Monitoring
Continuous monitoring: spotting changes before the annual review begins
Continuous monitoring combines contractual information, performance data, security events, evidence and internal changes.
8 minute read · Content as of 21.07.2026
Monitoring is more than an external cyber score
External ratings can provide signals, but they see neither the contractual scope nor internal dependencies. Reliable monitoring connects objective signals with committed evidence, SLA trends, incidents and changes to the service.
Triggers beat rigid calendars
A change of ownership, new subcontractors, a relocation, a substantial architecture change, repeated SLA breaches or a severe incident should trigger an unscheduled reassessment.
- evidence with expiry date and owner
- risk triggers and escalation thresholds
- open measures and exceptions
- an annual overall decision per critical relationship
Sources used
- Directive (EU) 2022/2555 – NIS2 · EU · 2022
- ISO/IEC 27036-2:2022 – Requirements · ISO · 2022
- Vendor, due diligence and exit patterns · KaitoSec