Cybersecurity Compliance Research & Benchmark Data | Lazarus Alliance

Lazarus Alliance Research publishes original cybersecurity audit, assessment, and compliance intelligence derived from aggregate, anonymized engagement data. Research covers CMMC, FedRAMP, SOC examinations, ISO certification, and related cybersecurity and governance frameworks. Reports are designed to provide security leaders, government contractors, compliance professionals, researchers, and journalists with evidence-based benchmarks drawn from real-world assessment experience.

Coming Soon

  • 2026 ISO 27001 Certification Benchmark Report
  • 2026 NIST 800-53 Assessment Benchmark Report

2026 Research Reports

Frequently Asked Questions

Published 2026 reports include:

Coming soon: 2026 ISO 27001 Certification Benchmark Report and 2026 NIST 800-53 Assessment Benchmark Report.

Each report aggregates completed assessments performed by Lazarus Alliance during the stated reporting period (currently January 2025–June 2026). Only completed formal assessments, examinations, or ACAB attestations are included. Readiness workshops, gap analyses, and documentation-only reviews are excluded unless a report explicitly states otherwise.

Organizational identifiers, system names, contract numbers, ORI numbers, agency sponsors, and proprietary details are removed before publication.

Yes. All published research uses aggregate, anonymized statistics. Individual client identities, assessment outcomes, and proprietary evidence remain confidential. Reports are licensed for citation of aggregate statistics with attribution; they do not disclose client-level data.

No. The reports are observational. They describe patterns across completed engagements and do not guarantee future performance, certification outcomes, authorization results, or timelines.

Individual results vary based on preparation quality, boundary complexity, evidence maturity, inheritance, control operation, and applicable program or agency review processes.

Lazarus Alliance publishes only aggregate, anonymized statistics after assessments are complete. The research does not identify assessed organizations and does not replace or influence individual assessment judgments.

Assessment independence is maintained under the applicable professional and accreditation requirements, including ISO/IEC 17020 (C3PAO / FedRAMP 3PAO), AICPA standards (SOC examinations), Cyber AB requirements, FedRAMP 3PAO requirements, and NTIS ACAB obligations for LADMF work.

The current reports cover completed assessments from January 2025 through June 2026 and were published in August 2026. Each report lists its version number, sample size, and methodology on the report page.

Yes. Aggregate statistics may be cited with attribution. Recommended short citations:

  • Lazarus Alliance (2026). 2026 CMMC Assessment Benchmark Report (N=47).
  • Lazarus Alliance (2026). 2026 FedRAMP Assessment Benchmark Report (N=38).
  • Lazarus Alliance (2026). 2026 SOC 2 Audit Benchmark Report (N=75).
  • Lazarus Alliance (2026). 2026 CJIS Certification Benchmark Report (N=28).
  • Lazarus Alliance (2026). 2026 LADMF Certification Benchmark Report (N=18).

Full citation formats appear on each report page.

Across the published datasets, additional evidence requests were common: 89% of CMMC Level 2 assessments, 95% of FedRAMP assessments, 88% of SOC 2 examinations, 86% of CJIS assessments, and 83% of LADMF assessments.

The most frequent causes are screenshots without context, policies without operational proof, incomplete log samples, unsupported inheritance claims, outdated inventories or baselines, and evidence that is not mapped to the specific control or practice being tested. Volume alone is a weak predictor of efficiency. Quality and mapping matter more.

Yes. ISO 27001 and NIST 800-53 benchmark reports are listed as coming soon. Additional framework reports and updated editions may be published as datasets grow. Check this page for new releases.

Research Methodology & Editorial Standards

  • Dataset Inclusion and Exclusion Rules

    Dataset Inclusion and Exclusion Rules. Lazarus Alliance Research datasets are derived from completed professional assessment engagements that meet the defined scope, framework, assessment type, and reporting period established for each study. Records are included only when sufficient engagement data exists to support the measurements being reported and the engagement meets the study's stated eligibility criteria. Readiness reviews, consulting engagements, incomplete or cancelled assessments, duplicate records, test data, and engagements lacking sufficient information for the applicable analysis are excluded unless a specific research publication expressly states otherwise. Each benchmark report identifies its population, sample size, observation period, and any additional inclusion or exclusion criteria so readers can understand the population represented by the findings.

  • Anonymization Methodology

    Anonymization Methodology. Lazarus Alliance Research is designed to produce useful industry benchmarks without disclosing confidential client information. Research datasets are de-identified before analysis and publication by removing or suppressing client names, personnel names, system names, contract identifiers, IP addresses, account information, proprietary artifacts, and other information that could directly identify an assessed organization or its environment. Findings are reported in aggregate wherever practicable, and potentially identifying combinations of characteristics may be generalized, grouped, or omitted. Lazarus Alliance does not publish client-specific assessment findings or confidential evidence through its research program unless disclosure has been expressly authorized.

  • Statistical Methodology

    Statistical Methodology. Lazarus Alliance Research uses descriptive statistical methods appropriate to the size, characteristics, and completeness of each dataset. Published analyses may include counts, percentages, distributions, medians, ranges, and other summary measures calculated from the eligible observations available for a particular metric. Denominators are identified where they differ from the overall study population, and missing or inapplicable observations are not automatically treated as negative findings. Results describe the observed dataset and should not be interpreted as guaranteed outcomes, causal relationships, or statistically representative of every organization subject to the applicable framework. Where sample size or data limitations materially affect interpretation, those limitations are disclosed with the research.

  • Publication and Version Policy

    Publication and Version Policy. Lazarus Alliance Research publications are dated and maintained as versioned research resources so readers can distinguish historical findings from subsequent updates. Material revisions to datasets, methodology, regulatory context, calculations, or conclusions are reflected through an updated publication or revision date and, where appropriate, explanatory revision notes. Minor editorial changes that do not alter the meaning of the research may be made without issuing a new research version. When regulatory requirements change after publication, Lazarus Alliance may update explanatory material while preserving the historical context and observation period of the underlying dataset rather than retroactively treating historical assessments as though they occurred under newer requirements.

  • Correction Policy

    Correction Policy. Lazarus Alliance is committed to correcting material factual, analytical, attribution, or presentation errors identified in its published research. Reported issues are evaluated against the underlying dataset, engagement records, applicable authoritative sources, and publication methodology. When an error could materially affect interpretation of a finding, Lazarus Alliance will correct the publication and, where appropriate, identify the nature or date of the correction. Corrections are intended to improve the accuracy of the research without obscuring the historical record. Changes in regulations, standards, or government guidance occurring after publication are distinguished from errors in the original research.

  • Regulatory-Source Hierarchy

    Regulatory-Source Hierarchy. Regulatory and compliance statements in Lazarus Alliance Research are grounded in authoritative primary sources whenever available. Priority is given to enacted statutes and regulations, official government publications and program requirements, controlling contract clauses, and standards or normative publications issued by the organization responsible for the applicable framework. Official implementation guidance, FAQs, program notices, and recognized accreditation or certification authorities are used as secondary interpretive sources where appropriate. Industry commentary, news reporting, vendor materials, and other third-party sources may provide context but are not treated as controlling authority when a primary source is available. When authoritative sources conflict or requirements are undergoing transition, the publication identifies the uncertainty rather than presenting an interpretation as settled fact.

  • Editorial Evidence Standard

    Editorial Evidence Standard. Material factual claims published by Lazarus Alliance Research must be supported by an identifiable evidentiary basis. Quantitative claims derived from Lazarus Alliance data must be traceable to the applicable dataset and accompanied by sufficient context to understand the sample, period, denominator, methodology, and relevant limitations. Regulatory and technical requirements must be supported by authoritative sources and must distinguish mandatory requirements from recommendations, interpretations, and professional observations. Client outcomes, performance improvements, cost reductions, timelines, comparative claims, and similar assertions are not presented as general facts unless adequate evidence supports them. Claims that cannot be adequately substantiated are qualified, attributed, identified as estimates or professional observations, or removed.

  • Author and Reviewer Qualifications

    Author and Reviewer Qualifications. Lazarus Alliance Research is prepared and reviewed by cybersecurity, risk, privacy, audit, and compliance professionals with experience relevant to the subject matter of each publication. Depending on the research topic, contributors may include Cybervisors®, independent assessors, auditors, technical specialists, and professionals experienced with the applicable regulatory or standards environment. Publications involving specialized frameworks are subject to technical review by personnel familiar with the relevant assessment requirements and authoritative sources. Author and reviewer credentials are presented where appropriate to help readers evaluate subject-matter expertise, while editorial and technical review does not replace the reader's responsibility to evaluate requirements applicable to a particular organization.

  • Conflict of Interest and Independence

    Conflict of Interest and Independence Statement. Lazarus Alliance conducts research in a manner intended to preserve the professional independence, objectivity, confidentiality, and impartiality required of its assessment activities. Research findings are not altered to favor a client, technology provider, commercial product, or desired marketing outcome, and commercial considerations do not determine whether an observed result is included in an eligible research dataset. Client information obtained through assessment engagements remains subject to applicable confidentiality and independence requirements. Where Lazarus Alliance performs independent third-party assessments, research, publications, advisory activities, and commercial relationships are managed so they do not impair the independence or impartiality required by the applicable accreditation, assessment program, professional standard, or contractual obligation.

Talk with one of our experts

Our Lazarus Alliance Cybervisor™ teams have experience performing thousands of assessments for organizations providing services to clients around the world.

We're here to answer any questions you may have.

Download our company brochure.