The SCF took the initiative to survey Governance, Risk & Compliance (GRC) professionals as part of the 2026 State of the Industry (SOTI) Survey. The results both validate many commonly-held assumptions that are observable in the industry, but also provide some interesting insights into challenges facing cybersecurity professionals.
Interesting insights from SOTI 2026:
- Organizations facing four times the audit load report almost the same confidence as those facing far less.
- Mergers, Acquisitions & Divestitures (MA&D) due-diligence was cited by zero respondents as a primary driver.Smaller organizations are pulled into compliance by their customers, while larger organizations are pushed into it by regulators and their own boards.
- GRC-platform satisfaction overall averages the lowest-rated metric anywhere in this survey and there is a size-based pattern behind that number, where mid-market organizations report the least satisfaction while having the heaviest reliance on spreadsheets.
- Having “no defined methodology” for risk management practices was most common at mid-market organizations.
- Mid-market organizations report numerous gaps and weaker practices that neither smaller nor larger peers share.
- The same practitioners who report their organizations actively using AI in security and compliance workflows are also the ones most distrustful of AI marketing claims.
- Decreased metaframework use in larger organizations indicates those organizations often have the resources to build and maintain a bespoke, in-house control mapping instead of adopting an off-the-shelf one.