The period between scheduled access reviews during which entitlements can change without fresh governance validation. In practice, this gap is where least privilege weakens, because the review may not occur until long after the risk event that altered the access.
What the recertification gap is
The recertification gap is the time between access review cycles, when entitlements can change and remain unvalidated until the next scheduled certification. It is not a failure of review itself, but a governance window where access can drift away from least privilege.
This gap matters because approvals, role changes, emergency access, and inherited entitlements can accumulate after the last review. If nothing else changes, the organisation may still believe access is current even though the underlying privilege set has already moved.
In practice, the gap is most visible in environments with long review cadences, broad role assignments, or high rates of mover activity. The longer the interval, the more opportunity there is for stale access, privilege creep, and unreviewed exceptions to persist.
Why the gap appears in access governance
Recertification is periodic by design, so the gap emerges whenever governance is event-based in reality but review-based on paper. A change in job function, project scope, vendor relationship, or service ownership may happen immediately, while the next certification is weeks or months away.
That mismatch is why the gap is best understood as a timing problem in entitlement governance. It reflects the difference between when access changes and when those changes are formally revalidated, which is why access reviews and certification need context and closure, not just a completed checklist.
The same issue often appears in broader identity programmes where lifecycle events are not tightly coupled to review cycles. A stronger access governance model reduces the gap by connecting provisioning, mover handling, and review evidence into one control loop, as described in IAM and IGA Basics.
What changes during the gap
During the gap, entitlements can become outdated without anyone noticing immediately. A user may retain access after changing teams, a contractor may keep permissions after the engagement shifts, or a workload may continue holding permissions long after its original purpose has changed.
The security consequence is not limited to excess rights. The gap can also conceal ownership ambiguity, delayed deprovisioning, and access that is technically valid but no longer justified by current business need.
That is why lifecycle controls matter. When access review is too far removed from the event that changed the entitlement, governance becomes reactive, and the review may only confirm that a problem has already existed for some time. Joiner-Mover-Leaver processes help shrink that window by tying entitlement changes to identity lifecycle events instead of waiting for the next cycle.
How practitioners should interpret the term
Recertification gap is a useful term because it shifts attention from whether reviews exist to whether they are timely enough to preserve control effectiveness. The practical question is not only “Are we reviewing access?” but also “How long can risky access remain in place before governance sees it?”
For that reason, the gap should be read as a control quality signal. If the interval is long, if reviews are shallow, or if remediation happens slowly, the organisation may have a certification process that exists but does not meaningfully constrain privilege drift.
It is also a reminder that review cadence alone is not evidence of strong governance. The value of certification depends on how much can change before the next review, and how quickly unapproved access is removed once identified.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Recertification gap arises between account/access reviews and entitlement lifecycle changes. |
| AC-6 — Least Privilege | The gap allows access to persist beyond current need, weakening least privilege. | |
| IA-5 — Authenticator Management | Entitlements often depend on credential and secret lifecycle during review gaps. | |
| Recommendation — Shorten review intervals and tie AC-2 reviews to access changes that create drift. Use AC-6 to minimize standing access and limit how much can drift between reviews. Apply IA-5 to ensure credentials tied to access are rotated or revoked when ownership changes. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Access rights governance depends on timely review, renewal and removal of entitlements. |
| Recommendation — Review access rights often enough to remove stale privileges before the next certification cycle. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | CIS access governance emphasizes account review and prompt removal of unnecessary access. |
| Recommendation — Use CIS-6 to keep access reviews and remediation close enough to prevent drift. | ||