Skip to content
Dataset · v2026.1

Compliance Maturity Dataset v2026.1

Percentile maturity distributions (P10–P90) per industry from 4,721 PCI DSS compliance programmes

7 IndustriesP10–P90 Distributions4,721 RecordsCSV + JSON4 Maturity Tiersk-Anonymity Protected

Maturity Tier Reference

Foundational
0–40
~8% of programmes
Developing
41–60
~55% of programmes
Established
61–75
~29% of programmes
Advanced
76–100
~8% of programmes

Data Preview — Percentile Distribution by Industry

industryp10p25p50_medianp75p90tier_at_p50sample_size
fintech4255687886Established810
saas4052657684Established920
financial_services3850637482Established480
healthcare3546587079Developing560
ecommerce3344556776Developing620
retail3041526373Developing540
hospitality2536475868Developing310

Download & Access

Download CSV

Full percentile distribution dataset as CSV with P10–P90 columns per industry cohort.

Download CSV

Access via API

Programmatic access via /api/intelligence/maturity-index

View API Endpoint

Frequently Asked Questions

What do P10, P25, P50, P75, P90 mean in this dataset?

Percentiles represent the distribution of maturity scores within each industry cohort. P50 is the median — half of programmes score above and half below. P10 represents bottom-decile performers and P90 represents top-decile performers. Use these to understand where your programme sits relative to peers.

How is the maturity score calculated?

The GRCTrack maturity score (0–100) is a weighted composite: evidence sufficiency (30%), automation rate (25%), remediation velocity (25%), and control coverage (20%). Scores are normalised within each industry cohort to account for scope differences before cross-industry comparison.

Can I use this dataset to report my maturity tier?

Yes. The dataset supports positioning within four tiers: Foundational (0–40), Developing (41–60), Established (61–75), and Advanced (76–100). Tier boundaries are consistent across industry cohorts so cross-sector comparison is valid.

Related Resources