Skip to content
Secantra

Why a compliance percentage should never be typed into a box

4 min read · Published 21 Aug 2026 · Secantra editorial

The number everybody wants

Every steering committee asks the same question: how compliant are we? And every compliance tool that has ever been sold answers it with a percentage — 78 % DORA-ready, 91 % of Annex A implemented — because a percentage fits on a slide and moves in the right direction between two meetings.

The trouble is not the percentage. It is where it comes from. In most organisations somebody assembles it: a spreadsheet with a status column, a formula, a judgement call about what “implemented” means this quarter. The moment a human types the status, the number stops describing the organisation and starts describing the person’s assessment of it. Both are useful. Only one is a fact.

A compliance figure is a fact only if you can point at the records it was computed from — and recompute it, tomorrow, from those records alone.

What “derived” has to mean

Derived posture is not “the tool draws a chart”. It means the number is a projection of a small set of records that each carry their own owner and history:

  1. What was adopted. A framework at a pinned version — DORA, NIS2, ISO/IEC 27001 Annex A. Not “we do ISO”, but this requirement set, at this version, adopted on this date.
  2. What applies. An applicability decision per requirement: applicable, not applicable with a reason, deferred to a date, waived, an approved exception — scoped tenant-wide or to a specific IT service, business solution or process. A requirement nobody has decided on is undecided, and undecided is not the same as “not applicable”.
  3. What covers it. Controls mapped to requirements, and links from those controls to the assets they protect, each with a status — compliant, partial, non-compliant.
  4. What proves it. Evidence with a date. Evidence older than its review period counts as stale, whatever the link says.

Posture is arithmetic on those four. Change a record and the number moves; you can always ask why it moved and get a record back as the answer. Nobody types the number.

Three things this changes for the team

Undecided becomes visible. In a typed spreadsheet, “not yet looked at” hides behind “not applicable” or a blank cell. In a derived model it is a bucket with a count. The first thing a derived posture usually shows a new team is not how compliant they are but how many requirements they have never decided on — and that is the honest starting point.

Stale evidence stops being compliant. A control marked implemented in 2024 with a policy PDF from 2022 is a status, not a state. When recency is part of the computation, the number decays on its own unless the work keeps happening. That is uncomfortable and correct.

“Why did it drop?” has an answer. Because a scope changed, a control link was set to partial, an evidence item aged out, a new framework version was adopted. Each of those is a record with an actor and a timestamp. A typed number that drops has no explanation except that somebody changed their mind.

Freeze it, do not edit it

There is one legitimate reason to want a fixed number: reporting. The board saw 74 % in March; in June you need to show what changed. The wrong way is to keep a spreadsheet of past percentages. The right way is to take a snapshot — a frozen copy of the derived state at that moment: which adoptions, which applicability buckets, which coverage buckets, which open work items — and never edit it.

That distinction matters more than it sounds. A snapshot is a copy of the record, not a new source of truth. Nobody can adjust it to make a trend look better; if the March number was wrong, the June snapshot shows the correction and the record shows why. Two frozen copies, side by side, are the report the management body actually asked for: not a percentage, but a delta with reasons.

What this looks like in Secantra

The compliance module is built on this rule and does not offer the alternative. There is no field to type a posture into. Adoption pins a published framework version; applicability is a decision per requirement with a status, a reason and a scope; controls link to requirements and to assets with a compliance status; evidence carries dates and a recency check. Posture is computed from those, and a posture snapshot is a point-in-time freeze of the derived state — immutable, no update or delete. If a number on a dashboard is wrong, the fix is a record, and the record leaves a trail.

Checklist

  • No status is typed at framework or requirement level — every posture number is computed from records
  • Undecided requirements are counted and shown, not hidden in “not applicable”
  • Evidence has a date and a review period; stale evidence lowers the number by itself
  • Every change in posture is explainable by a record with an actor and a timestamp
  • Reporting uses frozen snapshots of the derived state, never an editable table of past percentages

Related