Join our Newsletter — 33% off our NHI Course

Recurring Certification

Recurring certification is the repeated review and validation of user access against current business justification. In mature governance programmes it is used to confirm whether access is still needed, but it only works when the entitlement data being reviewed is current and complete.

What Recurring Certification Actually Does

Recurring certification is a governance checkpoint, not a one-time approval. It repeatedly asks whether access is still justified against current business need, which helps expose stale access, role drift, and approvals that were valid at grant time but no longer fit the job.

Its value depends on the quality of the entitlement inventory being reviewed. If access data is incomplete, delayed, or poorly attributed to owners and applications, the certification result can look authoritative while still missing the access that matters most.

How Recurring Certification Fits Access Governance

In mature programmes, recurring certification sits inside the wider access governance cycle alongside provisioning, role management, and removal of access. It is the review step that confirms whether an existing entitlement should remain in place, be reduced, or be removed because the justification has changed.

That makes it more than a compliance exercise. A good certification process reflects how the business actually uses access, who can attest to it, and whether the review process can be completed with enough context to make a defensible decision.

Where organisations run it well, recurring certification becomes part of a living governance model rather than a periodic audit event. NHIMG’s IAM and IGA Basics is a useful foundation for understanding how certification relates to entitlement governance, and the IGA Buyer’s Guide shows how platform capabilities support access review workflows.

Why Recurring Certification Needs Good Data and Clear Ownership

Certification only works when reviewers can trust what they are seeing. If identities, roles, entitlements, and application ownership are not current, reviewers may approve access that should have been removed or reject access they do not fully understand.

Ownership matters because access decisions are human decisions. Business managers, application owners, and delegated reviewers need enough context to judge whether the entitlement still matches the user’s function, sensitivity of the system, and segregation requirements.

At scale, recurring certification also depends on lifecycle hygiene. NHIMG’s Access Reviews and Certification Guide explains why reviewers need context and closure, while the Joiner-Mover-Leaver (JML) Guide shows why provisioning and deprovisioning processes must keep pace with role changes so certification is not forced to compensate for weak upstream controls.

What Good Certification Programs Usually Test

A useful certification programme checks whether access remains justified, but it also tests whether the access model itself is healthy. If the review repeatedly uncovers excessive privileges, unclear role ownership, or shared entitlements that no one can confidently attest to, the issue is not just review quality, it is the underlying access design.

Recurring certification also helps expose control patterns that are difficult to spot elsewhere, such as role creep, dormant access, and approvals that survive organisational changes. The best programmes use the review to drive cleanup, not to create a record of repeated inaction.

That is why recurring certification connects naturally to role design, separation of duties, and entitlement governance. NHIMG’s Role Mining and Role Design Guide helps with role structure, and the Segregation of Duties (SoD) Guide explains why some access must be challenged even when it appears operationally convenient.

Risk and Threat Considerations

Recurring certification reduces exposure only when it is accurate and acted on. If reviews are stale, poorly scoped, or repeatedly rubber-stamped, excessive access can persist long enough to become a practical avenue for misuse, lateral movement, or privilege abuse.

Failure mechanism: Incomplete entitlement data, weak reviewer context, and review fatigue can turn certification into a formal exercise that misses the access most likely to create harm. Access that should have been removed remains available, and the organisation gets a false sense of control.

Impact: The result can be lingering overprivilege, higher blast radius after compromise, weaker audit defensibility, and a greater chance that sensitive systems remain reachable by people who no longer need them.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management Recurring certification supports ongoing review of account access and justification.
AC-6 — Least Privilege Certification is used to reduce retained access to the minimum needed for the task.
IA-5 — Authenticator Management Certification depends on current, well-governed access material and lifecycle hygiene.
Recommendation — Review account access periodically and remove access that no longer has a current business need. Use access reviews to remove excess privileges and keep access aligned to least privilege. Govern credential and access material so reviews are based on current, trustworthy access state.
CIS Controls v8 CIS-5 — Account Management Recurring certification is a periodic account and entitlement validation practice.
Recommendation — Implement periodic account review and revoke access that is no longer justified.
ISO/IEC 27001:2022 A.5.18 — Access rights The term directly concerns the review and control of access rights over time.
Recommendation — Regularly review access rights and remove entitlements that are no longer needed.

Practitioner Guidance

Why practitioners should care: Recurring certification is only as strong as the entitlement data, ownership model, and reviewer context behind it. If any of those are weak, the process will tend to preserve access rather than correct it.

Practitioners should treat certification results as an operational signal, not an endpoint. Repeated removals in the same application, role, or business unit usually indicate either access sprawl or a design problem in the underlying role and entitlement model.

Practitioner takeaway: The most reliable certification programmes close the loop, so rejected or removed access actually disappears rather than reappearing in the next review cycle.