Reassessment cadence is the schedule on which a previously approved vendor is reviewed again. It matters because vendor risk changes as contracts, controls, data scope, and business dependency change, and a static assessment cannot show whether the original decision still holds.
What reassessment cadence means in vendor risk
Reassessment cadence is the rhythm of vendor re-review after initial approval. Its purpose is to keep the risk decision current as the vendor’s controls, data access, service scope, subcontractors, and operational dependence evolve.
Why cadence matters more than a one-time approval
A vendor can be acceptable at onboarding and later become misaligned with policy if the relationship changes. The cadence should reflect the vendor’s risk tier, the sensitivity of the data or systems involved, and how quickly the vendor’s environment or services tend to change.
In practice, shorter intervals are usually warranted when a vendor supports critical services, handles regulated or sensitive data, or has broad connectivity into internal systems. Longer intervals can be reasonable for low-risk providers, but only when the original assumptions remain stable and the business can tolerate slower detection of drift.
What a reassessment should review
A useful reassessment looks beyond the original questionnaire and asks whether the prior approval still holds. Common review points include material contract changes, scope creep, security control changes, incident history, access path changes, evidence of remediation, and whether the vendor’s own subcontractors or hosting model have changed.
Because reassessment is about continuity of assurance, it should include the factors most likely to change the answer over time. That often means reviewing NIST Cybersecurity Framework 2.0 for governance and risk review structure, and, where technical controls are central, NIST SP 800-53 Rev 5 Security and Privacy Controls for access control, audit, and configuration expectations.
How cadence supports ongoing vendor governance
Reassessment cadence is a governance control, not a paperwork exercise. It gives the organisation a formal checkpoint for confirming owner accountability, deciding whether risk acceptance still makes sense, and identifying when a vendor should move to a more frequent review cycle.
It is also a practical way to avoid stale approvals. If the cadence is too slow, organisations may miss control drift and business dependency creep; if it is too aggressive, teams can drown in reviews that add little decision value. The right schedule is the one that tracks change rate and consequence.
For broader control mapping, NIST Cybersecurity Framework 2.0 supports governance and risk review, while NIST SP 800-53 Rev 5 Security and Privacy Controls helps translate cadence into reviewable control expectations.
Risk and Threat Considerations
Reassessment cadence creates risk when it is too slow to catch meaningful vendor change. A vendor may accumulate new access, shift infrastructure, add subcontractors, or suffer an incident long before the next review, leaving the original approval outdated.
Failure mechanism: Approval drift develops when the business continues relying on an old risk assessment after the vendor’s controls, access, or dependencies have materially changed.
Impact: The organisation can retain an unacceptable vendor longer than intended, increasing exposure to service disruption, data loss, compliance failure, and trusted-path abuse.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Reassessment cadence operationalizes recurring vendor risk review. |
| GV.OV-01 — Oversight of Risk Management | Cadence is an oversight mechanism for checking whether prior approvals still hold. | |
| Recommendation — Align vendor review intervals to risk strategy and change rate. Use recurring oversight to confirm vendor risk decisions remain valid. | ||
| NIST SP 800-53 Rev 5 | CA-7 — Continuous Monitoring | Vendor reassessment is a periodic monitoring activity over time. |
| SA-9 — External System Services | Vendor cadence governs continued trust in externally provided services. | |
| Recommendation — Monitor supplier security posture on a recurring schedule. Review external service providers at intervals matched to service criticality. | ||
| ISO/IEC 27001:2022 | A.5.19 — Information security in supplier relationships | Supplier relationships require ongoing security review, not one-time approval. |
| Recommendation — Review supplier security terms and evidence throughout the relationship. | ||
Practitioner Guidance
Why practitioners should care: Set cadence by change rate and consequence, not by calendar habit. High-impact vendors should be reviewed often enough that the organisation can detect material drift before it becomes an accepted dependency.
Common misunderstanding: A scheduled reassessment is only useful if it is tied to decision-making. If no one can act on what changed, the review becomes a ritual rather than a control.
Practitioner takeaway: Reassessment cadence should answer one question clearly, namely whether the vendor is still acceptable under the assumptions that justified approval in the first place.
Related resources from NHI Mgmt Group
- When should a vendor risk policy trigger reassessment?
- What do organisations get wrong about update cadence in an AI hacking environment?
- How do teams know whether a change is significant enough to trigger reassessment?
- How should security teams validate applications when release cadence is continuous?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org