Compliance teams have gone continuous, but their evidence-gathering hasn’t caught up
Brief
The perception that compliance is a once-a-year scramble is out of date, according to a new survey of 201 security and compliance practitioners published by Pentest-Tools. com . The research finds that continuous compliance has effectively already arrived inside most organisations, but the automation needed to support it has not.
The study , carried out in July 2026 and drawn from IT managers, compliance and GRC leads, security engineers, DevSecOps professionals and security specialists, set out to test how organisations maintain certifications such as ISO 27001 and SOC 2. Rather than surveying executives or auditors, Pentest-Tools. com went directly to the practitioners responsible for the day-to-day evidence work.
Assessment cycles have quietly gone continuous
According to the findings, 60.
