95+ Cybersecurity Compliance Statistics for 2026: Breach Costs, GDPR and HIPAA Fines, Framework Adoption and AI
Published on
September 21, 2026
/
updated on
September 21, 2026

Numbered, sourced cybersecurity compliance statistics for 2026: how compliance is changing, what it costs, what regulators enforce and where programs fall short.
Cybersecurity compliance statistics for 2026 show what non-compliance costs, what regulators enforce and how far programs still have to go. Non-compliance with regulations added an average of $201,112 to the cost of a breach in IBM's 2026 report (1). EU and European Economic Area (EEA) data protection authorities issued €1,145,760,374 in General Data Protection Regulation (GDPR) fines in 2025 (2). In the United States, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) initiated no HIPAA audits in 2024 "due to a lack of financial resources" (3).
The compliance facts below are for compliance leads, chief information security officers (CISOs) and founders preparing for SOC 2, ISO 27001, HIPAA, the Payment Card Industry Data Security Standard (PCI DSS), Cybersecurity Maturity Model Certification (CMMC) or GDPR, grouped by the state of compliance, costs, frameworks, enforcement, budgets and staffing, then automation and AI. Each figure links to the report or regulator that published it, so it can go straight into a budget request, an audit file or a board deck.
Top cybersecurity compliance stats for 2026
- The global average cost of a data breach reached $4.99 million in IBM's 2026 Cost of a Data Breach Report, 12% more than the year before and a record high (1).
- Non-compliance with regulations added an average of $201,112 to the cost of a breach in IBM's 2026 report, measured as the difference from the $4.99 million global average (1).
- 85% of the 1,802 executives in PwC's 2025 Global Compliance Survey said compliance requirements have become more complex in the last three years (4).
- Breaches with third-party involvement reached 48% of all breaches in Verizon's 2026 Data Breach Investigations Report, up 60% from the previous year's dataset (5).
- OCR initiated no HIPAA audits in 2024 "due to a lack of financial resources", per its Annual Report to Congress for 2024 (3).
- Business associates filed 16% of the reports of large HIPAA breaches that occurred in 2024, and those breaches accounted for 85% of all affected individuals, 206,921,071 people, per OCR's 2024 breach report to Congress (6).
- EU and EEA data protection authorities issued €1,145,760,374 in GDPR fines in 2025, per the European Data Protection Board's Annual Report 2025 (2).
- The HIPAA regulation caps civil money penalties for identical violations due to willful neglect not corrected within 30 days at $2,190,294 per calendar year, as adjusted by HHS on 28 January 2026 (7, 8). HHS says its enforcement actions follow the penalty tiers of its April 2019 notice of enforcement discretion (9).
- The Justice Department recovered over $52 million in nine cybersecurity fraud settlements under the False Claims Act in fiscal year 2025 (10).
- 14.3% of organizations achieved full PCI DSS compliance at interim validation in 2023, per Verizon's 2024 Payment Security Report (11).
- The ISO Survey 2024 recorded 96,709 valid ISO/IEC 27001 certificates covering 179,877 sites worldwide (12).
- Nearly 2,000 defense contractors were certified at CMMC Level 2 (Final) as of 15 July 2026, according to The Cyber AB (13).
- 70% of organizations in the NIS Investments 2025 study by the European Union Agency for Cybersecurity (ENISA) named regulatory compliance as the main driver of their cybersecurity investment (14).
- 55% of cybersecurity teams are understaffed, per ISACA's State of Cybersecurity 2025 (15).
- 59% of governance, risk and compliance (GRC) practitioners use no commercial GRC tool at all, per GRC Engineer's State of GRC 2026, a survey of 795 responses that it describes as independent (16).
Methodology and sources
- IBM, Cost of a Data Breach Report 2026, whose year label is the publication year, not necessarily the breach year (1)
- Verizon, 2026 Data Breach Investigations Report and 2024 Payment Security Report
- European Data Protection Board, Annual Report 2025
- HHS Office for Civil Rights, Reports to Congress for 2020 to 2024
- ENISA, NIS Investments 2025
Two of the surveys come from compliance software vendors: NAVEX's 2026 State of Risk & Compliance, a survey of nearly 1,200 risk and compliance leaders, and Hyperproof's 2026 IT Risk and Compliance Benchmark Report, a survey of 1,002 respondents, fielded in November and December 2025 (17, 18). Sources were checked from 10 to 15 September 2026.
The state of compliance in 2026
- 85% of the 1,802 executives in PwC's 2025 Global Compliance Survey said compliance requirements have become more complex in the last three years (4).
"Compliance is not just about passing audits. Compliance now requires instrumentation and mechanisms to ensure your obligations, to your customers, are being met ..." Anil Markose, Chief Compliance Officer, Oracle SaaS, in PwC's 2025 Global Compliance Survey (19).
- 51% of PwC's 2025 respondents ranked cybersecurity among their top five compliance risk priorities, and 51% ranked data protection and privacy there (4).
- 70% of organizations in ENISA's NIS Investments 2025 study named regulatory compliance, with EU frameworks such as the NIS2 Directive, as the main driver of their cybersecurity investment over the past year (14).
- Nearly half of the same organizations (45%) named improved regulatory compliance as a key outcome of that investment, per ENISA's NIS Investments 2025 (14).
- In the Thomson Reuters Institute's 2025 C-Suite Survey, 68% of C-suite leaders rated time-consuming compliance and reporting tasks as a moderate (50%) or significant (18%) constraint on their enabling functions, departments such as customer success, technology and operations (20). Only 17% of the C-suite leaders surveyed saw simplified compliance as the most important opportunity for improvement, per the survey's press release (21).
- NAVEX, which sells compliance software, found in its 2026 State of Risk & Compliance survey of nearly 1,200 risk and compliance leaders that 47% describe compliance programs as a "necessary evil" that can inhibit business (17).
Compliance maturity and readiness gaps
- Just 7% of PwC's 2025 respondents consider their company to be leading in compliance and 31% classify it as mature, yet 84% aim to be leading or mature within three years (4).
- 91% of respondents to the Privacy Governance Report 2024 from the International Association of Privacy Professionals (IAPP) said they were at least somewhat confident their organization can comply with privacy regulatory requirements, while 99% reported facing challenges delivering privacy compliance (22).
- In ISACA's State of Privacy 2026 report, published in January 2026, 46% of respondents said they are very or completely confident in their privacy team's ability to achieve compliance with new privacy laws and regulations (23).
Third-party and vendor risk statistics
- Breaches with third-party involvement rose 60% from the previous year's dataset and reached 48% of all breaches in Verizon's 2026 Data Breach Investigations Report (DBIR) (5).
- Business associates filed 16% of the reports of breaches affecting 500 or more individuals that occurred in 2024, and those breaches accounted for 85% of all affected individuals, 206,921,071 in total, per the HHS Office for Civil Rights' report to Congress for 2024 (6).
- Third-party involvement featured in 32% of breaches at healthcare organizations in the 2026 DBIR (5).
- 90% of the organizations in ENISA's NIS Investments 2025 study said they implement specific controls for third-party and supply chain security (14).
Table 1: The most common third-party and supply chain security measures, 2025. Source: ENISA. (14)

- Despite those controls, supply chain and third-party attacks were the second most frequently cited top concern for the future (47%) among the organizations in ENISA's 2025 study (14).
- 34% of respondents were still using spreadsheets to identify and manage third-party risks in Hyperproof's 2026 IT Risk and Compliance Benchmark Report, a compliance software vendor's survey of 1,002 respondents, fielded in November and December 2025 (18).
- Only 23% of third-party organizations fully remediated missing or improperly secured multifactor authentication (MFA) on their cloud accounts, per the 2026 DBIR (5).
For a buyer, that is a reason to ask vendors how quickly they fix what an assessment finds, not only which certificates they hold.
The cost of compliance vs. the cost of non-compliance
Compliance carries two price tags: the budget a program needs to run, and what an incident costs when controls fail.
- Cybersecurity accounted for 9% of total IT budgets in 2024, with a median cybersecurity spend of €1.5 million, among the organizations in ENISA's NIS Investments 2025 study (14).
- NAVEX, which sells compliance software, found in its 2026 State of Risk & Compliance survey of nearly 1,200 risk and compliance leaders that each step up in self-assessed program maturity came with twice the budget of the previous level (17).
- In its CMMC acquisition rule of 10 September 2025, the Department of Defense (DoD) put the rule's cost to the public at a present value of $329,097,922 over 10 years, or $38,580,316 annualized, at a 3% discount rate (24).
Breach and non-compliance costs
- The global average cost of a data breach reached $4.99 million in IBM's 2026 Cost of a Data Breach Report, a record high and 12% more than the year before, driven largely by detection, escalation and lost business costs (1).
"AI is making attacks faster and cheaper, while breaches keep getting more expensive. When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs." Suja Viswesan, VP, IBM Security Software, on the 2026 report (25).
- Non-compliance with regulations added an average of $201,112 to the cost of a breach in IBM's 2026 report, measured as the difference from the $4.99 million global average (1).
- Business email compromise and funds transfer fraud accounted for 58% of the cyber incidents Coalition observed in 2025, with business email compromise claims rising 15% in frequency while their severity fell 28% to an average loss of $27,000, per its 2026 report (26).
- Coalition's global claims severity fell 19% in 2025 to an average loss of $116,000, while its claims frequency rose 3%, per its 2026 Cyber Claims Report, which draws on data from Coalition's more than 100,000 policyholders (26).
- 64% of the closed claims Coalition received in 2025 were resolved with no out-of-pocket loss for the policyholder, per Coalition's 2026 Cyber Claims Report (26).
- In Coalition's claims data for 2025, initial ransom demands rose 47%, and 86% of the businesses in that data refused to pay, while ransomware claims carried an average loss of $269,000, per Coalition's 2026 Cyber Claims Report (26).
- Losses reported to the FBI's Internet Crime Complaint Center (IC3) reached $20.877 billion in 2025 across 1,008,597 complaints, 26% more in losses than in 2024 (27).
- Cyber-enabled fraud accounted for 452,868 of those complaints and $17,697,074,980 in losses in 2025, 45% of all complaints and 85% of all losses, per the IC3's 2025 report (27).
The three sets of figures measure different things in different populations: IBM's $4.99 million in its 2026 report is the average cost of a breach among the organizations it studied, all of them breached (1); Coalition's $116,000 for 2025 is the average loss on the claims its policyholders made after security incidents (26); and the IC3's 2025 totals are the losses victims reported to it (27).
Learn more: the CMMC certification cost guide covers what drives a defense contractor's budget.
Breach response, recovery and remediation times
- The mean time organizations took to identify and contain a breach rose to 247 days in IBM's 2026 report, a 2.5% uptick that reversed a five-year decline; of those days, 183 went to identifying the breach and 64 to containing it (1).
- Among the organizations in IBM's 2026 report that fully recovered from a breach, 4%, fewer than one in 20, did so in less than 50 days, while the share that needed more than 150 days shrank to 19% from 26% a year earlier (1). IBM's definition of a full recovery includes the condition that "Organizations have met compliance obligations, such as paying fines" (1).
- 28% of the organizations in ENISA's NIS Investments 2025 study take more than three months to patch critical vulnerabilities (14).
Cybersecurity compliance statistics by framework
HIPAA compliance statistics
OCR enforces HIPAA compliance and reports to Congress each year on breaches of unsecured protected health information (3, 6).
- Hacking/IT incidents were the largest category of breaches affecting 500 or more individuals that occurred in 2024, at 81% of those breaches, and they affected 241,582,022 individuals, per OCR's 2024 breach report to Congress (6).
- The largest hacking breach reported for 2024 involved approximately 192,000,000 individuals, per OCR's 2024 breach report to Congress (6).
- Health care providers filed 505 (76%) of the reports of large breaches that occurred in 2024, affecting 34,456,670 individuals (14% of all affected individuals), and health plans filed 50 (8%), affecting 1,303,493 individuals (1%) (6).
- OCR also received 74,299 reports of breaches affecting fewer than 500 individuals that occurred in 2024, which together affected 340,618 individuals (6).
- In its 2024 breach investigations, OCR named five Security Rule areas as key areas for improvement: risk analysis, risk management, information system activity review, audit controls and person or entity authentication (6).
- Healthcare recorded the highest average breach cost of any industry for the 13th consecutive year, $6.64 million, which IBM's 2026 Cost of a Data Breach Report states is down 10.5% from $7.42 million a year earlier (1).
- OCR's report to Congress for 2024 states: "For the 28,228 complaints that OCR resolved in 2024, the top five issues alleged were Impermissible Uses and Disclosures (660 complaints), Right of Access (541 complaints), General Safeguards (481 complaints), Administrative Safeguards (Security Rule) (147 complaints), and Breach-Notice to Individuals (122 complaints)" (3).
The notification clock runs from discovery, not from the breach itself: a breach is treated as discovered on the first day it is known, or would have been known with reasonable diligence, per section 164.404 of Title 45 of the Code of Federal Regulations (45 CFR 164.404), as current in September 2026 (28). Except as provided in 45 CFR 164.412, notice to individuals is then due without unreasonable delay and in no case later than 60 calendar days after discovery (28).
Section 164.412, as current in September 2026, is the law enforcement delay: if a law enforcement official states that a notice would impede a criminal investigation or cause damage to national security, the notice is delayed for the period the official specifies in writing, or, after an oral statement, for no longer than 30 days unless a written statement follows (29).
For a covered entity or a business associate, the five areas OCR names make a ready checklist for the next risk analysis.
CMMC and NIST SP 800-171 compliance statistics
The security requirements for CMMC compliance at Level 2 are identical to those in National Institute of Standards and Technology (NIST) SP 800-171 Revision 2 (30).
- 32 CFR 170.4, as current in September 2026, counts 15 Level 1, 110 Level 2 and 24 Level 3 CMMC security requirements (30).
- DoD estimated that 337,968 unique entities, prime contractors and subcontractors, will be affected by the CMMC acquisition requirements, in its Defense Federal Acquisition Regulation Supplement (DFARS) final rule of 10 September 2025 (24).
- DoD estimated that 229,818 of the 337,968 entities its 2025 DFARS final rule will affect, 68%, are small entities (24).
- DoD estimated the number of small entities its 2025 DFARS final rule would apply to in each year of the three-year phase-in at 1,104 in year one, 5,565 in year two and 18,554 in year three, and at 229,818 from year four on (24).
- Nearly 2,000 defense contractors were certified at CMMC Level 2 (Final) as of 15 July 2026, according to The Cyber AB, the program's accreditation body (13).
Table 2: The CMMC ecosystem as of 15 July 2026. Source: The Cyber AB. (13)
The CMMC Phase II suspension
The Department of War (a secondary title of the Department of Defense under Executive Order 14347) suspended CMMC Phase II requirements on 13 July 2026 (31, 32).
- Phase I of CMMC implementation began on 10 November 2025, when the revised DFARS clause 252.204-7021 took effect (33). The CMMC page of the Department's Chief Information Officer (CIO) states that "All Phase I self-assessment requirements remain firmly in place", while the November 2026 transition to Phase II is suspended (31, 34).
- While the suspension lasts, program managers and requiring activities must include only CMMC Level 1 (Self) or Level 2 (Self) assessment requirements, and may not designate CMMC Level 2 (C3PAO) or Level 3 (Defense Industrial Base Cybersecurity Assessment Center, DIBCAC) assessments (34).
- Where a requirements package already carried a Level 2 (C3PAO) or Level 3 (DIBCAC) requirement, active solicitations are to be amended to remove it, and contracting officers are directed to remove it from existing contracts by modification prior to the exercise of the next option period or during the next scheduled administrative modification (34).
- The Department will meanwhile enforce baseline compliance with NIST SP 800-171 Revision 2 through Level 1 and Level 2 self-assessments and select government-led assessments, and the requirements of DFARS 252.204-7012 remain in effect (34).
"This directive is effective immediately. Further guidance will be promulgated at the conclusion of the CIO's 60-day review." Department of War, closing the CMMC procedures memorandum's section on waiver procedures, cleared 13 July 2026 (34).
- A class deviation to DFARS clause 252.204-7012 keeps NIST SP 800-171 Revision 2 as the standard against which defense industrial base companies are assessed, until Revision 3 is incorporated into the 32 CFR CMMC Program rule through rulemaking, per the Department's July 2026 CMMC FAQ (33).
- On 15 July 2026, The Cyber AB acknowledged the Department's announcement and stated that only the Phase II implementation requirements had been suspended and that C3PAO Level 2 certification assessments remained operational and available (13).
"NIST SP 800-171 and DFARS 7012 requirements remain in place and unchanged for most all [sic] contractors." Matthew Travis, Chief Executive Officer, The Cyber AB, 15 July 2026 (13).
For a defense contractor, the practical reading is that the requirement to pass a third-party assessment is paused, while the NIST SP 800-171 obligations behind it are not.
Learn more: the CMMC compliance guide explains the levels and the certification process.
PCI compliance statistics
Verizon's Payment Security Report measures how many organizations reach full PCI DSS compliance at interim validation; its 2024 edition is current as of September 2026 (11, 35).
- 14.3% of organizations achieved 100% PCI DSS compliance at interim validation in 2023, which the report calls full compliance, per Verizon's 2024 Payment Security Report (11).
"During the lifetime of PCI DSS v3.2.1, fewer than half of organizations demonstrated that they developed and maintained a robust, sustainable PCI security program that enabled them to rapidly detect and correct controls that are not in place." Verizon, 2024 Payment Security Report (11).
- The overall control gap across the 12 PCI DSS key requirements was 4.5% in 2023, down from a high of 7.7% in 2019 over the lifetime of PCI DSS v3.x, per the same report (11).
- Requirement 11 (security testing of systems and networks) had the largest control gap in 2023, followed by Requirements 6 (secure systems and software), 10 (logging and monitoring of access) and 2 (secure configurations), per the 2024 report (11).
For a merchant or service provider, the distance between passing a validation and staying compliant until the next one is what to plan for.
SOC 2 compliance statistics
A SOC 2 compliance report covers controls relevant to security, availability, processing integrity, confidentiality or privacy, per the American Institute of CPAs (AICPA) (36).
- In the AICPA's 2020 survey, sent to more than 400 firms and answered by 74, the SOC 2 examinations counted in the survey rose from 1,064 in 2018 to 1,587 in 2020, which the AICPA describes as a 49% increase in demand for SOC 2 engagements (37).
For a service organization, those figures count SOC 2 examinations at the firms that answered the survey, not across the whole SOC 2 market.
The Trust Services Criteria and the Type 1 and Type 2 reports are covered in the explainer on what a SOC 2 report is.
ISO 27001 compliance statistics
For ISO 27001 compliance, the count to cite comes from ISO's annual survey of the valid certificates that accredited certification bodies report (12):
- The ISO Survey 2024 recorded 96,709 valid ISO/IEC 27001 certificates covering 179,877 sites worldwide (12).
- In 2024, 76 of the 77 accreditation bodies took part in IAF CertSearch, the International Accreditation Forum's (IAF) global database that the ISO Survey is compiled from, together with 2,400 or more certification bodies, according to ISO's explanatory note (12).
For scale, the same survey's counts for neighboring management system standards:
Table 3: Valid certificates and sites for management system standards beside ISO/IEC 27001, 2024. Source: ISO. (12)
These are 2024 levels, not a trend. Starting with the 2024 edition, the survey is compiled directly from IAF CertSearch (12). ISO's note says that conclusions on trends should take into account that coverage "may vary slightly across countries, industries, and standards" (12). The note also says that the certification bodies under Germany's DAkkS were unable to share data through IAF CertSearch, that only some of them shared results directly and that their absence had an impact on German statistics (12).
Compliance enforcement and penalties
Each regime turns a compliance gap into legal penalties through its own channel:
- OCR works through complaints and compliance reviews (3).
- The Justice Department recovers money under the False Claims Act when contractors misstate their cybersecurity (10).
- The Federal Trade Commission (FTC) and state attorneys general act on data security (38, 39).
- EU and EEA data protection authorities combine fines with orders and warnings, and the European Data Protection Board (EDPB) tabulates the fines by authority (2, 40).
HIPAA enforcement statistics
Table 4: HIPAA complaints, compliance reviews, audits and large breaches by calendar year, 2020 to 2024. Source: HHS Office for Civil Rights. (3, 6, 41, 42, 43, 44, 45, 46, 47, 48)

In each breach report, a breach that spans more than one year is counted in its last year: the 2020 report states that "breach incidents spanning multiple years are included with the data for the last year in which the breach occurred", and the reports from 2021 count breaches that "occurred or ended in" the calendar year (6, 45, 46, 47, 48). Each of the five compliance reports also states that OCR initiated no HIPAA audits that year, and the reports for 2021 to 2024 give the same reason (3, 41, 42, 43, 44):
"OCR did not initiate any audits in 2024 due to a lack of financial resources." HHS Office for Civil Rights, Annual Report to Congress on HIPAA compliance for calendar year 2024 (3).
What the 2024 report adds:
- OCR resolved 28,228 HIPAA complaints in 2024, and nine of its complaint investigations ended in either a resolution agreement with a corrective action plan and a monetary settlement, or a civil money penalty, for a total of $1,180,781 (3). Another 13 compliance reviews were resolved the same way in 2024, for a total of $8,763,831 (3).
- OCR received 742 breach reports through its HIPAA Breach Web Portal in 2024, some of them about breaches that occurred in earlier years; its 2024 breach report counts the 663 breaches affecting 500 or more individuals that occurred or ended in 2024, and says OCR opened investigations into all 663 (6).
- Of the 730 compliance reviews OCR initiated in 2024, 663 were initiated because of a report of a breach affecting 500 or more individuals and two because of a report of a breach affecting fewer than 500 individuals; the remaining 65 were opened on incidents that reached OCR through multiple complaints about an entity or practice, media reports or other means (3).
HIPAA civil monetary penalty tiers for 2026
HHS says its enforcement actions follow the interim penalty tiers of its April 2019 notice of enforcement discretion: the notice states that "all HIPAA enforcement actions will be governed by" those tiers and that "HHS will use this penalty tier structure, as adjusted for inflation, until further notice" (9). OCR's 2024 notice to Warby Parker says its penalties "reflect the penalty tiers described in the Notification of Enforcement Discretion" (49).
In the notice as printed in 2019, the maximum per violation was $50,000 in every tier (9). The notice's annual limits were $25,000 for no knowledge, $100,000 for reasonable cause and $250,000 for corrected willful neglect (9). For willful neglect not corrected, the notice kept $1,500,000, the annual limit the notice says the regulation applies to all four tiers (9). Each limit applies to "the total amount imposed on the person for all such violations of an identical requirement or prohibition during a calendar year" (9).
The table below gives the amounts in the HIPAA regulation, as HHS adjusted them for inflation on 28 January 2026 (7). They apply to penalties assessed on or after that date, for violations that occurred on or after 2 November 2015 (7).
Table 5: HIPAA civil monetary penalty amounts by culpability tier in the regulation, as adjusted on 28 January 2026, with the calendar-year cap for identical violations. Source: HHS. (7, 8)
HHS adjusts HIPAA civil money penalties for inflation each year, as the Federal Civil Penalties Inflation Adjustment Act, amended in 2015, requires (7). In the willful-neglect tiers, the 30-day period starts when the entity knew, or should have known, of the violation (7). Under 45 CFR 160.404, the cap applies to identical violations during a calendar year (8).
HHS's 28 January 2026 inflation adjustment lists the regulation's amounts; it does not mention the 2019 notice and gives no adjusted figure for the notice's lower annual limits of $25,000, $100,000 and $250,000 (7, 9). The same Warby Parker notice says that "OCR has adjusted the CMP ranges for each penalty tier for inflation" (49).
- In its Notice of Proposed Determination to Warby Parker of September 2024, OCR applied the reasonable-cause tier to three HIPAA Security Rule violations at $1,424 per day, capped at $100,000 for each violation in each calendar year: risk analysis in calendar years 2018 to 2024, capped at a total of $700,000; risk management in 2018 to 2022, at $500,000; and information system activity review in 2018 to 2020, at $300,000 (49). OCR's "Total CMP for all violations" was $1,500,000, which became final in December 2024 (49, 50).
False Claims Act, FTC and state enforcement
The figures below cover False Claims Act enforcement, FTC data security cases and a state attorney general's count of breaches exposing residents' sensitive information.
- Settlements and judgments under the False Claims Act exceeded $6.8 billion in the fiscal year ending 30 September 2025, the highest in a single year in the Act's history, per the Justice Department (51).
- The Justice Department's FY2025 fact sheet on cybersecurity fraud: "In this year alone, the Department has recovered over $52 million in nine cybersecurity fraud settlements and civil cybersecurity fraud settlements have more than tripled in each of the past two years" (10).
- Whistleblowers filed 1,297 qui tam lawsuits in fiscal year 2025, the highest number in a single year, and the government opened 401 investigations (51).
Table 6: Cybersecurity fraud settlements under the False Claims Act named by the Justice Department for fiscal year 2025. Source: U.S. Department of Justice. (10)
- The FTC has brought more than 90 enforcement actions with favorable outcomes under its data security enforcement program to date, per its second report to Congress on its work to fight ransomware and other cyberattacks, published on 6 February 2026 (38).
- Washington State's Attorney General received reports of 209 data breaches affecting more than 8 million Washingtonians in 2025, per its 2026 Data Privacy Report (39).
- More than 80% of the breaches reported to Washington State's Attorney General in 2025 exposed Social Security numbers (39).
Several of the named settlements turn on what each organization certified, represented or reported about its controls, not only on the controls it lacked.
GDPR fines by supervisory authority
- EU and EEA data protection authorities issued €1,145,760,374 in GDPR fines in 2025, per the EDPB Annual Report 2025 (2).
- The Irish Data Protection Commission's 2025 fines, just over €530.77 million in total, include two fines totaling €530 million on TikTok Technology Limited, per its Annual Report 2025, published on 30 June 2026 (52).
Table 7: GDPR fines by supervisory authority in 2025, sorted by total. Source: EDPB. (2)

Ranked by value, the table is led by Ireland and France; ranked by number of fines, it is led by Slovakia, Germany and Spain. If your GDPR compliance program covers personal data of people in the EU, the line for the authority where you operate says more about your exposure than the EU-wide total.
GDPR enforcement statistics
National authorities such as France's CNIL issue formal notices, reminders and warnings (40), and cross-border cases run through the EDPB's cooperation procedures (2).
- France's data protection authority, the CNIL, issued 83 sanctions in 2025 for a cumulative €486,839,500 in fines, per the sanctions review it published on 9 February 2026 (40).
- Of the CNIL's 83 sanctions in 2025, 16 were decided under the ordinary procedure and 67 under the simplified procedure, and they comprise 78 fines, per its 2025 sanctions review (40).
- Alongside those sanctions, the CNIL issued 143 formal notices to comply, 31 reminders of legal obligations and two warnings in 2025, per its 2025 sanctions review (40).
- 414 cross-border cases were created in the EDPB's case register in 2025, and 1,299 One-Stop-Shop procedures under Article 60 GDPR were triggered, of which 572 produced final decisions (2).
- The EDPB's Annual Report 2025 counts 376 mutual assistance procedures under Article 61 GDPR in 2025 and 4,200 instances of assistance on a voluntary basis (2).
"In 2025, no binding decisions were adopted by the EDPB." European Data Protection Board, Annual Report 2025 (2).
- The Irish Data Protection Commission received 6,521 valid data breach notifications in 2025, per its Annual Report 2025 (52).
- The Irish Data Protection Commission received 16,160 new cases from individuals in 2025 and concluded 11,734 cases during the year, per the same annual report (52).
- The Irish Data Protection Commission also concluded 208 valid cross-border complaints and finalized 4 large-scale inquiries in 2025, per its Annual Report 2025 (52).
At the CNIL, formal notices to comply outnumbered sanctions in 2025, and cookies, employee surveillance and data security were the main subjects of those sanctions (40). For France, the EDPB's per-authority table (Table 7) records 84 fines and €486,854,500, while the CNIL's own review counts 83 sanctions and €486,839,500 (2, 40).
Learn more: a guide to the consequences of non-compliance covers the direct and indirect costs across industries.
Compliance budgets, staffing and skills
ISACA and ISC2 are two professional associations that survey security professionals (15, 53).
Compliance budgets and investment
Table 8: Budget outlook among cybersecurity and privacy professionals, 2025 and 2026. Source: ISACA. (15, 23)
What ISC2's workforce study adds:
- 33% of respondents to ISC2's 2025 Cybersecurity Workforce Study, which surveyed 16,029 practitioners, said their organizations do not have the resources to adequately staff their teams, and 29% said they cannot afford to hire staff with the skills they need (53).
- 36% of respondents to ISC2's 2025 study experienced cybersecurity budget cuts and 24% layoffs, both one percentage point lower than in 2024 (53).
What Hyperproof's GRC survey adds:
- 70% of respondents reported an annual governance, risk and compliance budget over $1 million in Hyperproof's 2026 IT Risk and Compliance Benchmark Report, a compliance software vendor's survey of 1,002 respondents, fielded in November and December 2025 (18).
- In Hyperproof's 2026 benchmark, 58% anticipate their organization will spend more on GRC in 2026, and 92% said they had the budget and resources they needed to achieve their goals in 2025 (18).
These are different surveys with different samples: Hyperproof's 2026 benchmark covers GRC programs, while ISACA and ISC2 poll cybersecurity and privacy professionals (15, 18, 23, 53).
Compliance staffing and workload
- 55% of cybersecurity teams are understaffed and 65% have unfilled cybersecurity positions, per ISACA's State of Cybersecurity 2025 (15).
- Cybersecurity staff make up only 10.6% of total IT full-time equivalents (FTEs), the lowest proportion observed to date, among the organizations in ENISA's NIS Investments 2025 study (14).
- 76% of the EU organizations in the same ENISA 2025 study report difficulty attracting cybersecurity professionals and 71% difficulty retaining them (14).
- The median privacy staff size fell from eight in 2025 to five in 2026, per ISACA's State of Privacy 2026 survey of more than 1,800 privacy professionals (23).
- 51% of GRC teams have four people or fewer, and 18.5% of practitioners run GRC completely alone, in GRC Engineer's State of GRC 2026 survey, which counted 795 responses (16).
- In Hyperproof's 2026 benchmark, a compliance software vendor's survey of 1,002 respondents, fielded in November and December 2025, 86% of respondents have a centralized team to manage GRC and only 14% manage it through individual teams or business units; 68% say their team sizes will grow over the next two years (18).
- In Hyperproof's 2026 benchmark, a compliance software vendor's survey of 1,002 respondents, 58% of those who experienced a security breach in the last 24 months anticipate spending more time on IT risk management and compliance in 2026 (18).
Cybersecurity and compliance skills
- 95% of respondents to ISC2's 2025 study reported at least one skill need on their team, and 59% cited critical or significant skill needs (53).
- 88% of the same respondents have experienced at least one significant cybersecurity consequence in their organization because of a skills shortage, and 69% more than one, per ISC2's 2025 study (53).
- Specialist knowledge (53%) and data management (43%) were named the key skills for maintaining effective compliance in PwC's 2025 Global Compliance Survey, and more than half of those who rated these skill needs critical expect a shortage in them within 12 months (19).
- Only 10 of 671 respondents, 1.5%, said they will not need additional AI governance staff in the next 12 months, in the IAPP AI Governance Profession Report 2025, whose survey ran in spring 2024 (54).
Read together, the association and practitioner surveys describe small teams with security and privacy budgets under pressure and more AI governance work ahead, and 18.5% of practitioners in the State of GRC 2026 run GRC completely alone (16). In Hyperproof's 2026 vendor survey of 1,002 respondents, 70% have annual GRC budgets over $1 million (18). Your own team's capacity, not the average of any one survey, is what an assessment calendar has to be planned around.
Compliance automation and AI statistics
Automation tools are where a thinly staffed compliance team looks for capacity, and AI is now both a tool for that work and a risk the program has to govern.
Compliance tools and automation
- 59% of practitioners use no commercial GRC tool at all, in GRC Engineer's State of GRC 2026, a survey it describes as independent, with 795 responses (748 unique after deduplication) collected between April 2025 and March 2026 (16).
- Among the non-commercial tools named as primary in the State of GRC 2026, spreadsheets led with 93 respondents, ahead of custom tools, meaning repurposed stacks such as Jira, Notion or SharePoint (70 respondents), and open source (38 respondents) (16).
- 49% of respondents to PwC's 2025 Global Compliance Survey use technology for 11 or more compliance activities, and the top three areas of technology use are training (82% of respondents), risk assessment (76%) and compliance and transaction monitoring (75%) (19).
- On investment plans, PwC's 2025 Global Compliance Survey states that "On average, 82% of companies are planning on investing more in at least one technology to automate and optimise compliance activities"; PwC gives 1,798 respondents as the base of its question on technology use and investment plans (4, 19).
- Organizations using AI and automation extensively in security saved an average of $1.93 million in breach costs compared with those using none, per IBM's 2026 Cost of a Data Breach Report (1).
- 56% of respondents to Hyperproof's 2026 benchmark, a compliance software vendor's survey of 1,002 respondents, fielded in November and December 2025, use a common controls framework to streamline their GRC processes (18).
AI adoption in compliance programs
- 71% of PwC's 2025 respondents believe AI will have a net positive impact overall on compliance, while 32% are not currently piloting or using AI for any compliance activity (19).
- NAVEX, which sells compliance software, found in its 2026 survey of nearly 1,200 risk and compliance leaders that only 4% were not using AI anywhere in their compliance program (17).
- Hyperproof, another compliance software vendor, found that 97% of the 1,002 respondents to its 2026 benchmark survey, fielded in November and December 2025, use AI to streamline their workflows (18).
The PwC 2025, NAVEX 2026 and Hyperproof 2026 adoption figures answer different questions: PwC counts respondents not piloting or using AI for any compliance activity; NAVEX counts respondents not using AI anywhere in their compliance program; and Hyperproof counts respondents using AI to streamline their workflows (17, 18, 19). Quote the one whose question matches yours.
- 26% of privacy professionals in ISACA's State of Privacy 2026 have no plans to use AI for privacy-related tasks, down from 36% in 2024 and 31% in 2025 (23).
- 45% of employees are now regular users of AI on their corporate devices, up from 15% the previous year, and 67% of users reach AI services through non-corporate accounts on those devices, per Verizon's 2026 DBIR (5).
- Shadow AI, the use of AI services the organization has not authorized, became the third most common non-malicious insider action in Verizon's data loss prevention dataset in 2025, a fourfold increase in percentage terms from the previous year (5).
- IBM's 2026 report puts the share of security incidents involving an organization's shadow AI, where workers use unapproved AI, at 43%, up from 20% a year earlier, and the average breach cost of those incidents at $5.39 million, up from $4.63 million in the 2025 report (1).
- In about one in five shadow AI security incidents, organizations reported paying a regulatory fine, per IBM's 2026 Cost of a Data Breach Report (1).
AI governance and oversight
- 77% of the organizations in the IAPP AI Governance Profession Report 2025 are working on AI governance, rising to nearly 90% among those already using AI, based on more than 670 respondents in 45 countries and territories, surveyed in spring 2024 (54).
- 47% of cybersecurity professionals in ISACA's State of Cybersecurity 2025 said they have helped develop AI governance, up from 35% the previous year, and 40% have been involved in AI implementation, up from 29% (15).
- 68% of the breached organizations in IBM's 2026 report lacked AI governance to manage AI or detect shadow AI, against 63% a year earlier, and among those with policies only about a third had strict approvals for deploying AI (1).
Table 9: AI governance policy status among breached organizations, 2026 and 2025. Source: IBM. (1)
- 92% of organizations that experienced an AI-related breach lacked proper AI access controls, and only 40% of the organizations IBM studied reported using access controls on AI models and data, per IBM's 2026 report (1).
Table 10: Functions most often tasked with primary responsibility for AI governance, surveyed in spring 2024. Source: IAPP. (54)
For a compliance program, the Verizon figures on non-corporate accounts and shadow AI are the ones to act on first: they describe AI use outside approved accounts, and so beyond the controls a policy can evidence.
What the numbers mean for your compliance program
- Proof of compliance travels with every contract. Third parties were involved in 48% of breaches in Verizon's 2026 DBIR (5), and breaches reported by business associates accounted for 85% of the individuals affected by large HIPAA breaches that occurred in 2024 (6). With vendors this close to the breach numbers, expect customers to ask how you evidence your security posture between assessments, not only which report you hold.
- HIPAA enforcement from 2020 to 2024 ran on complaints and breach reports, not audits. Each of OCR's annual reports for those years states that OCR initiated no HIPAA audits that year (3, 41, 42, 43, 44), and 663 of the 730 compliance reviews OCR initiated in 2024 followed a report of a breach affecting 500 or more individuals (3). Its 2024 breach investigations named risk analysis and risk management among five Security Rule areas needing improvement (6), which makes a current risk analysis the first document to have ready.
- What you certify is a compliance risk of its own. Several of the cybersecurity fraud settlements the Justice Department named for fiscal year 2025 turn on false certifications, an inaccurate score for the implementation of required security controls and misrepresented adherence to standards (10). An attestation or a contract certification should say only what your controls can show.
- Match the statistic to the budget case. A budget case built on IBM's 2026 average data breach cost of $4.99 million (1) describes breached organizations; one built on Coalition's 2025 average claim of $116,000 (26) describes insured businesses. Pick the figure whose population looks like yours, and name its source.
- Bring AI use inside your policies. 45% of employees were regular AI users on corporate devices in Verizon's 2026 DBIR (5), while 77% of organizations in the IAPP's 2025 study, surveyed in spring 2024, were working on AI governance (54). The approved tools, and the sensitive data they may touch, belong in your policies and your risk assessment.
- Plan around the team you have. 51% of GRC teams have four people or fewer and 59% of practitioners use no commercial GRC tool, per the State of GRC 2026 (16). Staging frameworks, reusing evidence across them and deciding what to hand to outside help are capacity decisions as much as budget ones.
The gap between the average organization and the best-performing one shows up in three numbers. Only 7% of PwC's 2025 respondents consider their company leading in compliance (4). NAVEX, which sells compliance software, found in its 2026 survey of nearly 1,200 risk and compliance leaders that each step up in program maturity came with twice the budget (17). And organizations using AI and automation extensively in security saved an average of $1.93 million in breach costs in IBM's 2026 report (1).
Final thoughts
Three findings stand out in the 2026 numbers. 85% of PwC's 2025 respondents said compliance requirements had become more complex in the last three years, while 55% of cybersecurity teams in ISACA's 2025 study were understaffed (4, 15). Regulators now publish enough of their own data to measure enforcement directly, and OCR's report to Congress for 2024 shows HIPAA cases opening from complaints and breach reports, with no audits initiated (3). And the distance between the few organizations that call their programs leading and everyone else remains wide in PwC's 2025 survey (4).
Build a compliance program you can evidence
Most of the figures above come down to one question from a customer, an assessor or a regulator: can you show it? Our cybersecurity compliance services start with a gap assessment that maps every gap to the requirement it belongs to, with a risk rating attached.
From there we build a remediation roadmap, stay involved while the controls are implemented and draft the policies, procedures and records an assessor expects to see, for SOC 2, ISO 27001, HIPAA, PCI DSS, CMMC, GDPR and the other frameworks we support. Most of our clients stay on recurring engagements, so their compliance posture is maintained between assessment cycles rather than rebuilt before each one. Tell us which framework is next, and we will get back to you within a day.
References
- IBM, Cost of a Data Breach Report 2026 (full report behind registration). https://www.ibm.com/reports/data-breach
- EDPB, Annual Report 2025. https://www.edpb.europa.eu/system/files/2026-04/edpb-annual-report-2025_en.pdf
- HHS Office for Civil Rights, Annual Report to Congress on HIPAA Privacy, Security, and Breach Notification Rule Compliance for Calendar Year 2024. https://www.hhs.gov/sites/default/files/compliance-report-to-congress-2024.pdf
- PwC, Global Compliance Survey 2025 (report PDF). https://www.pwc.com/gx/en/issues/risk-regulation/pwc-global-compliance-study-2025.pdf
- Verizon, 2026 Data Breach Investigations Report. https://www.verizon.com/business/resources/T5f4/reports/2026-dbir-data-breach-investigations-report.pdf
- HHS Office for Civil Rights, Annual Report to Congress on Breaches of Unsecured Protected Health Information for Calendar Year 2024. https://www.hhs.gov/sites/default/files/breach-report-to-congress-2024.pdf
- HHS, Annual Civil Monetary Penalties Inflation Adjustment, 91 FR 3665 (28 January 2026). https://www.federalregister.gov/documents/2026/01/28/2026-01688/annual-civil-monetary-penalties-inflation-adjustment
- HHS, 45 CFR 160.404 (Amount of a civil money penalty), eCFR, current as of September 2026. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-D/section-160.404
- HHS, Notification of Enforcement Discretion Regarding HIPAA Civil Money Penalties, 84 FR 18151 (30 April 2019). https://www.federalregister.gov/documents/2019/04/30/2019-08530/notification-of-enforcement-discretion-regarding-hipaa-civil-money-penalties
- U.S. Department of Justice, Fact Sheet: False Claims Act Settlements and Judgments FY2025. https://www.justice.gov/opa/media/1424126/dl
- Verizon, 2024 Payment Security Report. https://www.verizon.com/business/resources/T5f4/reports/2024/2024-payment-security-report.pdf
- ISO (CASCO), The ISO Survey of Management System Standard Certifications 2024, Explanatory Note, September 2025 (full results behind registration). https://www.iafcertsearch.org/services/iso-survey
- The Cyber AB, Statement on the Department of War's Suspension of CMMC Phase II Requirements, 15 July 2026. https://www.cyberab.org/Portals/0/Documents/CyberABStatementOnDoWPhaseIISuspension-15JUL2026.pdf
- ENISA, NIS Investments 2025. https://www.enisa.europa.eu/sites/default/files/2026-02/NIS%20Investments%202025%20-%20Main%20report.pdf
- ISACA, State of Cybersecurity 2025 (press release). https://www.isaca.org/about-us/newsroom/press-releases/2025/state-of-cybersecurity-2025-global-press-release
- GRC Engineer, The State of GRC 2026. https://grcengineer.com/report/
- NAVEX, 2026 State of Risk & Compliance (vendor survey). https://www.navex.com/en-us/northstar/global-risk-compliance-statistics/
- Hyperproof, 2026 IT Risk and Compliance Benchmark Report (vendor survey; full report behind registration). https://hyperproof.io/it-compliance-benchmarks/
- PwC, Global Compliance Survey 2025. https://www.pwc.com/gx/en/issues/risk-regulation/global-compliance-survey.html
- Thomson Reuters Institute, 2025 C-Suite Survey (full report PDF). https://www.thomsonreuters.com/en-us/posts/wp-content/uploads/sites/20/2025/05/2025-C-Suite-Report.pdf
- Thomson Reuters, 2025 C-Suite Survey (press release, May 2025). https://www.thomsonreuters.com/en/press-releases/2025/may/untapped-potential-c-suite-leaders-overlook-key-enabling-functions-full-contribution-to-business-success
- IAPP, Privacy Governance Report 2024. https://iapp.org/resources/article/privacy-governance-report
- ISACA, State of Privacy 2026 (press release, 15 January 2026). https://www.isaca.org/about-us/newsroom/press-releases/2026/new-isaca-study-privacy-teams-are-shrinking-increasingly-stressed
- U.S. Department of War (Department of Defense), DFARS final rule: Assessing Contractor Implementation of Cybersecurity Requirements (10 September 2025). https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of
- IBM, Cost of a Data Breach Report 2026 (press release, 29 July 2026). https://newsroom.ibm.com/2026-07-29-ibm-study-one-in-four-malicious-breaches-are-ai-enabled,-costing-companies-6-million-on-average
- Coalition, 2026 Cyber Claims Report (announcement). https://www.coalitioninc.com/announcements/2026-cyber-claims-report
- FBI IC3, 2025 Internet Crime Report. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
- HHS, 45 CFR 164.404 (HIPAA Breach Notification Rule, notification to individuals), eCFR, current as of September 2026. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.404
- HHS, 45 CFR 164.412 (HIPAA Breach Notification Rule, law enforcement delay), eCFR, current as of September 2026. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.412
- U.S. Department of War (Department of Defense), 32 CFR Part 170 (CMMC Program), eCFR, current as of September 2026. https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170
- U.S. Department of War (Department of Defense), Chief Information Officer, About CMMC. https://dowcio.war.gov/CMMC/About/
- The White House, Executive Order 14347: Restoring the United States Department of War, 90 FR 43893. https://www.federalregister.gov/documents/2025/09/10/2025-17508/restoring-the-united-states-department-of-war
- U.S. Department of War (Department of Defense), Office of the Chief Information Officer, CMMC Program Frequently Asked Questions, Revision 2.3 (Excerpt), July 2026. https://dowcio.war.gov/Portals/0/Documents/CMMC/FAQsv6.pdf
- U.S. Department of War (Department of Defense), Cybersecurity Maturity Model Certification Procedures, memorandum attachment cleared for open publication 13 July 2026. https://dowcio.war.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf
- Verizon, Payment Security Report landing page (read 10 September 2026). https://www.verizon.com/business/reports/payment-security-report/
- AICPA & CIMA, System and Organization Controls: SOC suite of services. https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
- AICPA & CIMA, System and Organization Controls (SOC) Survey (2020 survey, published 2021). https://www.aicpa-cima.com/resources/download/soc-survey-results-point-to-the-value-of-soc-1-and-2-engagements
- U.S. Federal Trade Commission, FTC Issues Second Report to Congress on its Work to Fight Ransomware and other Cyberattacks (press release, 6 February 2026). https://www.ftc.gov/news-events/news/press-releases/2026/02/ftc-issues-second-report-congress-its-work-fight-ransomware-other-cyberattacks
- Washington State Attorney General's Office, Data Privacy Report 2026 (figures restated in the Attorney General's own news release, read 10 September 2026). https://www.atg.wa.gov/news/news-releases/ag-s-first-ever-data-privacy-report-identifies-policy-priorities-and
- CNIL, Sanctions et mesures correctrices: bilan 2025 (published 9 February 2026). https://www.cnil.fr/fr/bilan-sanctions-2025
- HHS Office for Civil Rights, Annual Report to Congress on HIPAA Privacy, Security, and Breach Notification Rule Compliance for Calendar Year 2020. https://www.hhs.gov/sites/default/files/compliance-report-to-congress-2020.pdf
- HHS Office for Civil Rights, Annual Report to Congress on HIPAA Privacy, Security, and Breach Notification Rule Compliance for Calendar Year 2021. https://www.hhs.gov/sites/default/files/compliance-report-to-congress-2021.pdf
- HHS Office for Civil Rights, Annual Report to Congress on HIPAA Privacy, Security, and Breach Notification Rule Compliance for Calendar Year 2022. https://www.hhs.gov/sites/default/files/compliance-report-to-congress-2022.pdf
- HHS Office for Civil Rights, Annual Report to Congress on HIPAA Privacy, Security, and Breach Notification Rule Compliance for Calendar Year 2023. https://www.hhs.gov/sites/default/files/compliance-report-to-congress-2023.pdf
- HHS Office for Civil Rights, Annual Report to Congress on Breaches of Unsecured Protected Health Information for Calendar Year 2021. https://www.hhs.gov/sites/default/files/breach-report-to-congress-2021.pdf
- HHS Office for Civil Rights, Annual Report to Congress on Breaches of Unsecured Protected Health Information for Calendar Year 2022. https://www.hhs.gov/sites/default/files/breach-report-to-congress-2022.pdf
- HHS Office for Civil Rights, Annual Report to Congress on Breaches of Unsecured Protected Health Information for Calendar Year 2023. https://www.hhs.gov/sites/default/files/breach-report-to-congress-2023.pdf
- HHS Office for Civil Rights, Annual Report to Congress on Breaches of Unsecured Protected Health Information for Calendar Year 2020. https://www.hhs.gov/sites/default/files/breach-report-to-congress-2020.pdf
- HHS Office for Civil Rights, Notice of Proposed Determination, Warby Parker, Inc. (5 September 2024). https://www.hhs.gov/sites/default/files/ocr-warby-parker-npd.pdf
- HHS Office for Civil Rights, Notice of Final Determination, Warby Parker, Inc. (11 December 2024). https://www.hhs.gov/sites/default/files/ocr-warby-parker-nfd.pdf
- U.S. Department of Justice, False Claims Act statistics FY2025 (press release). https://www.justice.gov/opa/pr/false-claims-act-settlements-and-judgments-exceed-68b-fiscal-year-2025
- Irish Data Protection Commission, Annual Report 2025 (announcement, published 30 June 2026). https://www.dataprotection.ie/en/data-protection-commission-publishes-2025-annual-report
- ISC2, 2025 Cybersecurity Workforce Study (announcement). https://www.isc2.org/Insights/2025/12/ISC2-Publishes-2025-Cybersecurity-Workforce-Study
- IAPP, AI Governance Profession Report 2025 (fieldwork spring 2024). https://iapp.org/resources/article/ai-governance-profession-report
- Regulation (EU) 2016/679 (GDPR), Article 83, consolidated text on EUR-Lex (read 10 September 2026). https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016R0679


FAQ
Why is cybersecurity compliance important?
Because regulators and prosecutors act on it and it sets the standard an organization's defenses against cyber threats are measured against. Cyber risks rank high: 51% of PwC's 2025 respondents placed cybersecurity among their top five compliance risk priorities (4). 70% of organizations in ENISA's NIS Investments 2025 named regulatory compliance as the main driver of their cybersecurity investment (14). Several cybersecurity fraud settlements the Justice Department named for fiscal year 2025 turn on what contractors certified or represented about their cybersecurity (10).
What does cybersecurity compliance require from an organization?
It depends on the framework: each one sets out its own cybersecurity measures. As current in September 2026, CMMC Level 2 carries the 110 requirements of NIST SP 800-171 Revision 2, per 32 CFR 170.4 (30). A SOC 2 report covers controls relevant to security, availability, processing integrity, confidentiality or privacy, per the AICPA (36). Under HIPAA, OCR's 2024 breach investigations named risk analysis, risk management, information system activity review, audit controls and authentication as areas needing improvement (6).
What happens if a company fails to meet its compliance obligations?
It depends on the regime, and the regulators' own reports show the range. OCR resolved nine HIPAA complaint investigations in 2024 with settlements or civil money penalties totaling $1,180,781 (3). EU and EEA data protection authorities issued €1,145,760,374 in GDPR fines in 2025 (2). In the US, the Justice Department recovered over $52 million in nine cybersecurity fraud settlements in fiscal year 2025 (10). Fines are only part of it: in 2025 the CNIL also issued 143 formal notices to comply (40).
Why is third-party risk management important?
Because third parties were involved in 48% of all breaches in Verizon's 2026 Data Breach Investigations Report (5). Business associates filed 16% of the reports of large HIPAA breaches that occurred in 2024, but those breaches accounted for 85% of all affected individuals (6). In ENISA's 2025 study, 47% of organizations cited supply chain and third-party attacks as a top concern for the future (14). Vendors that handle your customer data are a route for supply chain attacks.
What is the maximum HIPAA fine in 2026?
The HIPAA regulation, as adjusted on 28 January 2026, sets the top tier (willful neglect not corrected within 30 days) at $73,011 to $2,190,294 per violation and caps identical violations at $2,190,294 per calendar year (7, 8). HHS says enforcement follows its 2019 notice's tiers "as adjusted for inflation, until further notice" (9); the 2026 adjustment never mentions that notice (7). OCR's 2024 Warby Parker penalty capped three reasonable-cause violations at $100,000 per calendar year in periods between 2018 and 2024, totaling $1,500,000 (49, 50).
What is the maximum GDPR fine?
Article 83 of the GDPR sets two ceilings: the infringements listed in its paragraph 4 carry administrative fines up to €10 million, or for an undertaking up to 2% of its total worldwide annual turnover of the preceding financial year, whichever is higher (55). Those listed in paragraphs 5 and 6 carry fines up to €20 million, or up to 4% of that turnover, whichever is higher (55). The largest national total in 2025 came from Ireland's authority: €530,773,000 across 4 fines (2).
Which CMMC requirements still apply after the Phase II suspension?
The self-assessment requirements do: the Department of War's CMMC page states "All Phase I self-assessment requirements remain firmly in place" (31). The Department's memorandum of 13 July 2026 suspends the November 2026 transition to Phase II and, meanwhile, lets requiring activities designate only CMMC Level 1 (Self) or Level 2 (Self) assessments (34). It said further guidance would follow the CIO's 60-day review (34). On 15 July 2026, The Cyber AB said C3PAO Level 2 assessments remained operational and available (13).
What are compliance metrics?
They are the measures that show whether obligations are met. Verizon's 2024 Payment Security Report counts how many organizations pass every PCI DSS requirement at interim validation, 14.3% in 2023, and the control gap, the share of controls found not in place, 4.5% that year (11). OCR counts complaints and compliance reviews: 30,256 new HIPAA complaints and 730 reviews initiated in 2024 (3). ENISA's 2025 study tracks operational measures: 28% of organizations take more than three months to patch critical vulnerabilities (14).
How can AI help with regulatory compliance?
71% of PwC's 2025 respondents expect AI to have a net positive impact on compliance, while 32% are not currently piloting or using it for any compliance activity (19). The measured benefit sits on the security side: organizations using AI and automation extensively in security saved an average of $1.93 million in breach costs in IBM's 2026 report (1). The risk runs the other way too: shadow AI was the third most common non-malicious insider action in Verizon's 2025 data (5).








.avif)


