← Back to feed
Policy & RegulationEmerging1 sourceSep 4, 2026 · 12:28via IT Security Guru

Compliance teams have gone continuous, but their evidence-gathering hasn’t caught up

Brief

The perception that compliance is a once-a-year scramble is out of date, according to a new survey of 201 security and compliance practitioners published by Pentest-Tools. com . The research finds that continuous compliance has effectively already arrived inside most organisations, but the automation needed to support it has not.

The study , carried out in July 2026 and drawn from IT managers, compliance and GRC leads, security engineers, DevSecOps professionals and security specialists, set out to test how organisations maintain certifications such as ISO 27001 and SOC 2. Rather than surveying executives or auditors, Pentest-Tools. com went directly to the practitioners responsible for the day-to-day evidence work.

Assessment cycles have quietly gone continuous

According to the findings, 60.

Read more on IT Security Guru