Annual Assessment
An Annual Assessment is a recurring, at-least-yearly review of a system's security controls to confirm they are still in place and working as intended. It is a core part of keeping a system's security posture current over time rather than checking it only once at initial approval. The specific controls examined, who performs the review, and how the results are reported generally vary by the applicable framework, agency tailoring, and the current revision of the governing publication.
An Annual Assessment is a periodic security control assessment performed on a recurring basis (typically at least once every twelve months) as an element of ongoing authorization and continuous monitoring, generally intended to evaluate whether selected controls remain effective and correctly implemented following the initial assessment and authorization. In most implementations it covers a subset of controls selected on a defined cycle rather than a full reassessment of every control, with scope, assessor independence requirements, and reporting cadence determined by the governing framework and agency or program tailoring (for example, continuous monitoring programs for federal systems, or FedRAMP requirements for cloud service offerings). Practitioners should note that an Annual Assessment is distinct from authorization: it produces assessment findings that inform an authorizing official's ongoing risk decision, but it does not by itself grant or renew an Authority to Operate, which remains time-bound and contingent on continuous monitoring. Because impact levels, control baselines, and assessment requirements change across revisions and are subject to agency-specific interpretation, the reader should verify the exact frequency, control selection methodology, independence requirement, and reporting obligations against the current authoritative text applicable to their system. This entry does not address contractual, legal, or implementation specifics, and no specific control numbers, clause numbers, effective dates, or version identifiers are asserted here because no supporting evidence was provided.
Why it matters
An Annual Assessment addresses a fundamental weakness in point-in-time security review: a system that was secure at the moment of its initial authorization can drift out of compliance as configurations change, personnel turn over, new vulnerabilities emerge, and operational demands introduce workarounds. By requiring a recurring, at-least-yearly review of security controls, the practice keeps a system's documented security posture aligned with its actual state, and it feeds current evidence into an authorizing official's ongoing risk decisions rather than leaving those decisions anchored to conditions that may no longer hold.
Who it's relevant to
Inside Annual Assessment
Common questions
Answers to the questions practitioners most commonly ask about Annual Assessment.