795 practitioners
told the truth.
The largest independent survey of GRC practitioners — no vendor funding, no sponsor influence, no analyst filter. This is what the industry actually looks like.
Why this report exists
Every year, analysts and vendors publish reports about the GRC market. They survey their own customers, interview their own prospects, and produce findings that conveniently validate their own positioning.
Most GRC market reports survey 100 to 300 people, primarily enterprise buyers sourced through vendor relationships. This survey reached nearly 800 practitioners across every seniority level, team size, and practitioner type — the full spectrum, not just the segment that takes analyst calls.
Who responded
PRACTITIONERS
The consultant ratio is the hidden variable in every GRC market analysis. When 29% of respondents advise multiple organizations, their tool preferences carry disproportionate influence — a single consultant recommending a tool to ten clients generates more pipeline than ten individual buyers.
The traditional vendor playbook targets the buyer at a single company. The GRC market rewards whoever wins the advisor.
The shape of GRC teams
4 PEOPLE OR FEWER
COMPLETELY ALONE
THE UNDERSERVED CORE
Solo does not mean junior. 40% of entry-level practitioners work solo with an average skill of 3.6 — but 19 CISOs (20.9% of all CISOs) also work solo, averaging 6.3. Same team size, completely different reality. One group is drowning. The other chose to swim alone.
USE NO TOOL AT ALL
COMMERCIAL ADOPTION
COMMERCIAL ADOPTION
SPREADSHEETS COLLAPSE TO 3%
Each team-size threshold is a buying trigger. The ladder is consistent: nothing, then spreadsheet, then commercial, then platform.
Among solo practitioners who do adopt, Vanta leads with a 7.4x overrepresentation versus its non-solo share (Fisher's exact p=0.0002). When one person runs the entire compliance function, automation is the only way the job gets done.
And 28 of those solo practitioners are entry-level — no team, no mentorship, no architecture. They default to spreadsheets because that is what they know. This is where compliance theatre is born.
Why spreadsheets still win
Almost every competitor analysis in GRC starts with the wrong assumption: that you are fighting other vendors. You are fighting inertia, spreadsheets, and "I'll just use Notion."
Spreadsheets persist because many practitioners lack the technical confidence to adopt and configure a dedicated platform. The switching cost is not financial. It is cognitive.
The consultant multiplier makes it worse: 64.9% of consultants use non-commercial solutions — an estimated 1,480 annual decisions steered away from commercial GRC products. The most influential distribution channel in the industry is actively recommending against the category.
Buyers don't use the market leader
(17.3% FOR EVERYONE ELSE)
COMMERCIAL TOOL AT ALL
THE MOST CAPABLE LEVEL
The people who approve GRC budgets don't use the market leader. Custom builds, spreadsheets, open source, or nothing — the budget holders have rejected the entire category. And they know what's available: CISOs evaluate tools rigorously, and they're choosing to build rather than buy.
The Director level is the most contested buyer segment in the dataset (HHI 924 — the lowest concentration of any seniority level). Every vendor has a shot. Nobody has a lock.
And then there's the auditor problem: your customer invests in a platform that produces evidence in structured formats. Their auditor expects screenshots and spreadsheet exports. The platform's value collapses — not because the product failed, but because the person validating the output won't accept the format.
Your tool choice is a mirror
Drata
TECHNICAL MID-MARKET- Most technical users in the sample: 6.5 avg, zero below 4
- 60% score 7 or higher
- Most balanced team-size distribution of any vendor
Vanta
AUTOMATION-FIRST STARTUP- Strong technical users: 6.0 avg
- Dramatic small-team skew: 30% solo, 36% in teams of 2–4
- The power user is the one-person compliance department
ServiceNow · AuditBoard
ENTERPRISE INCUMBENT- Mid-range skill (5.3), 43% of users in teams of 11+
- AuditBoard mirrors it: 68% in teams of 5+
- Bought on integration, not capability
Open Source
THE POLARIZED SIGNAL- 69% of users at the skill extremes, only 31% mid
- Ahead of OneTrust. Ahead of Archer.
- 21% CISOs, 45% consultants — the influencers
Tool-choice entropy is decaying: early respondents reported 21 distinct tools (Shannon entropy 3.71 bits); later cohorts converged on 13 (3.25 bits). The long tail is already shrinking.
The open-source signal is the one to watch. As the industry trends more technical, adoption accelerates — and commercial vendors attracting technical buyers are not competing with each other. They're competing with build-it-yourself.
The industry's defining challenge
A capability gap, not an access gap. Mid-skill practitioners have tools and budget. They lack the confidence to move beyond default configurations. Vendor onboarding solves the first week; nobody solves months two through twelve.
A career structure problem. GRC has no technical forcing function between years 3 and 15. You can reach Director without writing a policy-as-code rule or configuring an API integration. The ladder doesn't reward technical growth because it doesn't require it.
A composition problem, not a development problem. The industry looks more technical because the audience expanded to include engineers and security professionals (avg 6.3) — not because existing practitioners (avg 5.3) built new skills. That bridge isn't a training program. It's a hiring pattern.
Five strategic takeaways
The mid-market is the battleground
59% of practitioners use no commercial GRC tool. No tool holds above 18% share even among tool users. Salesforce holds 21% of CRM; ServiceNow 42% of ITSM; Datadog 52% of observability. GRC's top "vendor" is a spreadsheet — the least consolidated major enterprise software category in the market.
Enterprise is decided. For now.
ServiceNow owns enterprise GRC with 34 users in the 11+ segment — nearly 5x spreadsheet usage there. The real question: can automation vendors grow their footprint before ServiceNow absorbs their innovations?
The open source threat is real
38 users — ahead of OneTrust, ahead of Archer. Average skill 6.3, 21% CISOs, 45% consultants. The most technically skilled, most senior, most influential practitioners choose open source.
CISOs don't trust the category
7.4% of CISOs use ServiceNow. The most important buyer segment prefers custom tools, spreadsheets, and open source over every commercial platform — an underlying trust problem with the key security persona.
The skills gap is the biggest strategic issue
Every finding in this report traces back to it. Spreadsheet dependency, CISO custom builds, mid-market fragmentation — all downstream of one number: 5.3 average technical skill. The next year will be defined by which side of this gap you're on.
Methodology
Platform: Beehiiv subscription form · Period: April 2025 – March 2026 · Responses: 795 (748 unique after dedup) · Distribution: GRC Engineer newsletter subscribers and community.
Integrity: 44 emails submitted more than once; analysis uses the latest response per unique email. 32 vendor employees identified via domain matching; 15 of 22 who answered the tool question selected their own product — included but flagged.
Completeness: three structural tiers (5, 6, 7 questions answered by 140/253/399 respondents). Entry-level respondents are 3.9x overrepresented among partial responders; tool-share data skews mid-career and senior.
Bias: respondents self-selected from a GRC-focused audience; results may over-represent practitioners actively investing in professional development. Skill is self-assessed (1–10); interpret within seniority bands.
