Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageCompliance Desk
Compliance

Compliance teams have gone continuous, but their evidence-gathering hasn’t caught up

A Pentest-Tools.com survey of 201 practitioners finds continuous compliance is now standard practice, but evidence-gathering automation lags far behind — a gap that undermines audit readiness under NIS2 and DORA.

Summary written by editorial AI · Source link below

Filed by IT Security Guru1 min readRead at source ↗

The perception that compliance is a once-a-year scramble is out of date, according to a new survey of 201 security and compliance practitioners published by Pentest-Tools.com. The research finds that continuous compliance has effectively already arrived inside most organisations, but the automation needed to support it has not. The study, carried out in July 2026 […] The post Compliance teams have gone continuous, but their evidence-gathering hasn’t caught up appeared first on IT Security Guru .

Editorial Analysis

Framed for the Compliance & GRC desk

Why it matters

A survey of 201 practitioners confirms that most organisations already operate continuous compliance but still rely on manual evidence collection — a gap that directly affects audit readiness under NIS2 and DORA.

What to do

Evaluate automated evidence-collection platforms to close the gap between continuous compliance monitoring and the audit artefacts your frameworks require.

Board brief

Most organisations now monitor compliance continuously but still gather audit evidence manually — a mismatch that increases regulatory exposure.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at IT Security Guru

External link — opens at IT Security Guru in a new tab.

§
Continue with

More from the Compliance Desk