Comparing a security assessment with a continuing assurance service
A dated assessment and a continuing assurance service support different purchasing decisions. Compare the assessed subject, scope, corrective evidence and treatment of later product changes.
A security assessment report answers a question about a defined subject using evidence gathered within a particular scope. A continuing assurance service makes an additional promise: that someone will keep gathering relevant evidence as the product, its use and its dependencies change. Buyers should understand which of those offers they are purchasing.
The distinction matters to defence software companies selling products that evolve through frequent releases. A completed assessment can be valuable evidence for a customer, but the product offered today may differ from the version examined. The sales team needs an accurate explanation of what the report covers and how the supplier maintains confidence beyond that point.
Identify the assessed subject
The first purchasing question is the identity of the product, service or organisation assessed. These are different subjects. An assessment of a company's internal processes may contribute useful evidence about its development practices while leaving the customer with questions about a particular application release or deployment.
A report should allow the buyer to connect the assessed subject to the offer. That connection may involve a product version, a defined service boundary or an identified management process. A familiar assessment name cannot supply the missing relationship by itself.
NIST SP 800-53A revision 5 provides a methodology in which assessment methods include examining evidence, interviewing people and testing. It distinguishes depth, meaning the rigour and detail of the work, from coverage, meaning its breadth. The organisation selects an approach appropriate to its assurance needs. These distinctions help explain why two assessments carrying similar labels can support different conclusions.
The customer should therefore ask what was examined and what was excluded. A narrow assessment may be entirely appropriate for a specific purchase question. Its limitation becomes a problem when the commercial claim quietly expands beyond the work performed.
Read findings in their decision context
A report containing findings is not automatically evidence of a poor supplier. Identifying and addressing weaknesses can be part of a credible assurance process. Conversely, a report with few findings may reflect a narrow scope or limited evidence rather than a superior product.
The buyer needs to understand the significance of findings for the proposed use and their current status. A supplier may have completed corrective work, accepted a bounded limitation or scheduled a change. Those are different outcomes and should remain distinct in the customer-facing record.
The evidence supporting closure matters. A statement that an issue was assigned to engineering is different from a statement that a change was delivered and assessed. The report's original date and the date of later corrective evidence should both remain visible. Otherwise a buyer can mistake a recent cover note for a recent examination of the product.
This discussion can use a suitably redacted summary. Customers do not need unrestricted access to sensitive technical details to ask who reviewed the result, which release it concerns and what material limitations remain. The supplier should provide an authorised route for deeper questions where the purchase requires it.
Understand what continuing assurance adds
The NCSC's assurance guidance notes that many activities provide a snapshot and that confidence needs maintenance through the system lifecycle. Its model combines evidence about supplier development, independent evaluation, implementation and ongoing use. It specifically cautions that a formally assessed product still needs suitable implementation and continuing maintenance.
A continuing offer should therefore explain which changes prompt new work. A major release, a changed dependency or a new customer deployment model may affect the earlier evidence differently. The supplier should have a documented way to decide whether existing assessment results remain relevant and where further examination is needed.
The commercial deliverable is not necessarily a complete new assessment after every minor change. It can include a maintained scope record, an assessment of material changes and additional evidence where justified. The buyer needs to understand the promised process and its limits, rather than assume that “continuous assurance” means every part of the product is constantly examined.
A supplier should also identify what the customer receives. A recurring summary of relevant changes and assessment status may be more useful than access to a dashboard full of unqualified measurements. The information should help the customer decide whether its accepted use remains within the supported evidence boundary.
Compare a one-off engagement with a subscription
Consider a hypothetical supplier evaluating a scheduling application before entering a new customer segment. One offer provides an independent examination of the current release and a report. Another adds periodic review of material changes and a maintained customer evidence package. The second is broader, but its value depends on the product's expected rate of change and the customers' need for continuing evidence.
The company should compare the work included, not merely the assessment logo or annual fee. Does the continuing service include review of corrective actions? Does it cover several supported releases? Are customer-specific deployments included or separately scoped? A subscription can still leave important work outside its boundary.
The buyer should also identify who owns the resulting evidence and who may receive it. A report that cannot be shared with an authorised customer assessor may create additional procurement work. Access rights, retention and the process for answering follow-up questions are therefore part of the commercial value.
For a small vendor, a focused initial assessment followed by a clear internal maintenance process may be more appropriate than an expansive service it cannot use. The right choice depends on the actual product and customer decisions the evidence needs to support.
Keep deployment responsibility visible
Assessment evidence about a product does not automatically establish that every customer has implemented it appropriately. An application can rely on customer-managed access, hosting choices or external integrations. Those dependencies should be stated so the buyer can identify the work needed at adoption.
Our guide to cloud shared responsibilities examines how infrastructure, application and customer duties fit together. An assessment covering one participant should be used within that allocation. It should not erase the remaining responsibilities of the others.
The supplier can improve the handover by explaining the assumptions under which its evidence applies. If the customer changes a material part of the deployment, the parties should know whether a new assessment is needed and who arranges it. This is more useful than a generic condition saying that all customer changes are outside support.
Continuing assurance also depends on product-support information. A reported vulnerability, an unsupported dependency or a change in release status can alter the evidence available to a customer. Our guide to vulnerability-disclosure support describes the communication process needed to keep those developments connected to the purchased product.
Make the assurance claim reviewable
A strong commercial claim can be traced from the offer to an assessed subject, a scope, a dated body of evidence and a current statement of limitations. If the offer includes continuing work, that trace should extend to the process for reviewing change and communicating its consequences.
A buyer can evaluate the arrangement by following one completed finding and one subsequent product change through the available records. The purpose is to understand the supplier's evidence discipline, without commissioning an unnecessary new technical exercise during the sales process.
That approach lets a supplier describe assurance as a maintained product responsibility. It gives customers a basis for deciding which evidence they can reuse, which questions remain open and what continuing service is worth purchasing. The value rests in the scope and relevance of the evidence, together with the work that keeps it relevant.
Sources & evidence
- Assessing Security and Privacy Controls, SP 800-53A revision 5NIST
- How to gain and maintain assuranceUK National Cyber Security Centre · 23 June 2023
NIST methodology and NCSC lifecycle guidance are the primary references. The article does not grant certification or assess a named vendor; commercial comparisons are BDI analysis.
Suggest a correction