Security best practice recommends a full assessment at minimum once per year, and after any major event: a new product launch, significant infrastructure change, acquisition, or regulatory review. High-risk sectors (fintech, healthtech, e-commerce) benefit from quarterly assessments or continuous monitoring.