Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageCompliance Desk
Compliance

Compliance teams have gone continuous, but their evidence-gathering hasn’t caught up

A Pentest-Tools.com survey of 201 practitioners finds continuous compliance is now standard practice, but evidence-gathering automation lags far behind — a gap that undermines audit readiness under NIS2 and DORA.

Summary written by editorial AI · Source link below

Filed by IT Security Guru1 min readRead at source ↗

The perception that compliance is a once-a-year scramble is out of date, according to a new survey of 201 security and compliance practitioners published by Pentest-Tools.com. The research finds that continuous compliance has effectively already arrived inside most organisations, but the automation needed to support it has not. The study, carried out in July 2026 […] The post Compliance teams have gone continuous, but their evidence-gathering hasn’t caught up appeared first on IT Security Guru .

Editorial Analysis

Why it matters

Organisations that adopted continuous compliance without automating evidence collection face growing audit-preparation costs and regulatory risk as NIS2 and DORA enforcement intensifies.

What to do

Benchmark your evidence-collection automation maturity and prioritise tooling that maps collected artefacts directly to NIS2/DORA control requirements.

Board brief

Most organisations now monitor compliance continuously but still gather audit evidence manually — a mismatch that increases regulatory exposure.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at IT Security Guru

External link — opens at IT Security Guru in a new tab.

§
Continue with

More from the Compliance Desk