ITSecurityGuru

Compliance teams have gone continuous, but their evidence-gathering hasn’t caught up


The perception that compliance is a once-a-year scramble is out of date, according to a new survey of 201 security and compliance practitioners published by Pentest-Tools.com. The research finds that continuous compliance has effectively already arrived inside most organisations, but the automation needed to support it has not.

The study, carried out in July 2026 and drawn from IT managers, compliance and GRC leads, security engineers, DevSecOps professionals and security specialists, set out to test how organisations maintain certifications such as ISO 27001 and SOC 2. Rather than surveying executives or auditors, Pentest-Tools.com went directly to the practitioners responsible for the day-to-day evidence work.

Assessment cycles have quietly gone continuous

According to the findings, 60.2% of respondents now formally assess the effectiveness of their security controls at least monthly, with 37.8% doing so continuously and a further 22.4% monthly. Just 9.5% still work to an annual assessment cycle, and no organisation in the sample assessed controls less often than every six months.

That cadence has outpaced the rate at which the underlying environments actually change. More than half of respondents (56.8%) said their production systems change monthly or less often, meaning many organisations are now checking their controls as frequently as, or more frequently than, the systems themselves are updated.

The report suggests two possible explanations that likely both hold true: some organisations have deliberately decoupled control validation from the deployment cycle, treating assessment as an always-on discipline, while others are responding to external pressure, such as the rising volume of disclosed and actively exploited vulnerabilities, which can leave an unchanged system newly exposed.

The bottleneck is evidence, not policy

A central finding of the report is that audit delays are rarely caused by outstanding policy or documentation work. Instead, when asked to name their biggest audit preparation bottlenecks, respondents pointed overwhelmingly to operational and technical constraints: getting time and input from technical teams (50.7%), obtaining the required technical evidence in time (42.8%), coordinating responses across multiple teams (36.3%), and resolving outstanding security findings before the audit (34.3%). Only 3.5% of respondents reported no significant bottlenecks at all.

The same pattern emerged when practitioners were asked which parts of maintaining compliance evidence consume the most time. Detection, defined as collecting evidence from available sources, topped the list at 45.8%, ahead of validating that findings are real and repeatable (38.8%) and demonstrating that fixes have held (36.8%). Notably, only 2% of respondents said maintaining compliance evidence was not a significant workload.

“Security teams mostly already have the information auditors need,” the report states. “The bottleneck is turning what they know into what they can show.”

Automation hasn’t kept pace with ambition

While 80.6% of respondents said they collect compliance evidence throughout the year, only 38.3% said they rely primarily on automated tooling. A larger group, 42.3%, said they maintain continuous evidence collection but depend on significant manual consolidation to keep it usable, while 14.9% still assemble evidence largely before audits.

The duplication compounds further once multiple frameworks are involved, which the survey found to be the norm: almost nine in ten respondents maintain more than one compliance framework. Just 6.5% said tooling or templates handle most of the evidence mapping between frameworks. The majority, 63.2%, said they partially remap evidence by hand, and a further 25.9% said most evidence is manually re-documented separately for each framework, meaning the same underlying proof is often reproduced multiple times for different audits.

Certification is trusted, but seen as time-limited

The survey also examined how much confidence practitioners place in certification itself. While 93% of respondents said certification reflects their organisation’s security posture to some degree, only 51.2% believe it does so continuously. A further 41.8% said it is accurate only immediately after an assessment, implying that confidence in the badge fades over the certification cycle for a substantial share of practitioners.

That belief was closely linked to confidence in a hypothetical surprise audit. Among practitioners who see certification as continuously accurate, 59.2% said they would be very confident demonstrating control effectiveness in a next-day audit. Among those who believe it is only accurate immediately after assessment, that figure fell to 16.7%.

Most organisations catch failures before auditors do

One of the more positive findings challenges the assumption that organisations typically discover control failures during audit preparation. Only around 12% of respondents said they first learn of failures during audit preparation or the audit itself. The majority instead surface issues through continuous automated monitoring or scanning (44.3%) or routine internal security reviews (24.4%).

The report notes a maturity gradient by organisation size: among organisations with fewer than 100 employees, 31.3% rely on continuous automated monitoring to surface failures, compared with roughly half of organisations with more than 1,000 employees. Pentest-Tools.com suggests this gap reflects tooling maturity rather than headcount, and argues that automated discovery is one of the few maturity gains smaller teams can achieve without adding staff.

Practitioners want less manual work, not more integrations

When asked to rank which factors matter most when evaluating tools or workflows for audit readiness, continuous, automated evidence generation was the clear priority, ranked most important by 24.4% of respondents and least important by just 3%. By contrast, integration with existing GRC and ticketing tools was ranked most important by only 12.9% and drew the second-highest “matters least” score of any factor.

The report highlights an apparent contradiction: in open-ended responses, automation and integration together accounted for 33.5% of all suggestions when practitioners were asked what they would change about their compliance workflows. Pentest-Tools.com concludes that respondents want a single, continuously current evidence base rather than additional point-to-point connections between tools that still require manual consolidation.

What this means for security and compliance teams

Taken together, the findings paint a picture of a discipline whose ambitions have shifted toward continuous validation faster than its supporting tooling has evolved. Assessment cadences have tightened, evidence volumes have grown, and the number of frameworks organisations must satisfy continues to expand, but much of the resulting workload still falls to technical teams manually collecting, validating and re-mapping proof by hand.

Adrian Furtuna, founder and CEO of Pentest-Tools.com, said the survey was intended to capture the experience of the people actually doing the work rather than executives or auditors. “The bottleneck in modern compliance isn’t policy or paperwork,” the report states. “It’s producing technical evidence that security controls actually work, at the pace environments change, without burning out the engineering teams who hold that evidence.”

The full report, “The audit bottleneck isn’t policy. It’s proof.,” is available from Pentest-Tools.com.



Source link