This report reads the CertReports index as of 18 Sep 2026: 8,228 public evidence rows across 3,000 B2B software vendors, drawn from 6 sources. It measures drift: how much public compliance evidence lapsed, how old it is, and how coverage differs by framework and category. Every figure below is computed from stored rows, dated, and reproducible.
- 44.3%
- of evidence rows are past their date
- 3,645 of 8,228 rows
- 69%
- of DPF listings linked to vendors have lapsed
- 3,455 lapsed, 1,585 active
- 29.6%
- of the top 2,000 vendors carry a lapsed EU-US Data Privacy Framework row
- 586 of 1,981 vendors by demand rank
Lapse rates by framework
A row lapses when its own evidence says so: a certificate expiry, a report period plus twelve months, a registry usage end date, a registry validation date plus twelve months, or a registry withdrawal. Active rows are verified or stated rows whose date has not passed.
| Framework | Active rows | Lapsed rows | Lapse share | Expiring in 90 days | Sources |
|---|---|---|---|---|---|
| EU-US Data Privacy Framework | 1,585 | 3,455 | 68.6% | 356 | dpf |
| PCI DSS | 1,616 | 190 | 10.5% | 438 | drata, vanta, visa_grsp |
| FedRAMP | 673 | 0 | 0.0% | 0 | drata, fedramp, vanta |
| CSA STAR | 413 | 0 | 0.0% | 0 | csa_star, drata, vanta |
| ISO/IEC 27001 | 70 | 0 | 0.0% | 0 | csa_star, drata, vanta |
| SOC 2 | 46 | 0 | 0.0% | 0 | csa_star, drata, vanta |
| GDPR | 21 | 0 | 0.0% | 0 | drata, vanta |
| CCPA / CPRA | 17 | 0 | 0.0% | 0 | drata, vanta |
| ISO/IEC 27018 | 16 | 0 | 0.0% | 0 | drata, vanta |
| ISO/IEC 27017 | 16 | 0 | 0.0% | 0 | drata, vanta |
| HIPAA | 15 | 0 | 0.0% | 0 | drata, vanta |
| ISO/IEC 42001 | 13 | 0 | 0.0% | 0 | drata, vanta |
| ISO/IEC 27701 | 9 | 0 | 0.0% | 0 | drata, vanta |
| SOC 3 | 8 | 0 | 0.0% | 0 | drata |
| TX-RAMP | 8 | 0 | 0.0% | 0 | drata |
| BSI C5 | 7 | 0 | 0.0% | 0 | drata |
| ENS | 7 | 0 | 0.0% | 0 | drata |
| IRAP | 7 | 0 | 0.0% | 0 | drata, vanta |
| TISAX | 7 | 0 | 0.0% | 0 | drata |
| GovRAMP | 6 | 0 | 0.0% | 0 | drata |
| Cyber Essentials | 6 | 0 | 0.0% | 0 | drata, vanta |
| SOC 1 | 5 | 0 | 0.0% | 0 | drata, vanta |
Lapse share is lapsed divided by active plus lapsed, as of 18 Sep 2026.
- EU-US Data Privacy Framework3,45568.6%
- PCI DSS19010.5%
The top 2,000 vendors
The 2,000 highest-demand vendors in the catalogue (1,981 active) are the ones most reviews touch. This table asks a narrower question than the one above: how many of them carry at least one lapsed row per framework.
| Framework | Top-2,000 vendors with a row | With a lapsed row | Share of the top 2,000 |
|---|---|---|---|
| EU-US Data Privacy Framework | 1,019 | 586 | 29.6% |
| FedRAMP | 239 | 0 | 0.0% |
| CSA STAR | 217 | 0 | 0.0% |
| PCI DSS | 190 | 25 | 1.3% |
| ISO/IEC 27001 | 56 | 0 | 0.0% |
| SOC 2 | 38 | 0 | 0.0% |
| GDPR | 21 | 0 | 0.0% |
| CCPA / CPRA | 17 | 0 | 0.0% |
| ISO/IEC 27018 | 16 | 0 | 0.0% |
| ISO/IEC 27017 | 16 | 0 | 0.0% |
| HIPAA | 15 | 0 | 0.0% |
| ISO/IEC 42001 | 13 | 0 | 0.0% |
| ISO/IEC 27701 | 9 | 0 | 0.0% |
| SOC 3 | 8 | 0 | 0.0% |
| TX-RAMP | 8 | 0 | 0.0% |
| BSI C5 | 7 | 0 | 0.0% |
| ENS | 7 | 0 | 0.0% |
| IRAP | 7 | 0 | 0.0% |
| TISAX | 7 | 0 | 0.0% |
| GovRAMP | 6 | 0 | 0.0% |
| Cyber Essentials | 6 | 0 | 0.0% |
| SOC 1 | 5 | 0 | 0.0% |
| Cyber Essentials Plus | 3 | 0 | 0.0% |
| ISO 22301 | 2 | 0 | 0.0% |
| HITRUST | 2 | 0 | 0.0% |
| HDS | 2 | 0 | 0.0% |
| ISMAP | 2 | 0 | 0.0% |
| ISO 9001 | 1 | 0 | 0.0% |
Evidence age
Days between the capture date of each row and 18 Sep 2026. Registries are re-read nightly, so registry rows stay young; vendor-stated rows age until the page is captured again.
| Framework | Rows | Median age (days) | 90th percentile (days) |
|---|---|---|---|
| EU-US Data Privacy Framework | 5,040 | 1 | 1 |
| PCI DSS | 1,806 | 1 | 1 |
| FedRAMP | 673 | 1 | 1 |
| CSA STAR | 413 | 1 | 1 |
| ISO/IEC 27001 | 70 | 1 | 1 |
| SOC 2 | 46 | 1 | 1 |
| GDPR | 21 | 1 | 1 |
| CCPA / CPRA | 17 | 1 | 1 |
| ISO/IEC 27017 | 16 | 1 | 1 |
| ISO/IEC 27018 | 16 | 1 | 1 |
| HIPAA | 15 | 1 | 1 |
| ISO/IEC 42001 | 13 | 1 | 1 |
HIPAA BAA coverage by category
Share of indexable vendors in each category with a public business associate agreement offer. There is no HIPAA certification; the offer is the public artefact.
| Category | Indexable vendors | With a public BAA offer | Coverage |
|---|---|---|---|
| Security | 174 | 3 | 1.7% |
| Communications and CPaaS | 49 | 3 | 6.1% |
| Compliance and GRC | 118 | 2 | 1.7% |
| Cloud and hosting | 93 | 1 | 1.1% |
| DevOps and observability | 90 | 1 | 1.1% |
| Data platforms | 87 | 1 | 1.1% |
| Analytics | 85 | 1 | 1.2% |
| Customer support | 63 | 1 | 1.6% |
| Identity and access | 47 | 1 | 2.1% |
| Payments | 305 | 0 | 0.0% |
| Marketing | 98 | 0 | 0.0% |
| IT management | 86 | 0 | 0.0% |
| Finance and accounting | 83 | 0 | 0.0% |
| Business services | 82 | 0 | 0.0% |
| Education | 69 | 0 | 0.0% |
FedRAMP status mix
Statuses as published in the Marketplace data file at the last sync, plus vendor-stated rows from trust centres. Under the Consolidated Rules for 2026 the official label is "FedRAMP Certified"; rows carry the text the file published.
- FedRAMP Authorized528
- FedRAMP Ready70
- Agency In Process48
- FedRAMP In Process13
- Vendor states FedRAMP High on its trust centre5
- Vendor states FedRAMP Moderate on its trust centre4
- Vendor states FedRAMP on its trust centre3
- Vendor states FedRAMP 20x on its trust centre2
Data Privacy Framework usage end
- 1,585
- Active DPF listings linked to vendors
- 3,455
- Past their usage end date
- 68.6% of linked listings
- 356
- Usage end dates in the next 90 days
Drift index
The drift index is the number of rows that lapsed or were removed in a month per 1,000 active rows. It is the time series behind the change log; the first observed month is September 2026, when the index went live, so the series is short and will lengthen with each report.
| Month | Added | Renewed | Lapsed | Removed | Other events | Drift per 1,000 active rows |
|---|---|---|---|---|---|---|
| 2026-09 | 249 | 0 | 0 | 4 | 165 | 0.9 |
- 2026-09418
Events in the period
| Event type | Count |
|---|---|
| attestation added | 249 |
| subprocessor added | 165 |
| attestation removed | 4 |
Method and sources
- Registry rows: FedRAMP Marketplace data file, Data Privacy Framework participant list, Visa Global Registry of Service Providers, CSA STAR registry, mirrored nightly.
- Vendor-stated rows: trust centres and security pages captured with a content hash and capture date.
- Lapse: expiry date, period end plus twelve months, usage end date, validation date plus twelve months, or withdrawal.
- Top 2,000: vendors ranked by demand in the CertReports catalogue.
- Drift index: (lapsed + removed) in the month divided by active rows at generation, per 1,000.
- Generated 18 Sep 2026. Figures for a closed month are frozen when the month ends; the current month is refreshed daily.
Cite this report
CertReports, Compliance drift report, September 2026. https://certreports.com/reports/2026-09. Figures as of 18 Sep 2026.