Skip to main content

Understanding Upload Tests: Intervals, Evidence Validity, Due Dates, and Tolerance Windows

Written by Brady Price

This guide explains how Upload Tests work in Secureframe: how evidence is evaluated, when a test passes or fails, and how intervals, due dates, tolerance windows, and evidence dates fit together.

Upload Tests are tests where you manually upload evidence. They are different from:

  • Platform tests, which are completed inside Secureframe

  • Integration tests, which pull evidence from connected tools

The intervals, evidence-validity rules, and due date behavior in this article apply only to Upload Tests.

Interactive Walkthrough

Interactive Walkthrough: Launch the interactive walkthrough to practice working with upload tests. Click the highlighted areas on each screen to move to the next step. This is not a play/pause video.


Test Intervals

An Upload Test's interval is how often the test needs fresh evidence (for example, Monthly, Quarterly, or Annual).

Every Upload Test has a default interval. Most default to Annual. Some default to a shorter cadence, such as Quarterly, when the activity needs to be refreshed more often.

To change a test's interval:

  1. Open the test details slide-out

  2. Click Test Interval

  3. Choose a cadence

A custom interval always takes precedence over the default. You can change it at any time.


Activity Completion Date

The activity completion date is the date when a piece of evidence was actually completed or came into effect. Secureframe uses this date to evaluate pass/fail, not the date you uploaded the file.

Where you set it:

  • On upload: the Activity completion date field in the upload form

  • After upload: shown next to the evidence as Completed on...

Why it matters:

  • Ties each file to the timeframe it actually represents

  • Keeps pass/fail accurate

  • Advances the next due date correctly (completion date + interval)

Example

  • Your team finishes annual penetration testing on March 15, 2026

  • You upload the report on April 10, 2026

  • Activity completion date = March 15, 2026 (not April 10)

  • Next due date (Annual) = March 15, 2027


Evidence Validity and the "Expired" Status

An Upload Test passes when it has fresh evidence: evidence with an activity completion date that falls inside the test's current interval window. "Fresh" depends on the cadence:

  • For an Annual test, the completion date must be within the past year.

  • For a Quarterly test, the completion date must be within the past 3 months.

  • For a Monthly test, the completion date must be within the past month.

When no evidence on a test has a completion date inside the current interval window, the test moves to At Risk (if you have a Tolerance Window set) or Failing. A red banner appears on the test, showing the exact completion-date range your next evidence needs to fall within.

Evidence whose completion date sits outside the current interval window gets the "Expired" status. Expired evidence:

  • Stays visible in your test history.

  • Stays visible to auditors in the Audit Module, as long as its completion date falls within the audit's observation window.

  • Is not deleted.

  • Can be manually archived if you want to remove it.


Due Dates

The due date for an Upload Test is the date by which the test needs fresh evidence to keep passing. When you upload qualifying evidence, the next due date advances automatically to the activity completion date plus the test's interval.

For example, a Quarterly test with evidence completed April 1 sets the next due date to July 1 (April 1 plus 3 months).

You can view and adjust due dates and intervals on the test details slide-out.


Tolerance Window

Tolerance Window is an optional setting that adds a buffer between the time a test stops passing and when it falls out of compliance. When Secureframe detects that the test is no longer passing, the test status changes to "At Risk" until the test is remediated or the tolerance window has expired.

  • If you remediate the test failure during the tolerance window, the test starts passing again.

  • If you do not remediate the failure before the tolerance window expires, the test enters the Failing state.

You can set the tolerance window for a test in the test details slide-out on the right side panel.

Note: Tolerance Window applies to all test types in Secureframe (Upload, Integration, and Platform). It's covered here in the context of Upload Tests.


Frequently Asked Questions (FAQ)

If I set an interval on a disabled test, will the test be re-enabled after the interval reaches its desired window?

  • No, setting an interval on an already disabled test will not re-enable the test, and the test will stay disabled. The test needs to be re-enabled.

Why is my test At Risk or Failing?

  • A test moves to At Risk or Failing when no evidence has a completion date inside the current interval window. The red banner on the test shows the exact date range your next evidence needs to fall within. Upload fresh evidence with a completion date in that range and the test will pass. (At Risk applies when you have a Tolerance Window configured; without one, the test moves directly to Failing.)

What does the "Expired" status mean for evidence?

  • Evidence is marked Expired when its completion date falls outside the current interval window for the test. Expired evidence is not deleted, stays visible in your test history, and remains available to auditors in the Audit Module as long as its completion date falls within the audit's observation window. You can manually archive Expired evidence if you want to remove it from your active list.

I set a custom interval on a test. Will the default override it?

  • No. Custom intervals you set always take precedence over the default. Defaults only apply where no interval is set.

Why did my test default to Quarterly instead of Annual?

  • Secureframe defaults a small number of tests to Quarterly when the underlying activity typically needs to be refreshed every three months. Most Upload Tests default to Annual. If the default doesn't match your control's actual cadence, you can change the interval at any time from the test details slide-out.

If I'm using the Tolerance Window and the test goes to At Risk, how long do I have to complete the test?

  • You can complete the test at any point after it is failing, but the Tolerance Window is there to provide a buffer and give you time to fix it before the test enters the Failing state. The Tolerance Window puts the test into "At Risk" for a defined period when a failing condition is detected. If you have a test interval and due date set, the tolerance window starts after the due date has passed.

Why don't I see the Test Interval option on this test?

  • The Test Interval option is only applicable to Upload Tests, where evidence must be manually added to make the test pass. Integration and Platform Tests automatically pull evidence through their integrations, so they do not use Test Intervals.

My Upload Test is failing even though the due date is set far into the future. Why?

  • Upload Tests require evidence to pass. If you have no evidence with a completion date inside the current interval window, the test will be Failing regardless of the future due date. Open the test and check the banner for the required completion-date range, then upload qualifying evidence.

Will Expired evidence show up in my audit?

  • Yes, as long as the evidence's completion date falls within the audit's observation window. The Expired status applies in the Tests Module and signals that the evidence is no longer fresh for pass/fail purposes, but it stays visible to auditors in the Audit Module.

Can I manually archive evidence?

  • Yes. You can manually archive any piece of evidence from the test view. Archived evidence is removed from your active list and does not contribute to the test's pass/fail evaluation.

Did this answer your question?