board approval of the ICT risk framework from fourteen months ago is stale by the folk rule and perfectly valid if the framework has not changed and the review is scheduled. Recency is not a property of the evidence; it is a relationship between the evidence, the control it supports and how fast that control’s world changes.

Auditors do not ask how old the file is. They ask whether it still shows the control operating. Those are different questions with different clocks.

Three clocks, not one

Look at what actually determines whether a piece of evidence still proves anything:

  1. The control’s own review period. Access reviews quarterly, restore tests semi-annually, policy approvals annually, penetration tests per release cycle or yearly. Each control has a cadence that follows from what it protects; the evidence is stale when it is older than that cadence, not older than a calendar year.
  2. Change in what the control protects. A control on a system that changed materially — new provider, new architecture, new data — needs fresh evidence regardless of the calendar. Recency has an event trigger, not just a timer.
  3. The framework’s own cadence. DORA expects the ICT risk framework reviewed at least yearly and after major incidents; NIS2 expects effectiveness assessed on a defined cadence; ISO 27001 expects internal audit and management review at planned intervals. Those are ceilings for the whole system, not the rule for each file.

The twelve-month rule collapses three clocks into one and gets each of them wrong for a different reason.

What to measure

The measurable quantity is simple once the records exist: for each control, the date of the newest evidence linked to it, compared with the control’s review period. Not the age of each file — the newest date per control. A control with a two-year-old policy and a two-week-old test report is current for the test and stale for the policy only if the policy has its own review period; a control with no dated evidence at all is not “stale”, it is uncovered, which is a different finding.

That yields three honest states per control:

  • Current — newest evidence is inside the control’s review period.
  • Stale — newest evidence is older than the review period; the control may still operate, but nobody has shown it recently.
  • No dated evidence — a coverage gap, reported as such, never counted as stale (you cannot measure the age of nothing).

And a posture number that decays on its own: if a control’s evidence ages past its period, the control drops from “current” without anyone editing a status. That is the property a supervisor is actually looking for — a number that goes down when the work stops.

Practical consequences

  • Set the review period on the control, not on the evidence. Evidence inherits it. Otherwise every file needs its own expiry and nobody maintains that.
  • Date the evidence by when it was collected, not when it was uploaded. A report produced in March and uploaded in June is March evidence.
  • Let events reset the clock. Material change on the protected asset — new provider, new version, incident — should surface the control for re-evidence even inside its period.
  • Report the three states, not a percentage. “14 controls stale, 3 uncovered” tells the team what to do; “82 % current” tells them nothing about which 18 %.

In Secantra

Evidence records carry a collection date and link to controls, requirements, assets, assessments and findings; a control’s newest evidence date is measured per control and revalidated on the compliance operations cadence, and a control that has aged past its period is flagged as stale — a control with no dated evidence is reported as uncovered, never as stale. Review periods live on the control (and on governance documents), not on individual files. There is no field for “evidence age limit: 12 months” because there is no such rule.

Checklist

  • Every control has its own review period; evidence inherits it
  • Evidence is dated by collection, and “newest per control” is the number that matters
  • Three states are reported — current, stale, no dated evidence — never a single percentage
  • Material change on a protected asset triggers re-evidence inside the period
  • The twelve-month rule is retired in favour of the control’s cadence

Related