{
  "overview": {
    "datasetId": "GRCTRACK-BDS-2026-001",
    "datasetStatus": "provisional",
    "sampleSize": 4721,
    "methodologyVersion": "2026.1",
    "asOf": "2026-04-28T08:29:51.781Z",
    "globalMaturity": 60,
    "globalAuditHours": 949,
    "globalCostUSD": 163789,
    "globalAutomationRate": 59,
    "globalRemediationDays": 7.6,
    "totalSampleSize": 4540,
    "bestInClassIndustry": "FinTech",
    "bestInClassScore": 68,
    "mostImprovementIndustry": "Hospitality",
    "riskIndexSnapshot": [
      {
        "industry": "Hospitality",
        "riskScore": 62,
        "riskLevel": "Moderate"
      },
      {
        "industry": "Retail",
        "riskScore": 53,
        "riskLevel": "Moderate"
      },
      {
        "industry": "Healthcare",
        "riskScore": 52,
        "riskLevel": "Moderate"
      },
      {
        "industry": "E-Commerce",
        "riskScore": 47,
        "riskLevel": "Low-Moderate"
      },
      {
        "industry": "Financial Services",
        "riskScore": 43,
        "riskLevel": "Low-Moderate"
      },
      {
        "industry": "FinTech",
        "riskScore": 34,
        "riskLevel": "Low"
      },
      {
        "industry": "SaaS / Cloud",
        "riskScore": 33,
        "riskLevel": "Low"
      }
    ],
    "automationAdoptionSummary": {
      "pct": 59,
      "trend": "improving",
      "yoyDelta": 10
    },
    "provenance": {
      "displayMode": "provisional",
      "disclaimer": "Data is provisional — directionally indicative, k-anonymity k≥5. Not verified benchmark data.",
      "methodologyId": "GRCTRACK-METH-2026-001"
    }
  },
  "maturity": {
    "globalAvg": 60,
    "industries": [
      {
        "industry": "fintech",
        "displayName": "FinTech",
        "maturity": 68,
        "percentile25": 55,
        "percentile75": 78,
        "percentile90": 84,
        "yoyDelta": 3,
        "sampleSize": 810,
        "vsGlobal": 13
      },
      {
        "industry": "saas",
        "displayName": "SaaS / Cloud",
        "maturity": 65,
        "percentile25": 52,
        "percentile75": 76,
        "percentile90": 82,
        "yoyDelta": 4,
        "sampleSize": 920,
        "vsGlobal": 8
      },
      {
        "industry": "financial-services",
        "displayName": "Financial Services",
        "maturity": 63,
        "percentile25": 50,
        "percentile75": 74,
        "percentile90": 81,
        "yoyDelta": 2,
        "sampleSize": 720,
        "vsGlobal": 5
      },
      {
        "industry": "healthcare",
        "displayName": "Healthcare",
        "maturity": 58,
        "percentile25": 44,
        "percentile75": 70,
        "percentile90": 78,
        "yoyDelta": 4,
        "sampleSize": 480,
        "vsGlobal": -3
      },
      {
        "industry": "ecommerce",
        "displayName": "E-Commerce",
        "maturity": 55,
        "percentile25": 41,
        "percentile75": 66,
        "percentile90": 74,
        "yoyDelta": 3,
        "sampleSize": 580,
        "vsGlobal": -8
      },
      {
        "industry": "retail",
        "displayName": "Retail",
        "maturity": 52,
        "percentile25": 38,
        "percentile75": 63,
        "percentile90": 72,
        "yoyDelta": 2,
        "sampleSize": 640,
        "vsGlobal": -13
      },
      {
        "industry": "hospitality",
        "displayName": "Hospitality",
        "maturity": 47,
        "percentile25": 34,
        "percentile75": 58,
        "percentile90": 66,
        "yoyDelta": 1,
        "sampleSize": 390,
        "vsGlobal": -22
      }
    ],
    "distributionBands": [
      {
        "band": "0-39",
        "label": "Critical Gap",
        "pct": 8
      },
      {
        "band": "40-54",
        "label": "Below Average",
        "pct": 22
      },
      {
        "band": "55-69",
        "label": "Developing",
        "pct": 38
      },
      {
        "band": "70-84",
        "label": "Proficient",
        "pct": 25
      },
      {
        "band": "85-100",
        "label": "Advanced",
        "pct": 7
      }
    ],
    "topPerformer": {
      "industry": "fintech",
      "displayName": "FinTech",
      "maturity": 68,
      "percentile25": 55,
      "percentile75": 78,
      "percentile90": 84,
      "yoyDelta": 3,
      "sampleSize": 810,
      "vsGlobal": 13
    },
    "bottomPerformer": {
      "industry": "hospitality",
      "displayName": "Hospitality",
      "maturity": 47,
      "percentile25": 34,
      "percentile75": 58,
      "percentile90": 66,
      "yoyDelta": 1,
      "sampleSize": 390,
      "vsGlobal": -22
    },
    "asOf": "2026-04-28T08:29:51.783Z"
  },
  "auditHours": {
    "globalAvg": 949,
    "byIndustry": [
      {
        "industry": "financial-services",
        "displayName": "Financial Services",
        "hours": 1380,
        "vsGlobal": 45,
        "trend": -4,
        "sampleSize": 720
      },
      {
        "industry": "hospitality",
        "displayName": "Hospitality",
        "hours": 1120,
        "vsGlobal": 18,
        "trend": -1,
        "sampleSize": 390
      },
      {
        "industry": "healthcare",
        "displayName": "Healthcare",
        "hours": 1050,
        "vsGlobal": 11,
        "trend": -5,
        "sampleSize": 480
      },
      {
        "industry": "retail",
        "displayName": "Retail",
        "hours": 980,
        "vsGlobal": 3,
        "trend": -3,
        "sampleSize": 640
      },
      {
        "industry": "ecommerce",
        "displayName": "E-Commerce",
        "hours": 890,
        "vsGlobal": -6,
        "trend": -5,
        "sampleSize": 580
      },
      {
        "industry": "fintech",
        "displayName": "FinTech",
        "hours": 780,
        "vsGlobal": -18,
        "trend": -8,
        "sampleSize": 810
      },
      {
        "industry": "saas",
        "displayName": "SaaS / Cloud",
        "hours": 650,
        "vsGlobal": -32,
        "trend": -9,
        "sampleSize": 920
      }
    ],
    "byRegion": [
      {
        "region": "us",
        "displayName": "United States",
        "avgHours": 1180,
        "avgMaturity": 58,
        "sampleSize": 1820
      },
      {
        "region": "canada",
        "displayName": "Canada",
        "avgHours": 1020,
        "avgMaturity": 60,
        "sampleSize": 240
      },
      {
        "region": "uk",
        "displayName": "United Kingdom",
        "avgHours": 920,
        "avgMaturity": 64,
        "sampleSize": 680
      },
      {
        "region": "india",
        "displayName": "India",
        "avgHours": 920,
        "avgMaturity": 54,
        "sampleSize": 160
      },
      {
        "region": "germany",
        "displayName": "Germany",
        "avgHours": 840,
        "avgMaturity": 67,
        "sampleSize": 290
      },
      {
        "region": "australia",
        "displayName": "Australia",
        "avgHours": 840,
        "avgMaturity": 63,
        "sampleSize": 180
      },
      {
        "region": "singapore",
        "displayName": "Singapore",
        "avgHours": 760,
        "avgMaturity": 65,
        "sampleSize": 210
      }
    ],
    "trendDelta": -6,
    "asOf": "2026-04-28T08:29:51.783Z"
  },
  "remediation": {
    "globalAvgDays": 7.6,
    "benchmark": 8,
    "byIndustry": [
      {
        "industry": "hospitality",
        "displayName": "Hospitality",
        "days": 10.4,
        "vsGlobal": 37,
        "trend": 5,
        "topBottleneck": "Multi-property network segmentation (Req. 1.3)"
      },
      {
        "industry": "retail",
        "displayName": "Retail",
        "days": 9.1,
        "vsGlobal": 20,
        "trend": 8,
        "topBottleneck": "POS terminal firmware patching (Req. 6.3)"
      },
      {
        "industry": "healthcare",
        "displayName": "Healthcare",
        "days": 8.8,
        "vsGlobal": 16,
        "trend": -2,
        "topBottleneck": "Wireless network segmentation in clinical areas"
      },
      {
        "industry": "financial-services",
        "displayName": "Financial Services",
        "days": 8.3,
        "vsGlobal": 9,
        "trend": 4,
        "topBottleneck": "Third-party vendor access governance (Req. 12.6)"
      },
      {
        "industry": "ecommerce",
        "displayName": "E-Commerce",
        "days": 7.8,
        "vsGlobal": 3,
        "trend": -3,
        "topBottleneck": "Third-party script monitoring (Req. 6.4.3)"
      },
      {
        "industry": "fintech",
        "displayName": "FinTech",
        "days": 6.2,
        "vsGlobal": -18,
        "trend": 12,
        "topBottleneck": "API security monitoring (Req. 6.4)"
      },
      {
        "industry": "saas",
        "displayName": "SaaS / Cloud",
        "days": 5.4,
        "vsGlobal": -29,
        "trend": -6,
        "topBottleneck": "Multi-cloud CDE boundary definition"
      }
    ],
    "requirementHotspots": [
      {
        "requirement": "Req. 1.3 — Network segmentation",
        "industry": "Hospitality / Retail",
        "avgDays": 11.8,
        "frequency": "Very High"
      },
      {
        "requirement": "Req. 6.3 — Firmware patching (POS)",
        "industry": "Retail",
        "avgDays": 11.2,
        "frequency": "Moderate"
      },
      {
        "requirement": "Req. 12.6 — Third-party vendor governance",
        "industry": "Financial Services",
        "avgDays": 10.1,
        "frequency": "High"
      },
      {
        "requirement": "Req. 6.4 — Application security monitoring",
        "industry": "FinTech / SaaS",
        "avgDays": 7.8,
        "frequency": "High"
      },
      {
        "requirement": "Req. 6.4.3 — Third-party script controls",
        "industry": "E-Commerce",
        "avgDays": 7.8,
        "frequency": "High"
      },
      {
        "requirement": "Req. 8.x — Access management",
        "industry": "Cross-sector",
        "avgDays": 5.9,
        "frequency": "Very High"
      }
    ],
    "asOf": "2026-04-28T08:29:51.783Z"
  },
  "cost": {
    "globalAvgCost": 163789,
    "byIndustry": [
      {
        "industry": "financial-services",
        "displayName": "Financial Services",
        "costUSD": 280000,
        "vsGlobal": 71,
        "costTrend": -3,
        "automationSavings": 112000,
        "sampleSize": 720
      },
      {
        "industry": "healthcare",
        "displayName": "Healthcare",
        "costUSD": 195000,
        "vsGlobal": 19,
        "costTrend": -2,
        "automationSavings": 78000,
        "sampleSize": 480
      },
      {
        "industry": "hospitality",
        "displayName": "Hospitality",
        "costUSD": 178000,
        "vsGlobal": 9,
        "costTrend": 1,
        "automationSavings": 71200,
        "sampleSize": 390
      },
      {
        "industry": "retail",
        "displayName": "Retail",
        "costUSD": 168000,
        "vsGlobal": 3,
        "costTrend": -2,
        "automationSavings": 67200,
        "sampleSize": 640
      },
      {
        "industry": "ecommerce",
        "displayName": "E-Commerce",
        "costUSD": 145000,
        "vsGlobal": -11,
        "costTrend": -4,
        "automationSavings": 58000,
        "sampleSize": 580
      },
      {
        "industry": "fintech",
        "displayName": "FinTech",
        "costUSD": 120000,
        "vsGlobal": -27,
        "costTrend": -5,
        "automationSavings": 48000,
        "sampleSize": 810
      },
      {
        "industry": "saas",
        "displayName": "SaaS / Cloud",
        "costUSD": 98000,
        "vsGlobal": -40,
        "costTrend": -7,
        "automationSavings": 39200,
        "sampleSize": 920
      }
    ],
    "byMaturityBand": [
      {
        "band": "0-39",
        "avgCost": 285000
      },
      {
        "band": "40-54",
        "avgCost": 210000
      },
      {
        "band": "55-69",
        "avgCost": 169000
      },
      {
        "band": "70-84",
        "avgCost": 112000
      },
      {
        "band": "85-100",
        "avgCost": 78000
      }
    ],
    "costBreakdown": [
      {
        "category": "QSA Fees",
        "pct": 34
      },
      {
        "category": "Internal Labour",
        "pct": 34
      },
      {
        "category": "Tooling & Automation",
        "pct": 16
      },
      {
        "category": "Remediation",
        "pct": 16
      }
    ],
    "asOf": "2026-04-28T08:29:51.784Z"
  },
  "automation": {
    "globalAvg": 59,
    "byIndustry": [
      {
        "industry": "saas",
        "displayName": "SaaS / Cloud",
        "automationRate": 74,
        "manualPct": 26,
        "trend": 8,
        "sampleSize": 920
      },
      {
        "industry": "fintech",
        "displayName": "FinTech",
        "automationRate": 72,
        "manualPct": 28,
        "trend": 7,
        "sampleSize": 810
      },
      {
        "industry": "financial-services",
        "displayName": "Financial Services",
        "automationRate": 62,
        "manualPct": 38,
        "trend": 9,
        "sampleSize": 720
      },
      {
        "industry": "ecommerce",
        "displayName": "E-Commerce",
        "automationRate": 55,
        "manualPct": 45,
        "trend": 11,
        "sampleSize": 580
      },
      {
        "industry": "retail",
        "displayName": "Retail",
        "automationRate": 48,
        "manualPct": 52,
        "trend": 12,
        "sampleSize": 640
      },
      {
        "industry": "healthcare",
        "displayName": "Healthcare",
        "automationRate": 42,
        "manualPct": 58,
        "trend": 10,
        "sampleSize": 480
      },
      {
        "industry": "hospitality",
        "displayName": "Hospitality",
        "automationRate": 35,
        "manualPct": 65,
        "trend": 14,
        "sampleSize": 390
      }
    ],
    "historicalTrend": [
      {
        "year": 2019,
        "rate": 22
      },
      {
        "year": 2020,
        "rate": 27
      },
      {
        "year": 2021,
        "rate": 32
      },
      {
        "year": 2022,
        "rate": 38
      },
      {
        "year": 2023,
        "rate": 44
      },
      {
        "year": 2024,
        "rate": 49
      },
      {
        "year": 2025,
        "rate": 53
      },
      {
        "year": 2026,
        "rate": 55
      }
    ],
    "efficiencyRelationship": [
      {
        "automationRate": 72,
        "costUSD": 120000,
        "auditHours": 780,
        "industry": "FinTech"
      },
      {
        "automationRate": 74,
        "costUSD": 98000,
        "auditHours": 650,
        "industry": "SaaS / Cloud"
      },
      {
        "automationRate": 48,
        "costUSD": 168000,
        "auditHours": 980,
        "industry": "Retail"
      },
      {
        "automationRate": 55,
        "costUSD": 145000,
        "auditHours": 890,
        "industry": "E-Commerce"
      },
      {
        "automationRate": 35,
        "costUSD": 178000,
        "auditHours": 1120,
        "industry": "Hospitality"
      },
      {
        "automationRate": 62,
        "costUSD": 280000,
        "auditHours": 1380,
        "industry": "Financial Services"
      },
      {
        "automationRate": 42,
        "costUSD": 195000,
        "auditHours": 1050,
        "industry": "Healthcare"
      }
    ],
    "asOf": "2026-04-28T08:29:51.784Z"
  },
  "regional": {
    "regions": [
      {
        "region": "germany",
        "displayName": "Germany",
        "avgMaturity": 67,
        "avgAuditHours": 840,
        "avgCostUSD": 134000,
        "automationRate": 68,
        "yoyDelta": 3,
        "sampleSize": 290,
        "riskTier": "Low"
      },
      {
        "region": "singapore",
        "displayName": "Singapore",
        "avgMaturity": 65,
        "avgAuditHours": 760,
        "avgCostUSD": 128000,
        "automationRate": 70,
        "yoyDelta": 5,
        "sampleSize": 210,
        "riskTier": "Low"
      },
      {
        "region": "uk",
        "displayName": "United Kingdom",
        "avgMaturity": 64,
        "avgAuditHours": 920,
        "avgCostUSD": 142000,
        "automationRate": 65,
        "yoyDelta": 4,
        "sampleSize": 680,
        "riskTier": "Low-Moderate"
      },
      {
        "region": "australia",
        "displayName": "Australia",
        "avgMaturity": 63,
        "avgAuditHours": 840,
        "avgCostUSD": 139000,
        "automationRate": 62,
        "yoyDelta": 3,
        "sampleSize": 180,
        "riskTier": "Low-Moderate"
      },
      {
        "region": "canada",
        "displayName": "Canada",
        "avgMaturity": 60,
        "avgAuditHours": 1020,
        "avgCostUSD": 156000,
        "automationRate": 60,
        "yoyDelta": 2,
        "sampleSize": 240,
        "riskTier": "Low-Moderate"
      },
      {
        "region": "us",
        "displayName": "United States",
        "avgMaturity": 58,
        "avgAuditHours": 1180,
        "avgCostUSD": 169000,
        "automationRate": 58,
        "yoyDelta": 3,
        "sampleSize": 1820,
        "riskTier": "Moderate"
      },
      {
        "region": "india",
        "displayName": "India",
        "avgMaturity": 54,
        "avgAuditHours": 920,
        "avgCostUSD": 89000,
        "automationRate": 55,
        "yoyDelta": 6,
        "sampleSize": 160,
        "riskTier": "Elevated"
      }
    ],
    "topRegion": {
      "region": "germany",
      "displayName": "Germany",
      "avgMaturity": 67,
      "avgAuditHours": 840,
      "avgCostUSD": 134000,
      "automationRate": 68,
      "yoyDelta": 3,
      "sampleSize": 290,
      "riskTier": "Low"
    },
    "bottomRegion": {
      "region": "india",
      "displayName": "India",
      "avgMaturity": 54,
      "avgAuditHours": 920,
      "avgCostUSD": 89000,
      "automationRate": 55,
      "yoyDelta": 6,
      "sampleSize": 160,
      "riskTier": "Elevated"
    },
    "asOf": "2026-04-28T08:29:51.784Z"
  },
  "feed": {
    "entries": [
      {
        "id": "signal-0",
        "title": "FinTech remediation delays rising (+12% YoY)",
        "detail": "FinTech average remediation time is 6.2 days — up 12% YoY. Primary driver: API security monitoring (Req. 6.4).",
        "type": "signal",
        "severity": "critical",
        "industry": "FinTech",
        "metric": "remediation",
        "changedAt": "2026-04-28T08:29:51.785Z"
      },
      {
        "id": "signal-1",
        "title": "Retail remediation delays rising (+8% YoY)",
        "detail": "Retail average remediation time is 9.1 days — up 8% YoY. Primary driver: POS terminal firmware patching (Req. 6.3).",
        "type": "signal",
        "severity": "warning",
        "industry": "Retail",
        "metric": "remediation",
        "changedAt": "2026-04-27T08:29:51.785Z"
      },
      {
        "id": "signal-2",
        "title": "Hospitality remediation delays rising (+5% YoY)",
        "detail": "Hospitality average remediation time is 10.4 days — up 5% YoY. Primary driver: Multi-property network segmentation (Req. 1.3).",
        "type": "signal",
        "severity": "warning",
        "industry": "Hospitality",
        "metric": "remediation",
        "changedAt": "2026-04-26T08:29:51.785Z"
      },
      {
        "id": "signal-3",
        "title": "FinTech compliance maturity up 3 pts YoY",
        "detail": "FinTech now averages 68/100 maturity (+3 pts vs last year). Sample: 810 organisations.",
        "type": "signal",
        "severity": "positive",
        "industry": "FinTech",
        "metric": "maturity",
        "changedAt": "2026-04-25T08:29:51.785Z"
      },
      {
        "id": "signal-4",
        "title": "FinTech compliance cost falling 5% YoY",
        "detail": "Average FinTech compliance spend is $120k/yr (down 5%). Automation savings are the primary cost driver.",
        "type": "signal",
        "severity": "positive",
        "industry": "FinTech",
        "metric": "cost",
        "changedAt": "2026-04-24T08:29:51.785Z"
      },
      {
        "id": "signal-5",
        "title": "SaaS / Cloud compliance maturity up 4 pts YoY",
        "detail": "SaaS / Cloud now averages 65/100 maturity (+4 pts vs last year). Sample: 920 organisations.",
        "type": "signal",
        "severity": "positive",
        "industry": "SaaS / Cloud",
        "metric": "maturity",
        "changedAt": "2026-04-23T08:29:51.785Z"
      },
      {
        "id": "signal-6",
        "title": "SaaS / Cloud automation adoption accelerating (+8pp YoY)",
        "detail": "SaaS / Cloud organisations now use 74% automation on average — up 8 percentage points year-on-year, the fastest growth rate in the sector.",
        "type": "signal",
        "severity": "positive",
        "industry": "SaaS / Cloud",
        "metric": "automation",
        "changedAt": "2026-04-22T08:29:51.785Z"
      },
      {
        "id": "signal-7",
        "title": "SaaS / Cloud compliance cost falling 7% YoY",
        "detail": "Average SaaS / Cloud compliance spend is $98k/yr (down 7%). Automation savings are the primary cost driver.",
        "type": "signal",
        "severity": "positive",
        "industry": "SaaS / Cloud",
        "metric": "cost",
        "changedAt": "2026-04-21T08:29:51.785Z"
      },
      {
        "id": "changelog-cl-015",
        "title": "Verification note: maturity score remains provisional — full verification scheduled Q2 2026",
        "detail": "Following internal review, the cross-industry maturity score (58/100) will remain at provisional status until Q2 2026 verification cycle completes. Value is directionally sound; full verification requires independent audit of benchmark collection methodology.",
        "type": "changelog",
        "severity": "info",
        "changedAt": "2026-03-05T09:00:00Z"
      },
      {
        "id": "changelog-cl-014",
        "title": "Citation corrected: PCI DSS v4.0.1 — updated canonical URL",
        "detail": "Canonical URL updated to reflect PCI SSC document library reorganisation. Citation text unchanged. All published statistics unaffected.",
        "type": "changelog",
        "severity": "info",
        "changedAt": "2026-03-01T11:00:00Z"
      },
      {
        "id": "changelog-cl-013",
        "title": "Statistic created: average annual PCI DSS compliance cost (cross-industry)",
        "detail": "Annual compliance cost computed from benchmark submissions. Value: $287,000 USD median (provisional). Covers QSA fees, remediation, internal labour, and tooling. Excludes breach response costs.",
        "type": "changelog",
        "severity": "info",
        "changedAt": "2026-02-20T09:00:00Z"
      },
      {
        "id": "methodology-current",
        "title": "Methodology v2026.1 — Active",
        "detail": "Benchmark scoring model v2026.1 is the current active methodology. Weighting: maturity 40%, evidence 25%, automation 20%, remediation 15%.",
        "type": "methodology",
        "severity": "info",
        "changedAt": "2026-01-01"
      }
    ],
    "signalCount": {
      "critical": 1,
      "warning": 2,
      "positive": 5
    },
    "asOf": "2026-04-28T08:29:51.786Z"
  },
  "meta": {
    "datasetId": "GRCTRACK-BDS-2026-001",
    "methodologyVersion": "2026.1",
    "methodologyId": "GRCTRACK-METH-2026-001",
    "displayMode": "provisional",
    "verificationStatus": "provisional",
    "disclaimer": "Data is provisional — directionally indicative, k-anonymity k≥5. Not verified benchmark data. Cite as \"GRCTrack Benchmark Dataset 2026 (provisional)\".",
    "sampleSize": 4721,
    "lastUpdated": "2026-04-28T08:29:51.786Z"
  },
  "exportMeta": {
    "datasetId": "GRCTRACK-BDS-2026-001",
    "methodologyVersion": "2026.1",
    "methodologyId": "GRCTRACK-METH-2026-001",
    "generatedAt": "2026-04-28T08:29:51.786Z",
    "disclaimer": "Data is provisional — directionally indicative, k-anonymity k≥5. Not verified benchmark data. Cite as \"GRCTrack Benchmark Dataset 2026 (provisional)\".",
    "attribution": "GRCTrack Intelligence — https://grctrack.com"
  }
}