You should have a vulnerability assessment done at least once a year, with monthly scans if your organisation has high-risks or frequent changes in systems, networks, or regulatory compliance requirements.