Compliance Maturity Dataset v2026.1
Percentile maturity distributions (P10–P90) per industry from 4,721 PCI DSS compliance programmes
Maturity Tier Reference
Data Preview — Percentile Distribution by Industry
| industry | p10 | p25 | p50_median | p75 | p90 | tier_at_p50 | sample_size |
|---|---|---|---|---|---|---|---|
| fintech | 42 | 55 | 68 | 78 | 86 | Established | 810 |
| saas | 40 | 52 | 65 | 76 | 84 | Established | 920 |
| financial_services | 38 | 50 | 63 | 74 | 82 | Established | 480 |
| healthcare | 35 | 46 | 58 | 70 | 79 | Developing | 560 |
| ecommerce | 33 | 44 | 55 | 67 | 76 | Developing | 620 |
| retail | 30 | 41 | 52 | 63 | 73 | Developing | 540 |
| hospitality | 25 | 36 | 47 | 58 | 68 | Developing | 310 |
Download & Access
Download CSV
Full percentile distribution dataset as CSV with P10–P90 columns per industry cohort.
Download CSVFrequently Asked Questions
What do P10, P25, P50, P75, P90 mean in this dataset?
Percentiles represent the distribution of maturity scores within each industry cohort. P50 is the median — half of programmes score above and half below. P10 represents bottom-decile performers and P90 represents top-decile performers. Use these to understand where your programme sits relative to peers.
How is the maturity score calculated?
The GRCTrack maturity score (0–100) is a weighted composite: evidence sufficiency (30%), automation rate (25%), remediation velocity (25%), and control coverage (20%). Scores are normalised within each industry cohort to account for scope differences before cross-industry comparison.
Can I use this dataset to report my maturity tier?
Yes. The dataset supports positioning within four tiers: Foundational (0–40), Developing (41–60), Established (61–75), and Advanced (76–100). Tier boundaries are consistent across industry cohorts so cross-sector comparison is valid.