The distance between a documented control and an operated one is where most certified organisations actually sit. Not because anyone cut corners, but because the certification process was never designed to measure the third state.
A control has three states
Take something concrete: privileged access review.
Documented. A policy says privileged accounts are reviewed quarterly. It names an owner, sets a frequency, defines what counts as privileged. The document is version-controlled and approved.
Verified. Someone produces the last four quarterly review records. An auditor reads them, confirms they exist, checks the dates line up with the stated frequency, and samples a few entries against the directory.
Operated. Privileged accounts are enumerated continuously. When an account gains admin rights outside the change process, something detects it within hours and a named person receives it, triages it, and either approves or revokes. The quarterly review is a summary of a process that was already running, not the process itself.
The three states describe the same control. Only the third one reduces risk between reviews.
What a certification audit actually tests
ISO 27001 certification runs in two stages. Stage 1 reviews the management system documentation: scope, policy, risk assessment, the Statement of Applicability produced under clause 6.1.3. Stage 2 audits implementation: the auditor looks for evidence that the ISMS is functioning and that selected controls are in place. Certification is followed by annual surveillance audits and full recertification on a three-year cycle.
That structure is sound, and it is also sampled. An auditor examines a subset of controls against a subset of evidence on a small number of days. Annex A of ISO 27001:2022 contains 93 controls across four themes: organisational, people, physical and technological. An audit does not test all 93 exhaustively every year. It cannot, and it does not claim to.
SOC 2 is more explicit about the distinction. A Type I report addresses the design of controls at a point in time. A Type II report addresses operating effectiveness across a defined period. The two are not interchangeable, and a customer asking for SOC 2 and receiving a Type I has usually not received what they asked for.
ENS works on a two-year rhythm: certificates carry two years of validity, with an ordinary audit at least every two years and an extraordinary audit where the system changes substantially.
None of these mechanisms is weak. They are periodic by design. Periodic assurance and continuous operation are simply different things, and conflating them is what produces certified organisations that cannot answer a technical question about last Tuesday.
Why documentation drifts
Evidence describes the organisation on the day it was collected.
A screenshot of a firewall rule set proves what the rules were that morning. An access review record proves who held privileges that quarter. A training completion export proves who had completed a module by that date. All valid, all accurate, and all decaying from the moment they are filed.
Meanwhile the organisation moves. New repositories appear. A cloud account is spun up for a project and never decommissioned. Someone leaves and their SaaS access outlives their laptop. A dependency picks up a vulnerability. The staff who wrote the procedure rotate out, and their replacements follow a version that lives in someone's head.
By the next audit, the distance between the documented control and the operating reality has grown for a year. The audit finds some of it. The parts it does not find are not resolved: they are simply not yet observed.
This is the failure mode that a folder of policies cannot address, however well written. Documents record intent. They do not detect drift.
The questions a technical review asks
The practical consequence shows up in enterprise procurement, because the people reviewing you are increasingly not satisfied by the certificate alone.
A security questionnaire or a customer technical review tends to ask things like:
- How long between a critical vulnerability being published and it being patched across your estate?
- Who receives an alert at 02:00 on a Sunday, and what happens next?
- When did you last test your incident response, and what did it find?
- What is currently exposed on your external perimeter?
- Show me the last three security incidents and how each was closed.
A certificate answers none of these. It attests that a management system exists and was found conforming when sampled. The questions above ask what the organisation does, continuously, and who is accountable when it does not.
An organisation in the documented state answers with policy extracts. An organisation in the operated state answers with dates, durations and names.
What closing the gap costs
Here the arithmetic is worth doing properly, because the comparison is often framed wrongly.
A compliance platform closes the first state well and part of the second. It centralises policy, maps controls to frameworks, holds evidence, and automates some collection. That is real value and it is not in dispute.
What it does not do is operate. To reach the third state, the same organisation still needs detection and response on endpoints and servers, log collection and correlation, someone monitoring outside working hours, external attack surface visibility, cloud configuration assessment, application and dependency scanning, periodic penetration testing with a defined scope, and a security lead who owns the whole thing and can stand in front of an auditor or a customer.
The honest cost comparison is therefore not one licence against another licence. It is one licence against the full assembled stack: compliance platform, plus SIEM, plus EDR, plus scanning, plus pentest engagements, plus fractional security leadership, plus the internal hours to run and integrate all of it. Priced that way, consolidation usually wins, and the comparison stops being about software at all.
The question to put to any provider is simply which of the three states they cover, and to be sceptical of an answer that does not distinguish between them.
A certificate is worth having. It is evidence that a management system exists and has been examined by someone independent. It is not evidence that anything is watching today. Those are separate claims, and buyers have started asking for the second one.
See which of the three states your programme actually reaches.








