Compliance teams have gone continuous, but their evidence-gathering hasn’t caught up
A Pentest-Tools.com survey of 201 practitioners finds continuous compliance is now standard practice, but evidence-gathering automation lags far behind — a gap that undermines audit readiness under NIS2 and DORA.
Summary written by editorial AI · Source link below
The perception that compliance is a once-a-year scramble is out of date, according to a new survey of 201 security and compliance practitioners published by Pentest-Tools.com. The research finds that continuous compliance has effectively already arrived inside most organisations, but the automation needed to support it has not. The study, carried out in July 2026 […] The post Compliance teams have gone continuous, but their evidence-gathering hasn’t caught up appeared first on IT Security Guru .
Editorial Analysis
Framed for the Compliance & GRC desk
A survey of 201 practitioners confirms that most organisations already operate continuous compliance but still rely on manual evidence collection — a gap that directly affects audit readiness under NIS2 and DORA.
Evaluate automated evidence-collection platforms to close the gap between continuous compliance monitoring and the audit artefacts your frameworks require.
Most organisations now monitor compliance continuously but still gather audit evidence manually — a mismatch that increases regulatory exposure.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at IT Security Guru in a new tab.
More from the Compliance Desk
- Population-Calibrated Graph Screening at 835-Million-Address Scale, with Label-Free Transfer to New Chains4d
- French hospital fined €500,000 after breach exposes data of 727,0004d
- Identification of Compositional Risks in Data Protection Impact Assessments and Beyond6d
- You Know GDPR Is Good Based on Who Hates It29 Aug
- Why Provision 29 is raising the bar for board accountability26 Aug