Market size, audit costs, breach-after-compliance case studies, and the gap between spending and outcomes.
Contents 35 sections

1. Market Size: The Compliance Industrial Complex

Global Cybersecurity Spending

Global information security spending has been growing at double-digit rates every year, with no corresponding decline in breaches:

YearGlobal InfoSec Spending (Gartner)YoY Growth
2023$188.1 billion11.3%
2024$215 billion14.3%
2025$213 billion (forecast)15.1%
2026$240 billion (forecast)12.5%

Source: Gartner Forecasts Global Information Security Spending to Grow 15% in 2025; Gartner Forecasts Worldwide End-User Spending on Information Security to Total $213 Billion in 2025

IDC independently forecast worldwide security investments at $187.5 billion in 2023 and $211.4 billion in 2024 (12.1% annual growth), with a further 12.2% increase in 2025.

Source: IDC: Worldwide Security Spending to Increase by 12.2% in 2025

Compliance Services Market (Subset)

The cybersecurity compliance consulting market alone was estimated at approximately $15.5 billion in 2025, projecting a CAGR of 14.5% through 2033.

Source: Cybersecurity Compliance Consulting Market 2025-2033

The compliance management platforms market (software, not services) was valued at $2.66 billion in 2025, projected to reach $8.5 billion by 2033 (CAGR 15.6%).

Source: Cybersecurity Compliance Management Platforms Market 2026-2033

Framework Adoption Rates (2025)

Over 68% of large U.S. enterprises now operate centralized compliance platforms covering SOC 2, ISO 27001, HIPAA, PCI DSS, and FedRAMP. Framework adoption among companies pursuing compliance:

  • SOC 2: 76%
  • Penetration testing: 74%
  • SOC 1: 70%
  • ISO 27001: 67% (20%+ year-over-year growth in certifications)
  • HIPAA: 63%

Source: 280+ Cybersecurity Compliance Statistics for 2026


2. Revenue of Major Compliance/Audit Firms

Traditional Audit Firms

FirmEst. RevenueEmployeesClientsNotes
Coalfire~$210M1,000-5,0001,800+Includes 8 of top 10 SaaS providers. 31 locations. New CEO Jan 2026.
SchellmanNot publicly disclosed800+Top 50 CPA firm. 36 S&P 500 clients. Founded 2002 (Tampa).
A-LIGNNot publicly disclosed2,500+#1 issuer of SOC 2 and HITRUST. Top 3 FedRAMP assessor. $54.5M total funding (Hg, FTV Capital). Founded 2009 (Tampa).

Sources: Coalfire - Owler; Coalfire - ZoomInfo; Schellman - CB Insights; A-LIGN - Crunchbase; A-LIGN - GrowJo

SecurityScorecard (Ratings/Risk)

  • Revenue: $144.3M (Oct 2024), up from $106M (Oct 2023), $88.5M (Nov 2022), $71M (Nov 2021)
  • Valuation: $1B (Series E, March 2021); one estimate puts current valuation at ~$360M
  • Total funding: $293M (Sequoia, Intel Capital, GV)
  • Customers: 2,600 (including 70% of Fortune 1000)

Sources: SecurityScorecard Revenue - Latka; SecurityScorecard Growth Playbook; SecurityScorecard 2024 Momentum


3. The Compliance Automation Market

Three startups have raised over $850 million combined to automate the process of proving you checked the boxes.

Vanta

  • Valuation: $4.15B (Series D, July 2025 — led by Wellington Management)
  • ARR: ~$220M (July 2025), up from $152M (end 2024)
  • Customers: 12,000 (July 2025), up from 7,000 (end FY24), 4,000 (2022)
  • Total funding: $150M+ (Series D alone)

Source: Vanta Revenue, Valuation & Funding - Sacra

Drata

  • Valuation: $2B (Series C, co-led by ICONIQ Growth and GGV Capital)
  • ARR: ~$98M (Jan 2025), up from $59M (2023) — 61% YoY growth
  • Revenue: $100M (Feb 2025)
  • Customers: 7,000 (55% YoY growth)
  • Total funding: $328.2M

Sources: Drata Revenue - Sacra; Drata Revenue - Latka; Drata Series C Announcement

Secureframe

  • Valuation: $294-350M (Jan 2022, last disclosed)
  • Revenue: $6M (Oct 2024), up from $4.7M (Dec 2023)
  • Total funding: $79M (Kleiner Perkins, Base10, Gradient Ventures)

Sources: Secureframe Revenue - Latka; Secureframe - Crunchbase

What “Compliance Automation” Actually Automates

Vanta runs 1,200+ automated hourly tests via integrations, collecting evidence and mapping controls to frameworks. The pitch is that it replaces spreadsheets and screenshot folders.

What it actually does: semi-automated evidence collection, integrations with cloud infrastructure/ticketing/code repos, auto-generated Statements of Applicability, and continuous monitoring dashboards.

What it does not do: evidence collection is only semi-automated — some tasks still require manual uploads and confirmations (scored 7/10 for automation depth in independent reviews). The platform loses effectiveness at scale, with growing friction, limited report depth, and inflexible workflows. Onboarding is described as “hands-off” and the automation as “shallow.”

Source: Honest Vanta Review - Sprinto; Compliance Tools That Outperform Vanta and Drata

The fundamental criticism: these tools automate the paperwork of compliance, not the security of compliance. They make it faster and cheaper to produce the documentation an auditor wants to see. Whether any of that documentation reflects actual security posture is a separate question entirely.


4. Cost to Organizations of Achieving/Maintaining Compliance

SOC 2

ComponentCost Range
SOC 2 Type 1 audit (small-mid)$7,500 - $15,000
SOC 2 Type 1 audit (large org)Up to $60,000+
SOC 2 Type 2 audit$7,000 - $50,000
Total SOC 2 certification (2026)$30,000 - $150,000
Readiness assessment~$15,000
Security awareness training~$2,500
Implementation/toolingUp to $30,000

Sources: SOC 2 Certification Cost 2026 - CyberArrow; SOC 2 Budget - StrongDM; SOC 2 Audit Cost - Secureframe; SOC 2 Audit Cost - Drata

PCI DSS

Compliance LevelTransaction VolumeCost Range
Level 1>6M transactions/year$50,000 - $150,000
Level 21-6M transactions/year$10,000 - $50,000
Level 3 & 4<1M transactions/year$1,000 - $10,000
QSA engagement (full ROC)$30,000 - $200,000
Self-Assessment Questionnaire$5,000 - $20,000
Quarterly vulnerability scans$2,000 - $8,000/year
Annual penetration testing$20,000 - $60,000

Sources: PCI DSS Compliance Cost 2025 - Centraleyes; PCI DSS Certification Cost 2026 - Sprinto; PCI DSS Audit Cost - Thoropass

ISO 27001

  • Certification audit: $10,000 - $50,000 on average
  • Typically 1.5x to 2x the cost of SOC 2 due to heavier documentation requirements (proving a compliant ISMS)
  • Total cost including implementation: significantly higher

Source: SOC 2 vs ISO 27001 - Secureframe

HIPAA

  • Overall compliance costs (mid-range): $80,000 - $120,000
  • Internal HIPAA audit: $1,000 - $5,000
  • External readiness assessment: $15,000 - $40,000
  • External audit (small entity, <50 employees): $10,000 - $50,000
  • HITRUST certification: $15,000 - $200,000+
  • Technology upgrades: $20,000 - $50,000+ (initial implementation)

Sources: HIPAA Compliance Costs 2025 - Secureframe; HIPAA Compliance Cost 2026 - Compyl; HIPAA Compliance Cost - HIPAA Journal


5. Growth Rate of Compliance Industry vs. Actual Breach Reduction

This is where the security theater argument becomes undeniable.

Cybersecurity Spending: Up, Up, Up

Global infosec spending grew from ~$150 billion (2021) to ~$215 billion (2024) — a roughly 43% increase in three years.

Source: Gartner figures above.

Breaches: Also Up, Up, Up

YearU.S. Data CompromisesNotes
2020~1,862Baseline for comparison
2021~1,862Similar level
2022~1,802Slight dip
20233,205Record year — 78% jump
20243,158Sustained high
20253,332New record — 79% increase over 2020

Sources: Data Breach Statistics - Varonis; U.S. Data Compromises Hit Record in 2025 - HIPAA Journal; Data Breach Statistics 2026 - Bright Defense

The industry spent 43% more money and got 79% more breaches. Compliance spending went up. Breach counts went up. The correlation between the two is, at best, zero. The compliance industry’s product is not security — it is the appearance of security, sold at scale.

Verizon’s Damning Finding

Verizon’s forensics team, which has investigated nearly 300 payment card breaches between 2010 and 2016, has never found a single organization that was fully PCI DSS compliant at the time it was breached. This is frequently cited as evidence that compliance works — “they weren’t actually compliant!” — but it equally demonstrates that the compliance process itself fails to produce compliant organizations. If the audit says you pass and you’re not actually secure, the audit is the problem.

As of 2019, less than 28% of organizations were fully PCI DSS compliant — an 8.8% drop from the prior year. Only 8.4% of breached organizations had PCI Requirement 10 (track and monitor access) in place at time of breach.

Sources: Verizon 2024 Payment Security Report; PCI Compliance Declining - eWeek; Verizon Report: Businesses Not Fully PCI-Compliant - Dark Reading


6. Breach-After-Compliance Case Studies

Six well-documented cases where organizations held compliance certifications and were breached through the exact surfaces those certifications were supposed to cover.

6.1. Heartland Payment Systems (2008-2009)

  • Compliance status: Certified PCI DSS compliant by their QSA (Qualified Security Assessor) two weeks before the compromise.
  • Breach: SQL injection attack on the company website led to malware on the payment processing network. Attackers exfiltrated payment card data for approximately 130 million cards.
  • Detection failure: Three separate forensics firms hired by Heartland analyzed the network and declared it malware-free. Heartland’s own staff finally found the malware in January 2009.
  • Impact: Stock price fell 78%. 5,000 of 250,000 merchants left.
  • The gap: The QSA assessment was a point-in-time snapshot. The SQL injection — a basic web application vulnerability — was within PCI DSS scope. The compliance process certified the system as secure while malware was already present.

Sources: Heartland PCI Case Study - Secureworks; 5 Biggest PCI Compliance Breaches - GoAnywhere

6.2. Target (2013)

  • Compliance status: PCI DSS certified as of September 2013, per CFO testimony.
  • Breach: Attackers compromised Fazio Mechanical Services (an HVAC contractor with network access), pivoted to Target’s network, and installed malware on point-of-sale systems. 40 million payment card numbers and 70 million customer records stolen.
  • Detection failure: Target had deployed FireEye (advanced threat detection). It generated alerts. The security team forwarded them to the operations team. Nobody acted.
  • Cost: $18.5M state AG settlement. $292M total breach cost (Target’s reported figure).
  • The gap: PCI DSS explicitly covers network segmentation, third-party access controls, and intrusion detection. Target failed on all three while certified compliant.

Sources: Target Passed PCI Inspection Before Breach - Digital Transactions; Kill Chain Analysis of 2013 Target Breach - U.S. Senate; Target Hack Throwback - Portnox

6.3. Anthem (2015)

  • Compliance status: Subject to HIPAA requirements as one of the largest health insurers in the U.S. Maintained compliance programs.
  • Breach: Between December 2014 and January 2015, attackers stole electronic PHI for 78.8 million individuals — names, SSNs, medical IDs, addresses, DOBs, email addresses, employment information. Largest healthcare breach in U.S. history.
  • Post-breach findings: OCR investigation found Anthem had failed to conduct an enterprise-wide risk analysis (the most fundamental HIPAA Security Rule requirement), had insufficient procedures to review system activity, failed to identify and respond to security incidents, and failed to implement adequate minimum access controls.
  • Settlement: $16 million to HHS/OCR (record HIPAA settlement at the time) plus $48.2 million to state attorneys general.
  • The gap: HIPAA’s Security Rule specifically requires risk analysis, access controls, and audit controls. Anthem failed on all of them while operating under HIPAA’s compliance framework. The compliance process did not catch these failures before the breach did.

Sources: Anthem Pays $16M Record HIPAA Settlement - HHS.gov; Anthem HIPAA Settlement - HIPAA Journal; Anthem State AG Settlement - HIPAA Journal

6.4. Equifax (2017)

  • Compliance status: Held ISO 27001 certification (issued by EY CertifyPoint, accredited by RvA) since at least 2015. Also maintained PCI-DSS, SOC 1, SOC 2, and FISMA certifications.
  • Breach: Unpatched Apache Struts vulnerability (CVE-2017-5638, public exploit available since March 2017). Attackers accessed 147.9 million Americans’ personal data including SSNs, birth dates, addresses, and driver’s license numbers.
  • Post-breach: ISO 27001 certificates were suspended after the breach was publicized. Equifax subsequently worked to regain all certifications (PCI/ISO/SOC 1&2/FISMA), eventually obtaining 20 certifications post-breach.
  • The gap: ISO 27001 requires vulnerability management and patch management as explicit controls (A.12.6). The vulnerability was public for months. The certification body certified Equifax’s ISMS as conformant while a known critical vulnerability sat unpatched on an internet-facing system.

Sources: Equifax Held ISO 27001 at Time of Hack - Oxebridge; Equifax Data Breach - Huntress

6.5. Marriott/Starwood (2014-2018)

  • Compliance status: Marriott maintained PCI DSS compliance programs for payment card processing. Starwood’s systems were subject to PCI requirements prior to and after the 2016 acquisition.
  • Breach: Attackers had access to Starwood’s guest reservation database from July 2014 through September 2018 — over four years. 339 million guest records exfiltrated, including 5.25 million unencrypted passport numbers. Credit card numbers were encrypted, but the encryption keys were stored on the same server.
  • Detection failure: The breach was not discovered until September 2018, despite Marriott’s acquisition due diligence process in 2016.
  • Regulatory action: FTC required Marriott to implement a “robust information security program” — an implicit acknowledgment that compliance frameworks had not produced one.
  • The gap: PCI DSS covers encryption key management as an explicit requirement (Requirement 3). Storing encryption keys alongside the encrypted data is a textbook violation. Four years of undetected access means logging, monitoring, and incident detection (Requirements 10, 11, 12) were all failing.

Sources: Marriott Data Breach - Huntress; FTC Action Against Marriott - FTC; Marriott Data Breach FAQ - CSO Online

6.6. SolarWinds (2019-2020)

  • Compliance status: SOC 2 Type 2 certified (2019 assessment — after the threat actors had already infiltrated the system). ISO 27001 certified. FedRAMP authorized for certain products.
  • Breach: Russian SVR (Foreign Intelligence Service) compromised SolarWinds’ build system starting September 2019, injecting trojanized code into Orion software updates from February 2020 onward. ~18,000 customers received compromised updates, including multiple U.S. federal agencies (Treasury, Commerce, Homeland Security, etc.).
  • SEC findings: The SEC charged SolarWinds and its CISO with fraud. The complaint revealed that only 6% of NIST controls had a defined program in place, and 61% had no program or practice at all — despite the company holding certifications that ostensibly verified these controls.
  • The gap: This is the most damning case. The SOC 2 assessment was conducted while the build system was already compromised. The ISO 27001 certification was active. The FedRAMP authorization was in place. The SEC’s findings showed that the actual security posture bore almost no resemblance to what the compliance certifications attested. The auditors certified a fantasy.

Sources: SEC Charges SolarWinds; SolarWinds Hack Explained - TechTarget; 2020 U.S. Federal Government Data Breach - Wikipedia


7. Compliance Spending vs. Security Outcomes

The Industry’s Own Numbers

The compliance industry likes to cite studies showing correlation between compliance investment and reduced breach cost. The most commonly cited:

  • Organizations with fully deployed security automation save ~$1.9 million per breach on average (IBM Cost of a Data Breach Report methodology).
  • 78% of CISOs agree that cyber and privacy regulations help lower cyber risk.

Sources: 150+ Key Compliance Statistics for 2026 - Security Boulevard; 100+ Compliance Statistics 2025 - Sprinto

What Those Numbers Actually Show

The CISO survey is self-reporting by people whose budgets and career advancement depend on compliance spending. The IBM figure measures cost per breach (i.e., organizations with automation handle incidents more cheaply), not breach prevention. Neither metric addresses the fundamental question: does compliance spending reduce the probability of being breached?

The macro data answers that question clearly:

  • Cybersecurity spending 2020-2025: Up ~43% ($150B to $215B)
  • U.S. data compromises 2020-2025: Up ~79% (1,862 to 3,332)
  • Compliance consulting market: Growing at 14.5% CAGR
  • Compliance automation market: Growing at 15.6% CAGR
  • Organizations fully PCI compliant: Declining (under 28% in 2019, down 8.8% YoY)

The compliance industry is growing faster than breaches are being prevented. The automation vendors are growing fastest of all — not by making organizations more secure, but by making it cheaper and faster to produce the documentation that certifies they are.

SecurityMetrics Finding

A 2020 SecurityMetrics study found that all weak points exploited by attackers in PCI compliance breaches were explicitly covered by the PCI DSS. The standard covered the attack vectors. The compliance process simply failed to verify that the controls were actually in place and functioning.

Source: PCI DSS and the Target Breach - PCIFree

46% Don’t Even Know

According to Kiteworks’ 2025 annual survey, 46% of companies don’t know their own breach frequency. They cannot tell you how often they’ve been breached. These are the same organizations paying for compliance certifications that attest to the adequacy of their security monitoring.

Source: Why 46% of Companies Don’t Know Their Breach Frequency - Kiteworks


Summary: The Numbers

MetricValue
Global cybersecurity compliance consulting market (2025)~$15.5 billion
Global compliance management platforms market (2025)~$2.66 billion
Global infosec spending (2025)~$213 billion
Vanta valuation$4.15 billion
Drata valuation$2 billion
Coalfire revenue~$210 million
SecurityScorecard revenue~$144 million
Vanta ARR~$220 million
Drata ARR~$98 million
Average SOC 2 total cost$30K - $150K
Average PCI Level 1 assessment$50K - $150K
Average HIPAA compliance$80K - $120K
U.S. data breaches (2025)3,332 (record)
Organizations fully PCI compliant (2019)<28%
Breached orgs fully PCI compliant at time of breach (Verizon, 2010-2016)0%

The compliance industry generates tens of billions in annual revenue. The compliance automation vendors have collectively raised nearly a billion dollars and are valued at over $6 billion. Breach counts hit new records every year. The money flows in one direction; the security does not flow in any direction at all.


Source URLs