Skip to main content

Compliance drift report

Compliance drift report, September 2026: 69% of DPF listings lapsed, BAA coverage and registry mix across 3,000 vendors

Figures as of 18 Sep 2026 · generated 18 Sep 2026 · refreshed daily

This report reads the CertReports index as of 18 Sep 2026: 8,228 public evidence rows across 3,000 B2B software vendors, drawn from 6 sources. It measures drift: how much public compliance evidence lapsed, how old it is, and how coverage differs by framework and category. Every figure below is computed from stored rows, dated, and reproducible.

44.3%
of evidence rows are past their date
3,645 of 8,228 rows
69%
of DPF listings linked to vendors have lapsed
3,455 lapsed, 1,585 active
29.6%
of the top 2,000 vendors carry a lapsed EU-US Data Privacy Framework row
586 of 1,981 vendors by demand rank

Lapse rates by framework

A row lapses when its own evidence says so: a certificate expiry, a report period plus twelve months, a registry usage end date, a registry validation date plus twelve months, or a registry withdrawal. Active rows are verified or stated rows whose date has not passed.

FrameworkActive rowsLapsed rowsLapse shareExpiring in 90 daysSources
EU-US Data Privacy Framework1,5853,45568.6%356dpf
PCI DSS1,61619010.5%438drata, vanta, visa_grsp
FedRAMP67300.0%0drata, fedramp, vanta
CSA STAR41300.0%0csa_star, drata, vanta
ISO/IEC 270017000.0%0csa_star, drata, vanta
SOC 24600.0%0csa_star, drata, vanta
GDPR2100.0%0drata, vanta
CCPA / CPRA1700.0%0drata, vanta
ISO/IEC 270181600.0%0drata, vanta
ISO/IEC 270171600.0%0drata, vanta
HIPAA1500.0%0drata, vanta
ISO/IEC 420011300.0%0drata, vanta
ISO/IEC 27701900.0%0drata, vanta
SOC 3800.0%0drata
TX-RAMP800.0%0drata
BSI C5700.0%0drata
ENS700.0%0drata
IRAP700.0%0drata, vanta
TISAX700.0%0drata
GovRAMP600.0%0drata
Cyber Essentials600.0%0drata, vanta
SOC 1500.0%0drata, vanta

Lapse share is lapsed divided by active plus lapsed, as of 18 Sep 2026.

Lapsed rows by framework
  • EU-US Data Privacy Framework3,45568.6%
  • PCI DSS19010.5%

The top 2,000 vendors

The 2,000 highest-demand vendors in the catalogue (1,981 active) are the ones most reviews touch. This table asks a narrower question than the one above: how many of them carry at least one lapsed row per framework.

FrameworkTop-2,000 vendors with a rowWith a lapsed rowShare of the top 2,000
EU-US Data Privacy Framework1,01958629.6%
FedRAMP23900.0%
CSA STAR21700.0%
PCI DSS190251.3%
ISO/IEC 270015600.0%
SOC 23800.0%
GDPR2100.0%
CCPA / CPRA1700.0%
ISO/IEC 270181600.0%
ISO/IEC 270171600.0%
HIPAA1500.0%
ISO/IEC 420011300.0%
ISO/IEC 27701900.0%
SOC 3800.0%
TX-RAMP800.0%
BSI C5700.0%
ENS700.0%
IRAP700.0%
TISAX700.0%
GovRAMP600.0%
Cyber Essentials600.0%
SOC 1500.0%
Cyber Essentials Plus300.0%
ISO 22301200.0%
HITRUST200.0%
HDS200.0%
ISMAP200.0%
ISO 9001100.0%

Evidence age

Days between the capture date of each row and 18 Sep 2026. Registries are re-read nightly, so registry rows stay young; vendor-stated rows age until the page is captured again.

FrameworkRowsMedian age (days)90th percentile (days)
EU-US Data Privacy Framework5,04011
PCI DSS1,80611
FedRAMP67311
CSA STAR41311
ISO/IEC 270017011
SOC 24611
GDPR2111
CCPA / CPRA1711
ISO/IEC 270171611
ISO/IEC 270181611
HIPAA1511
ISO/IEC 420011311

HIPAA BAA coverage by category

Share of indexable vendors in each category with a public business associate agreement offer. There is no HIPAA certification; the offer is the public artefact.

CategoryIndexable vendorsWith a public BAA offerCoverage
Security17431.7%
Communications and CPaaS4936.1%
Compliance and GRC11821.7%
Cloud and hosting9311.1%
DevOps and observability9011.1%
Data platforms8711.1%
Analytics8511.2%
Customer support6311.6%
Identity and access4712.1%
Payments30500.0%
Marketing9800.0%
IT management8600.0%
Finance and accounting8300.0%
Business services8200.0%
Education6900.0%

FedRAMP status mix

Statuses as published in the Marketplace data file at the last sync, plus vendor-stated rows from trust centres. Under the Consolidated Rules for 2026 the official label is "FedRAMP Certified"; rows carry the text the file published.

FedRAMP rows by published status
  • FedRAMP Authorized528
  • FedRAMP Ready70
  • Agency In Process48
  • FedRAMP In Process13
  • Vendor states FedRAMP High on its trust centre5
  • Vendor states FedRAMP Moderate on its trust centre4
  • Vendor states FedRAMP on its trust centre3
  • Vendor states FedRAMP 20x on its trust centre2

Data Privacy Framework usage end

1,585
Active DPF listings linked to vendors
3,455
Past their usage end date
68.6% of linked listings
356
Usage end dates in the next 90 days

Drift index

The drift index is the number of rows that lapsed or were removed in a month per 1,000 active rows. It is the time series behind the change log; the first observed month is September 2026, when the index went live, so the series is short and will lengthen with each report.

MonthAddedRenewedLapsedRemovedOther eventsDrift per 1,000 active rows
2026-092490041650.9
Change events in the current series
  • 2026-09418

Events in the period

Event typeCount
attestation added249
subprocessor added165
attestation removed4

Method and sources

  • Registry rows: FedRAMP Marketplace data file, Data Privacy Framework participant list, Visa Global Registry of Service Providers, CSA STAR registry, mirrored nightly.
  • Vendor-stated rows: trust centres and security pages captured with a content hash and capture date.
  • Lapse: expiry date, period end plus twelve months, usage end date, validation date plus twelve months, or withdrawal.
  • Top 2,000: vendors ranked by demand in the CertReports catalogue.
  • Drift index: (lapsed + removed) in the month divided by active rows at generation, per 1,000.
  • Generated 18 Sep 2026. Figures for a closed month are frozen when the month ends; the current month is refreshed daily.

Cite this report

CertReports, Compliance drift report, September 2026. https://certreports.com/reports/2026-09. Figures as of 18 Sep 2026.