What the annual sprint costs
The traditional cycle collects evidence in the weeks before the audit, from screenshots and exports that describe the state of that week. The rest of the year is a blind spot: a control can fail in February and be discovered in November. The sprint also repeats for every framework, because each auditor asks for the same access-review evidence in a different form. Continuous compliance spreads the work across the year and does it once for all frameworks.
Map once, prove once
The mechanism is a single control set mapped to the requirements of every applicable framework: an access-review control satisfies an ISO 27001 Annex A control, a NIS2 risk-management measure and a SOC 2 criterion at the same time. Evidence is attached to the control, not to the framework, with a cadence, an owner and a review. Adding a framework then means mapping requirements to existing controls and writing only the missing ones, not rebuilding the program.
What the regulations changed
NIS2 requires policies to assess the effectiveness of cybersecurity risk-management measures; DORA requires financial entities to keep their ICT risk framework documented, reviewed and audited regularly. Both turn “compliant on the audit day” into an insufficient answer: the question becomes whether the organization can demonstrate that its measures operate at any date the supervisor picks. Continuous compliance is the operating model that can answer yes.