Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Recertification Gap
Governance, Ownership & Risk

Recertification Gap

← Back to Glossary
By NHI Mgmt Group Updated October 7, 2026 Domain: Governance, Ownership & Risk

The period between scheduled access reviews during which entitlements can change without fresh governance validation. In practice, this gap is where least privilege weakens, because the review may not occur until long after the risk event that altered the access.

What the recertification gap is

The recertification gap is the time between access review cycles, when entitlements can change and remain unvalidated until the next scheduled certification. It is not a failure of review itself, but a governance window where access can drift away from least privilege.

This gap matters because approvals, role changes, emergency access, and inherited entitlements can accumulate after the last review. If nothing else changes, the organisation may still believe access is current even though the underlying privilege set has already moved.

In practice, the gap is most visible in environments with long review cadences, broad role assignments, or high rates of mover activity. The longer the interval, the more opportunity there is for stale access, privilege creep, and unreviewed exceptions to persist.

Why the gap appears in access governance

Recertification is periodic by design, so the gap emerges whenever governance is event-based in reality but review-based on paper. A change in job function, project scope, vendor relationship, or service ownership may happen immediately, while the next certification is weeks or months away.

That mismatch is why the gap is best understood as a timing problem in entitlement governance. It reflects the difference between when access changes and when those changes are formally revalidated, which is why access reviews and certification need context and closure, not just a completed checklist.

The same issue often appears in broader identity programmes where lifecycle events are not tightly coupled to review cycles. A stronger access governance model reduces the gap by connecting provisioning, mover handling, and review evidence into one control loop, as described in IAM and IGA Basics.

What changes during the gap

During the gap, entitlements can become outdated without anyone noticing immediately. A user may retain access after changing teams, a contractor may keep permissions after the engagement shifts, or a workload may continue holding permissions long after its original purpose has changed.

The security consequence is not limited to excess rights. The gap can also conceal ownership ambiguity, delayed deprovisioning, and access that is technically valid but no longer justified by current business need.

That is why lifecycle controls matter. When access review is too far removed from the event that changed the entitlement, governance becomes reactive, and the review may only confirm that a problem has already existed for some time. Joiner-Mover-Leaver processes help shrink that window by tying entitlement changes to identity lifecycle events instead of waiting for the next cycle.

How practitioners should interpret the term

Recertification gap is a useful term because it shifts attention from whether reviews exist to whether they are timely enough to preserve control effectiveness. The practical question is not only “Are we reviewing access?” but also “How long can risky access remain in place before governance sees it?”

For that reason, the gap should be read as a control quality signal. If the interval is long, if reviews are shallow, or if remediation happens slowly, the organisation may have a certification process that exists but does not meaningfully constrain privilege drift.

It is also a reminder that review cadence alone is not evidence of strong governance. The value of certification depends on how much can change before the next review, and how quickly unapproved access is removed once identified.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementRecertification gap arises between account/access reviews and entitlement lifecycle changes.
AC-6 — Least PrivilegeThe gap allows access to persist beyond current need, weakening least privilege.
IA-5 — Authenticator ManagementEntitlements often depend on credential and secret lifecycle during review gaps.
Recommendation — Shorten review intervals and tie AC-2 reviews to access changes that create drift. Use AC-6 to minimize standing access and limit how much can drift between reviews. Apply IA-5 to ensure credentials tied to access are rotated or revoked when ownership changes.
ISO/IEC 27001:2022A.5.18 — Access rightsAccess rights governance depends on timely review, renewal and removal of entitlements.
Recommendation — Review access rights often enough to remove stale privileges before the next certification cycle.
CIS Controls v8CIS-6 — Access Control ManagementCIS access governance emphasizes account review and prompt removal of unnecessary access.
Recommendation — Use CIS-6 to keep access reviews and remediation close enough to prevent drift.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org