Skip to main content

Analysis

The state of public compliance evidence in 2026: what 3,000 vendors actually publish

We read the public record for three thousand B2B software vendors. How much is verifiable, how much is a badge, which frameworks are most often out of date, and what buyers should do about it.

CertReports ResearchPublished 18 Sep 202612 min read

The state of public compliance evidence in 2026: what 3,000 vendors actually publish

CertReports indexes public compliance evidence for B2B software vendors: what a registry lists, what a trust centre states, what an auditor confirms, and when each fact was captured. With three thousand vendors carrying at least one public evidence page, the index is large enough to answer a question buyers ask constantly and vendors rarely answer: how much of what the market claims can actually be checked? This is the first annual reading of the index. Every number is reproducible on the date given, and the method is described before the findings.

Method

Figures are from the CertReports index on 18 September 2026. Registry figures come from nightly mirrors of the FedRAMP Marketplace data file, the Data Privacy Framework participant list, the Visa Global Registry of Service Providers and the CSA STAR registry. Vendor-stated figures come from captured trust centres and security pages, each with a content hash and a capture time. Nothing here rates a vendor; the index records what is public and when.

3,000
Vendors with a public evidence page
Out of 11,451 in the catalogue
8,341
Dated evidence rows
One row per vendor, framework and source
3,111
Rows already expired
Mostly DPF certifications past their usage end date

Finding 1: registries are where verification lives

Four public registries account for almost all of the verified rows in the index. They share a property no vendor page has: a third party publishes the status, and the status carries a date. The Data Privacy Framework list is the largest by far, followed by the Visa registry, the FedRAMP Marketplace and CSA STAR.

Public evidence rows by framework, September 2026
  • EU-US Data Privacy Framework4,6731,562 active, 3,111 lapsed
  • PCI DSS (Visa registry)1,5311,361 validated
  • FedRAMP561560 Marketplace listings
  • CSA STAR402
  • ISO/IEC 2700168
  • SOC 245
  • GDPR artefacts21
  • HIPAA (BAA offered)15

The imbalance is the story. SOC 2 and ISO 27001 are the two frameworks buyers ask about most, and they are the two with the least public, third-party-published evidence. There is no SOC 2 registry and no crawlable ISO registry, so what the index holds for them comes from vendor pages and, where an auditor confirms an engagement, from the auditor. Those rows are labelled vendor-stated or verified by auditor, never verified by registry.

FrameworkWho publishes the statusCan a buyer verify without asking?Share of index rows that are registry-verified
FedRAMPGSA, Marketplace data fileYes100%
DPFUS Department of CommerceYes100%
PCI DSSVisa and MastercardYes, where listed89%
CSA STARCloud Security AllianceYes100%
ISO 27001Certification bodies; no bulk registryOnly by asking the CB0%
SOC 2Nobody; the report is restrictedNo0%
HIPAANobody; it is a contractNo0%
A glass office tower
Where a government or card-brand registry exists, verification is free. Where it does not, buyers rely on what vendors choose to publish. · Photo by Sean Pollock on Unsplash

Finding 2: two thirds of DPF rows are lapsed

The DPF participant list includes every organisation that ever self-certified, including inactive and withdrawn ones. Of the DPF rows the index links to a vendor, 3,111 are past their usage end date without a visible recertification, against 1,562 active. That ratio is why a DPF badge on a privacy page proves nothing on its own: the list, not the badge, decides, and it changes daily. It also means the DPF is the single largest source of expiry in the index.

What the vendor page showsWhat the registry saysCertReports state
DPF badge on the privacy pageActive, usage end date in the futureVerified by registry
DPF badge on the privacy pageInactive, usage end date passedExpired
NothingActive listing under a parent entityVerified by registry, entity noted
"GDPR compliant" badgeNo listingNo public evidence for DPF; the badge is not a framework

Finding 3: PCI DSS, the registry is bigger than the validations

The Visa Global Registry mixes validated service providers with Third Party Agents registered for other reasons. Only rows with a validation date become verified PCI DSS rows in the index; the rest are recorded as agent registrations. Across the whole registry that is roughly three quarters of rows, covered in a separate analysis. Among the 1,531 PCI DSS rows linked to indexed vendors, 1,361 carry a validation date and 158 have passed the twelve-month window.

Finding 4: FedRAMP is the cleanest signal a buyer can get

FedRAMP has one authoritative public source, a machine-readable file, and a status vocabulary with no ambiguity. Every one of the 561 FedRAMP rows in the index is registry-verified, and the Marketplace supplies the class, the certifying agency and the assessor as well. No other framework gives a buyer that much for free. The 2026 Consolidated Rules renamed authorization to certification and retired the Ready status; the FedRAMP explainer covers the change.

Finding 5: what is usually stale

  • SOC 2 report period ends more than twelve months old on trust centres that still show a current-looking badge.
  • ISO 27001 certificates citing the 2013 edition, which lapsed under accredited certification on 31 October 2025.
  • DPF listings past the usage end date on privacy pages that were never updated.
  • PCI DSS attestations of compliance older than a year, referenced on checkout pages as if permanent.
Expired rows by framework, September 2026
  • DPF3,111
  • PCI DSS158
  • ISO 27001 (2013 edition or past expiry)24
  • SOC 2 (period older than 12 months)12
Reports on a desk
A third of the rows in the index have a date that has already passed. Most of the vendor pages they came from have not changed. · Photo by Helloquence on Unsplash

Context from outside the index

The index measures what is public, not what exists. The ISO Survey 2024 counted 96,709 valid ISO/IEC 27001 certificates worldwide, so the 68 vendors with public ISO evidence in the index are a small fraction of certified companies; most simply do not publish the certificate. Agency’s roundup of SOC 2 statistics puts SOC 2 in 70 to 85 percent of enterprise B2B RFPs, which explains why SOC 2 is the most claimed framework on trust centres and the least verifiable. And Verizon’s 2025 Data Breach Investigations Report found that breaches involving a third party doubled to 30 percent, which is the reason any of this matters.

Breaches involving a third party jumped to 30%, up from roughly 15% the previous year.

What a buyer should take from this

  1. Trust registries first. FedRAMP, DPF, Visa and CSA STAR rows are verified by a third party and dated; check them before asking anything.
  2. Treat SOC 2 and ISO badges as claims until the report type, period end, certificate edition and scope are visible. Ask for exactly those four facts.
  3. Watch expiry. A third of the rows in the index have a date that has already passed; most vendor pages do not say so.
  4. Put your shortlist side by side on Compare and export the table. The empty cells are your questionnaire.

What a vendor should take from this

Publish the four facts next to every badge: type or edition, period end or expiry, auditor or certification body, and scope. Link the registry entry where one exists. Vendors that do this appear in the index as verified or dated vendor-stated rows instead of "no public evidence", and reviewers stop emailing sales for the basics.

No public evidence is literally true and never means non-compliant. It means nobody published anything we could capture, and a vendor can fix that in a day.

People also ask

How many companies have SOC 2 reports?

Nobody publishes a count, because there is no SOC 2 registry and reports are restricted. The CertReports index found 45 vendors with public SOC 2 facts on trust centres on 18 September 2026; the real number of reports is far higher and unpublished.

Which compliance framework is easiest to verify?

FedRAMP, because the Marketplace publishes a machine-readable file with status, class, agency and assessor. DPF, the Visa registry and CSA STAR are also public and dated.

What percentage of vendor compliance claims are out of date?

In the CertReports index, 3,111 of 8,341 rows (37 percent) had a date that had passed on 18 September 2026, most of them DPF certifications past their usage end date.

Is a compliance badge on a website reliable?

Only as the name of a question. A badge does not carry a type, period, edition, scope or date. Verify it against a registry where one exists, or ask for the four facts behind it.

How often does CertReports update the data?

Registries are mirrored nightly. Trust centres and legal pages are re-captured on a rolling schedule, and every row shows its as-of date.

What does no public evidence mean?

That nothing public was found at the last check. It is not a judgement about compliance, and vendors can change it by publishing evidence or claiming their page.

indexSOC 2ISO 27001FedRAMPPCI DSSDPFstatistics
C

CertReports Research · Index and methodology

Notes from the team that runs the nightly registry syncs, the snapshot pipeline and the state resolver. Every figure quoted is reproducible from the index on the date given.

You might also like