Research: The Compliance Industry — How Much Money Flows Through Security Theater
Contents 35 sections
1. Market Size: The Compliance Industrial Complex
Global Cybersecurity Spending
Global information security spending has been growing at double-digit rates every year, with no corresponding decline in breaches:
| Year | Global InfoSec Spending (Gartner) | YoY Growth |
|---|---|---|
| 2023 | $188.1 billion | 11.3% |
| 2024 | $215 billion | 14.3% |
| 2025 | $213 billion (forecast) | 15.1% |
| 2026 | $240 billion (forecast) | 12.5% |
Source: Gartner Forecasts Global Information Security Spending to Grow 15% in 2025; Gartner Forecasts Worldwide End-User Spending on Information Security to Total $213 Billion in 2025
IDC independently forecast worldwide security investments at $187.5 billion in 2023 and $211.4 billion in 2024 (12.1% annual growth), with a further 12.2% increase in 2025.
Source: IDC: Worldwide Security Spending to Increase by 12.2% in 2025
Compliance Services Market (Subset)
The cybersecurity compliance consulting market alone was estimated at approximately $15.5 billion in 2025, projecting a CAGR of 14.5% through 2033.
Source: Cybersecurity Compliance Consulting Market 2025-2033
The compliance management platforms market (software, not services) was valued at $2.66 billion in 2025, projected to reach $8.5 billion by 2033 (CAGR 15.6%).
Source: Cybersecurity Compliance Management Platforms Market 2026-2033
Framework Adoption Rates (2025)
Over 68% of large U.S. enterprises now operate centralized compliance platforms covering SOC 2, ISO 27001, HIPAA, PCI DSS, and FedRAMP. Framework adoption among companies pursuing compliance:
- SOC 2: 76%
- Penetration testing: 74%
- SOC 1: 70%
- ISO 27001: 67% (20%+ year-over-year growth in certifications)
- HIPAA: 63%
Source: 280+ Cybersecurity Compliance Statistics for 2026
2. Revenue of Major Compliance/Audit Firms
Traditional Audit Firms
| Firm | Est. Revenue | Employees | Clients | Notes |
|---|---|---|---|---|
| Coalfire | ~$210M | 1,000-5,000 | 1,800+ | Includes 8 of top 10 SaaS providers. 31 locations. New CEO Jan 2026. |
| Schellman | Not publicly disclosed | — | 800+ | Top 50 CPA firm. 36 S&P 500 clients. Founded 2002 (Tampa). |
| A-LIGN | Not publicly disclosed | — | 2,500+ | #1 issuer of SOC 2 and HITRUST. Top 3 FedRAMP assessor. $54.5M total funding (Hg, FTV Capital). Founded 2009 (Tampa). |
Sources: Coalfire - Owler; Coalfire - ZoomInfo; Schellman - CB Insights; A-LIGN - Crunchbase; A-LIGN - GrowJo
SecurityScorecard (Ratings/Risk)
- Revenue: $144.3M (Oct 2024), up from $106M (Oct 2023), $88.5M (Nov 2022), $71M (Nov 2021)
- Valuation: $1B (Series E, March 2021); one estimate puts current valuation at ~$360M
- Total funding: $293M (Sequoia, Intel Capital, GV)
- Customers: 2,600 (including 70% of Fortune 1000)
Sources: SecurityScorecard Revenue - Latka; SecurityScorecard Growth Playbook; SecurityScorecard 2024 Momentum
3. The Compliance Automation Market
Three startups have raised over $850 million combined to automate the process of proving you checked the boxes.
Vanta
- Valuation: $4.15B (Series D, July 2025 — led by Wellington Management)
- ARR: ~$220M (July 2025), up from $152M (end 2024)
- Customers: 12,000 (July 2025), up from 7,000 (end FY24), 4,000 (2022)
- Total funding: $150M+ (Series D alone)
Source: Vanta Revenue, Valuation & Funding - Sacra
Drata
- Valuation: $2B (Series C, co-led by ICONIQ Growth and GGV Capital)
- ARR: ~$98M (Jan 2025), up from $59M (2023) — 61% YoY growth
- Revenue: $100M (Feb 2025)
- Customers: 7,000 (55% YoY growth)
- Total funding: $328.2M
Sources: Drata Revenue - Sacra; Drata Revenue - Latka; Drata Series C Announcement
Secureframe
- Valuation: $294-350M (Jan 2022, last disclosed)
- Revenue: $6M (Oct 2024), up from $4.7M (Dec 2023)
- Total funding: $79M (Kleiner Perkins, Base10, Gradient Ventures)
Sources: Secureframe Revenue - Latka; Secureframe - Crunchbase
What “Compliance Automation” Actually Automates
Vanta runs 1,200+ automated hourly tests via integrations, collecting evidence and mapping controls to frameworks. The pitch is that it replaces spreadsheets and screenshot folders.
What it actually does: semi-automated evidence collection, integrations with cloud infrastructure/ticketing/code repos, auto-generated Statements of Applicability, and continuous monitoring dashboards.
What it does not do: evidence collection is only semi-automated — some tasks still require manual uploads and confirmations (scored 7/10 for automation depth in independent reviews). The platform loses effectiveness at scale, with growing friction, limited report depth, and inflexible workflows. Onboarding is described as “hands-off” and the automation as “shallow.”
Source: Honest Vanta Review - Sprinto; Compliance Tools That Outperform Vanta and Drata
The fundamental criticism: these tools automate the paperwork of compliance, not the security of compliance. They make it faster and cheaper to produce the documentation an auditor wants to see. Whether any of that documentation reflects actual security posture is a separate question entirely.
4. Cost to Organizations of Achieving/Maintaining Compliance
SOC 2
| Component | Cost Range |
|---|---|
| SOC 2 Type 1 audit (small-mid) | $7,500 - $15,000 |
| SOC 2 Type 1 audit (large org) | Up to $60,000+ |
| SOC 2 Type 2 audit | $7,000 - $50,000 |
| Total SOC 2 certification (2026) | $30,000 - $150,000 |
| Readiness assessment | ~$15,000 |
| Security awareness training | ~$2,500 |
| Implementation/tooling | Up to $30,000 |
Sources: SOC 2 Certification Cost 2026 - CyberArrow; SOC 2 Budget - StrongDM; SOC 2 Audit Cost - Secureframe; SOC 2 Audit Cost - Drata
PCI DSS
| Compliance Level | Transaction Volume | Cost Range |
|---|---|---|
| Level 1 | >6M transactions/year | $50,000 - $150,000 |
| Level 2 | 1-6M transactions/year | $10,000 - $50,000 |
| Level 3 & 4 | <1M transactions/year | $1,000 - $10,000 |
| QSA engagement (full ROC) | — | $30,000 - $200,000 |
| Self-Assessment Questionnaire | — | $5,000 - $20,000 |
| Quarterly vulnerability scans | — | $2,000 - $8,000/year |
| Annual penetration testing | — | $20,000 - $60,000 |
Sources: PCI DSS Compliance Cost 2025 - Centraleyes; PCI DSS Certification Cost 2026 - Sprinto; PCI DSS Audit Cost - Thoropass
ISO 27001
- Certification audit: $10,000 - $50,000 on average
- Typically 1.5x to 2x the cost of SOC 2 due to heavier documentation requirements (proving a compliant ISMS)
- Total cost including implementation: significantly higher
Source: SOC 2 vs ISO 27001 - Secureframe
HIPAA
- Overall compliance costs (mid-range): $80,000 - $120,000
- Internal HIPAA audit: $1,000 - $5,000
- External readiness assessment: $15,000 - $40,000
- External audit (small entity, <50 employees): $10,000 - $50,000
- HITRUST certification: $15,000 - $200,000+
- Technology upgrades: $20,000 - $50,000+ (initial implementation)
Sources: HIPAA Compliance Costs 2025 - Secureframe; HIPAA Compliance Cost 2026 - Compyl; HIPAA Compliance Cost - HIPAA Journal
5. Growth Rate of Compliance Industry vs. Actual Breach Reduction
This is where the security theater argument becomes undeniable.
Cybersecurity Spending: Up, Up, Up
Global infosec spending grew from ~$150 billion (2021) to ~$215 billion (2024) — a roughly 43% increase in three years.
Source: Gartner figures above.
Breaches: Also Up, Up, Up
| Year | U.S. Data Compromises | Notes |
|---|---|---|
| 2020 | ~1,862 | Baseline for comparison |
| 2021 | ~1,862 | Similar level |
| 2022 | ~1,802 | Slight dip |
| 2023 | 3,205 | Record year — 78% jump |
| 2024 | 3,158 | Sustained high |
| 2025 | 3,332 | New record — 79% increase over 2020 |
Sources: Data Breach Statistics - Varonis; U.S. Data Compromises Hit Record in 2025 - HIPAA Journal; Data Breach Statistics 2026 - Bright Defense
The industry spent 43% more money and got 79% more breaches. Compliance spending went up. Breach counts went up. The correlation between the two is, at best, zero. The compliance industry’s product is not security — it is the appearance of security, sold at scale.
Verizon’s Damning Finding
Verizon’s forensics team, which has investigated nearly 300 payment card breaches between 2010 and 2016, has never found a single organization that was fully PCI DSS compliant at the time it was breached. This is frequently cited as evidence that compliance works — “they weren’t actually compliant!” — but it equally demonstrates that the compliance process itself fails to produce compliant organizations. If the audit says you pass and you’re not actually secure, the audit is the problem.
As of 2019, less than 28% of organizations were fully PCI DSS compliant — an 8.8% drop from the prior year. Only 8.4% of breached organizations had PCI Requirement 10 (track and monitor access) in place at time of breach.
Sources: Verizon 2024 Payment Security Report; PCI Compliance Declining - eWeek; Verizon Report: Businesses Not Fully PCI-Compliant - Dark Reading
6. Breach-After-Compliance Case Studies
Six well-documented cases where organizations held compliance certifications and were breached through the exact surfaces those certifications were supposed to cover.
6.1. Heartland Payment Systems (2008-2009)
- Compliance status: Certified PCI DSS compliant by their QSA (Qualified Security Assessor) two weeks before the compromise.
- Breach: SQL injection attack on the company website led to malware on the payment processing network. Attackers exfiltrated payment card data for approximately 130 million cards.
- Detection failure: Three separate forensics firms hired by Heartland analyzed the network and declared it malware-free. Heartland’s own staff finally found the malware in January 2009.
- Impact: Stock price fell 78%. 5,000 of 250,000 merchants left.
- The gap: The QSA assessment was a point-in-time snapshot. The SQL injection — a basic web application vulnerability — was within PCI DSS scope. The compliance process certified the system as secure while malware was already present.
Sources: Heartland PCI Case Study - Secureworks; 5 Biggest PCI Compliance Breaches - GoAnywhere
6.2. Target (2013)
- Compliance status: PCI DSS certified as of September 2013, per CFO testimony.
- Breach: Attackers compromised Fazio Mechanical Services (an HVAC contractor with network access), pivoted to Target’s network, and installed malware on point-of-sale systems. 40 million payment card numbers and 70 million customer records stolen.
- Detection failure: Target had deployed FireEye (advanced threat detection). It generated alerts. The security team forwarded them to the operations team. Nobody acted.
- Cost: $18.5M state AG settlement. $292M total breach cost (Target’s reported figure).
- The gap: PCI DSS explicitly covers network segmentation, third-party access controls, and intrusion detection. Target failed on all three while certified compliant.
Sources: Target Passed PCI Inspection Before Breach - Digital Transactions; Kill Chain Analysis of 2013 Target Breach - U.S. Senate; Target Hack Throwback - Portnox
6.3. Anthem (2015)
- Compliance status: Subject to HIPAA requirements as one of the largest health insurers in the U.S. Maintained compliance programs.
- Breach: Between December 2014 and January 2015, attackers stole electronic PHI for 78.8 million individuals — names, SSNs, medical IDs, addresses, DOBs, email addresses, employment information. Largest healthcare breach in U.S. history.
- Post-breach findings: OCR investigation found Anthem had failed to conduct an enterprise-wide risk analysis (the most fundamental HIPAA Security Rule requirement), had insufficient procedures to review system activity, failed to identify and respond to security incidents, and failed to implement adequate minimum access controls.
- Settlement: $16 million to HHS/OCR (record HIPAA settlement at the time) plus $48.2 million to state attorneys general.
- The gap: HIPAA’s Security Rule specifically requires risk analysis, access controls, and audit controls. Anthem failed on all of them while operating under HIPAA’s compliance framework. The compliance process did not catch these failures before the breach did.
Sources: Anthem Pays $16M Record HIPAA Settlement - HHS.gov; Anthem HIPAA Settlement - HIPAA Journal; Anthem State AG Settlement - HIPAA Journal
6.4. Equifax (2017)
- Compliance status: Held ISO 27001 certification (issued by EY CertifyPoint, accredited by RvA) since at least 2015. Also maintained PCI-DSS, SOC 1, SOC 2, and FISMA certifications.
- Breach: Unpatched Apache Struts vulnerability (CVE-2017-5638, public exploit available since March 2017). Attackers accessed 147.9 million Americans’ personal data including SSNs, birth dates, addresses, and driver’s license numbers.
- Post-breach: ISO 27001 certificates were suspended after the breach was publicized. Equifax subsequently worked to regain all certifications (PCI/ISO/SOC 1&2/FISMA), eventually obtaining 20 certifications post-breach.
- The gap: ISO 27001 requires vulnerability management and patch management as explicit controls (A.12.6). The vulnerability was public for months. The certification body certified Equifax’s ISMS as conformant while a known critical vulnerability sat unpatched on an internet-facing system.
Sources: Equifax Held ISO 27001 at Time of Hack - Oxebridge; Equifax Data Breach - Huntress
6.5. Marriott/Starwood (2014-2018)
- Compliance status: Marriott maintained PCI DSS compliance programs for payment card processing. Starwood’s systems were subject to PCI requirements prior to and after the 2016 acquisition.
- Breach: Attackers had access to Starwood’s guest reservation database from July 2014 through September 2018 — over four years. 339 million guest records exfiltrated, including 5.25 million unencrypted passport numbers. Credit card numbers were encrypted, but the encryption keys were stored on the same server.
- Detection failure: The breach was not discovered until September 2018, despite Marriott’s acquisition due diligence process in 2016.
- Regulatory action: FTC required Marriott to implement a “robust information security program” — an implicit acknowledgment that compliance frameworks had not produced one.
- The gap: PCI DSS covers encryption key management as an explicit requirement (Requirement 3). Storing encryption keys alongside the encrypted data is a textbook violation. Four years of undetected access means logging, monitoring, and incident detection (Requirements 10, 11, 12) were all failing.
Sources: Marriott Data Breach - Huntress; FTC Action Against Marriott - FTC; Marriott Data Breach FAQ - CSO Online
6.6. SolarWinds (2019-2020)
- Compliance status: SOC 2 Type 2 certified (2019 assessment — after the threat actors had already infiltrated the system). ISO 27001 certified. FedRAMP authorized for certain products.
- Breach: Russian SVR (Foreign Intelligence Service) compromised SolarWinds’ build system starting September 2019, injecting trojanized code into Orion software updates from February 2020 onward. ~18,000 customers received compromised updates, including multiple U.S. federal agencies (Treasury, Commerce, Homeland Security, etc.).
- SEC findings: The SEC charged SolarWinds and its CISO with fraud. The complaint revealed that only 6% of NIST controls had a defined program in place, and 61% had no program or practice at all — despite the company holding certifications that ostensibly verified these controls.
- The gap: This is the most damning case. The SOC 2 assessment was conducted while the build system was already compromised. The ISO 27001 certification was active. The FedRAMP authorization was in place. The SEC’s findings showed that the actual security posture bore almost no resemblance to what the compliance certifications attested. The auditors certified a fantasy.
Sources: SEC Charges SolarWinds; SolarWinds Hack Explained - TechTarget; 2020 U.S. Federal Government Data Breach - Wikipedia
7. Compliance Spending vs. Security Outcomes
The Industry’s Own Numbers
The compliance industry likes to cite studies showing correlation between compliance investment and reduced breach cost. The most commonly cited:
- Organizations with fully deployed security automation save ~$1.9 million per breach on average (IBM Cost of a Data Breach Report methodology).
- 78% of CISOs agree that cyber and privacy regulations help lower cyber risk.
Sources: 150+ Key Compliance Statistics for 2026 - Security Boulevard; 100+ Compliance Statistics 2025 - Sprinto
What Those Numbers Actually Show
The CISO survey is self-reporting by people whose budgets and career advancement depend on compliance spending. The IBM figure measures cost per breach (i.e., organizations with automation handle incidents more cheaply), not breach prevention. Neither metric addresses the fundamental question: does compliance spending reduce the probability of being breached?
The macro data answers that question clearly:
- Cybersecurity spending 2020-2025: Up ~43% ($150B to $215B)
- U.S. data compromises 2020-2025: Up ~79% (1,862 to 3,332)
- Compliance consulting market: Growing at 14.5% CAGR
- Compliance automation market: Growing at 15.6% CAGR
- Organizations fully PCI compliant: Declining (under 28% in 2019, down 8.8% YoY)
The compliance industry is growing faster than breaches are being prevented. The automation vendors are growing fastest of all — not by making organizations more secure, but by making it cheaper and faster to produce the documentation that certifies they are.
SecurityMetrics Finding
A 2020 SecurityMetrics study found that all weak points exploited by attackers in PCI compliance breaches were explicitly covered by the PCI DSS. The standard covered the attack vectors. The compliance process simply failed to verify that the controls were actually in place and functioning.
Source: PCI DSS and the Target Breach - PCIFree
46% Don’t Even Know
According to Kiteworks’ 2025 annual survey, 46% of companies don’t know their own breach frequency. They cannot tell you how often they’ve been breached. These are the same organizations paying for compliance certifications that attest to the adequacy of their security monitoring.
Source: Why 46% of Companies Don’t Know Their Breach Frequency - Kiteworks
Summary: The Numbers
| Metric | Value |
|---|---|
| Global cybersecurity compliance consulting market (2025) | ~$15.5 billion |
| Global compliance management platforms market (2025) | ~$2.66 billion |
| Global infosec spending (2025) | ~$213 billion |
| Vanta valuation | $4.15 billion |
| Drata valuation | $2 billion |
| Coalfire revenue | ~$210 million |
| SecurityScorecard revenue | ~$144 million |
| Vanta ARR | ~$220 million |
| Drata ARR | ~$98 million |
| Average SOC 2 total cost | $30K - $150K |
| Average PCI Level 1 assessment | $50K - $150K |
| Average HIPAA compliance | $80K - $120K |
| U.S. data breaches (2025) | 3,332 (record) |
| Organizations fully PCI compliant (2019) | <28% |
| Breached orgs fully PCI compliant at time of breach (Verizon, 2010-2016) | 0% |
The compliance industry generates tens of billions in annual revenue. The compliance automation vendors have collectively raised nearly a billion dollars and are valued at over $6 billion. Breach counts hit new records every year. The money flows in one direction; the security does not flow in any direction at all.
Source URLs
- PCI DSS — Wikipedia
- SOC 2 — Wikipedia
- Target Data Breach — Wikipedia
- Equifax Data Breach — Wikipedia
- SolarWinds Hack — Wikipedia
- SEC Charges SolarWinds — SEC.gov
- Marriott Data Breach — Wikipedia
- Capital One Data Breach — Wikipedia
- FTC Action Against Marriott — FTC
- Vanta — Crunchbase
- Drata — Crunchbase
- IBM Cost of a Data Breach Report 2024
- Identity Theft Resource Center 2024 Annual Data Breach Report
Prefer RSS? Subscribe here.