The state of public compliance evidence in 2026: what 3,000 vendors actually publish
CertReports Research · 18 Sep 2026 · 12 min read
Regulations
The third-party provisions of 9 regulations and standards, each with its citation and the vendor evidence that may support it, checked against the CertReports index. Reviewed 21 Sep 2026.
Across 6,433 indexed vendors, the evidence these requirements ask for most.
vendors, at least
vendors
vendors list one
vendors list one
GDPR and UK GDPR (Article 28 for processors), DORA (Articles 28 and 30 for ICT third-party providers), NIS2 (Article 21(2)(d) supply chain security), HIPAA (business associate agreements under 45 CFR 164.308(b) and 164.314), PCI DSS (Requirement 12.8) and, for AI, the EU AI Act (Articles 25, 26 and 53). ISO/IEC 27001 and SOC 2 carry the same expectation as controls 5.19 to 5.23 and CC9.2.
No. A SOC 2 report or ISO 27001 certificate is evidence that may support a requirement such as GDPR Article 28(1) or DORA Article 28(5). Each regulation also asks for things a security report does not cover, such as a data processing agreement, subprocessor control, data locations and incident assistance.
Each requirement lists the kinds of evidence that usually support it. CertReports looks for them in registry rows, trust-centre documents and statements, legal documents and subprocessor lists, each with a date and a source. A requirement shows evidence found, available on request, partial, expired or no public evidence.
No. It maps obligations to evidence so a review starts from what is public. Scope, sufficiency and contract terms are for your counsel or auditor.
CertReports Research · 18 Sep 2026 · 12 min read
This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.