DURHAM, NC, June 2, 2026 (GLOBE NEWSWIRE) — JupiterOnethe AI Risk Management Platform, today unveiled JupiterOne Continuous Controls Monitoring (CCM), a solution that helps security and compliance teams determine whether controls are working as intended across cloud, SaaS and hybrid environments. By testing controls against live asset data, CCM helps teams identify control deviations and track evidence before gaps become audit findings, customer concerns, or business risks.
Advances in compliance automation have made audit preparation faster, but many tools still can’t prove whether controls work in practice. As organizations grow, framework managers, control owners, and asset owners are often forced to merge evidence from multiple systems, manually review configurations, and manually verify that controls remain effective after implementation.
Continuous controls Monitoring is fast becoming the way security and compliance teams expect to work, moving from periodic attestations to real-time assurance about the effectiveness of controls. JupiterOne CCM enters this category with the architectural foundation it needs: a graphical data model that evaluates controls over asset, identity, and configuration relationships, with every test completely transparent: exact queries, integration source, and test logic visible to both security teams and auditors.
JupiterOne CCM replaces screenshots, spreadsheets, and point-in-time assessments with always-up-to-date control assessments that are based on live asset data, the actual state of the environment, and not its documentation. The solution helps teams see control performance, track supporting evidence, and respond when controls deviate from their intended state.
“Most organizations can demonstrate that policies exist. Far fewer can prove at any point that the controls behind those policies are actually working,” said Kevin Tonkin, Chief Product Officer at JupiterOne. “GRC tools are built to manage the compliance workflow. Security teams need something different: a way to prove that the technical controls behind every policy actually work, in environments that change by the hour. JupiterOne CCM brings a security lens to GRC.”
Built on JupiterOne’s graph platform and more than 200 integrations, JupiterOne CCM evaluates controls over relationships between assets, identities, cloud resources, SaaS applications, and security findings. With JupiterOne AI, teams can ask compliance questions in natural language and get answers about audit status, evidence, drift, and framework alignment in seconds. Early customer feedback reinforces a consistent need for faster, more defensible answers about the effectiveness of controls without spending weeks manually collecting evidence.
With JupiterOne CCM, teams can:
- Continuously evaluate controls: Test controls against live asset data and detect drift when it happens
- Evaluate the controls graphically: Test controls over asset relationships, identity, configuration, exposure, and policies, not just isolated API responses from each tool
- Ask questions with JupiterOne AI: Use natural language to get answers about audit status, evidence, drift, and compliance posture in seconds
- Provide audit-ready evidence: Generate and update evidence from current data sources, reducing manual collection and review cycles
- Map controls across frameworks: Define controls once and use evidence for SOC 2, ISO, NIST, FedRAMP, HIPAA and more.
The launch builds on JupiterOne’s launch of JupiterOne in May AI attack surface management (AI ASM) and JupiterOne Unified vulnerability management (UVM), which helps teams understand how assets, vulnerabilities, AI systems, and mission-critical resources connect to create risk. Together, AI ASM, UVM and CCM extend JupiterOne’s graph approach from attack surface and vulnerability context to effectiveness monitoring, allowing security and compliance teams to track risk and evidence in the same underlying asset graph.
To learn more about JupiterOne’s CCM capabilities, attendees can meet the team at Money20/20 Europe in Amsterdam (Hall 5, Stand 5F61) and Infosecurity Europe in London (Stand G122) from 2 to 4 June 2026.
For more information about JupiterOne CCM, visit https://www.jupiterone.com/products/ccm.
About JupiterOne
JupiterOne is the AI Risk Management Platform that helps security teams in highly regulated industries understand and prioritize risks in complex, AI-driven environments. Built on a true graph data model, JupiterOne brings together assets, identities, security posture and controls, revealing the intuitive relationships that connect everything across the enterprise. Unlike list-based approaches, interrogating those relationships allows you to understand how risk flows, the blast radius, and what to prioritize within seconds, at an enterprise scale. With deep integrations and automated discovery across hundreds of tools, JupiterOne provides a continuously updated view of asset relationships and context to prevent tool proliferation and quickly prioritize solutions.
Media contacts
Mary Ross
Market bridge for JupiterOne
jupiterone@marketbridge.com

