The State of Physical Security & Compliance
Why the enterprise can't say who's in the building
Download the PDF
of enterprises give contractors no single identity across their sites
Compliance study, n=782
report at least one unauthorized or unverified person in a workspace where they shouldn't be in the past year
Sensitive-workspace study, n=294
cannot confidently say who was in their building yesterday
Sensitive-workspace study, n=294
are sure they would pass an audit today, yet most had an incident
Compliance study, n=782
Two studies, one security challenge
Organizations have invested heavily in physical security. They have access controls, visitor systems, security teams, policies, and compliance programs. Yet many still struggle to answer one of the most fundamental questions in physical security: who was actually here?
That disconnect is at the heart of this report. The challenge isn't simply whether security controls exist. It's whether identity, authorization, access, presence, and evidence connect well enough to give teams a clear picture of what happened and the proof to back it up.
We saw that challenge emerge from two separate surveys conducted in 2026. One examined the tooling and compliance practices of 782 enterprise leaders. The other focused on 294 leaders protecting some of the country's most sensitive workplaces, including frontier AI labs, defense technology companies, and biotech and medical R&D organizations.
The studies asked different questions of different populations. We expected them to tell different stories. Instead, they surfaced a similar pattern.
Organizations have security controls in place, but those controls do not always operate as a continuous chain. Identity may be verified in one system, authorization determined in another, access granted somewhere else, and presence recorded separately. Different workplaces require different safeguards, but fragmentation can make it harder to answer the questions that matter: Who is this person? What are they authorized to access? Are they onsite now? When should their access change or end? And can the organization demonstrate afterward that the appropriate controls were followed?
Throughout this report, every figure is tagged with the study it came from. The datasets are analyzed separately and compared, never combined into a blended result. Where similar patterns emerge, they reflect two distinct populations answering different questions and pointing in a similar direction.
The research doesn't reveal a lack of security. It reveals how difficult it can be to connect the pieces of security into a complete picture.
Sophisticated security programs still face a fundamental challenge: connecting identity, authorization, presence, and evidence. Confidence is high. The opportunity is to make the chain easier to verify.
They feel secure. Are they?
Ask the leaders doing some of the most sensitive work in the world whether their program would stop an intruder, and most say yes. Ask what is actually instrumented behind that confidence, and the number drops. A net 58% believe their program would prevent unauthorized physical access, yet only 52% have badge control on sensitive doors and only 47% escort visitors at all times.
The belief is running ahead of the build. And confidence is not universal. The same question that produces a 58% majority also leaves 42% who will not say their program would stop an intruder, including 35% who actively doubt it. The picture splits two ways: a slight majority who feel protected but have not built the controls to be, and a large minority who already know they are exposed.
What lab and R&D leaders believe about their own program
Thinking about your organization’s overall physical security program for sensitive areas, to what extent do you agree with each of the following? (net agree, strongly + somewhat)
In practice, the security controls in place vary considerably. Badge or key-card control on sensitive doors is present at just over half. Escorting visitors, capturing a government ID, revoking a terminated employee’s access within a day, and maintaining an auditable visit record are each used by fewer than half. These controls will not be appropriate in exactly the same way for every environment, but together they show how differently organizations approach identity verification, access governance, and evidence.
What they’ve actually built
Which of the following are currently part of your physical security program for sensitive areas? Select all that apply. (multi-select, exceeds 100%)
Regulated frameworks often require longer retention; six years under HIPAA and five under ITAR, so 12 months is a floor, not a compliance bar
The research shows a wide range of physical security approaches. In the sensitive-workspace study, 92% lack at least one of five common controls measured across identity verification, access governance, and documentation. That doesn't necessarily mean those organizations are insecure. Different environments require different controls based on their risks, operations, and compliance obligations.
Confidence stays high across both studies. In the broader compliance study of 782 enterprise leaders, 62% are very confident they could pass a physical-security audit today with no time to prepare, and another 34% are somewhat confident.
Taken together, the findings shift the question from whether organizations have the "right" set of controls to whether the controls they choose work together, are consistently applied, and can be demonstrated when needed.
The broad enterprise is just as sure
If your organization had to pass a physical security compliance audit today, with no time to prepare, how confident are you? (single-select)
58% believe their program would stop an intruder, while 96% of the broader enterprise are at least somewhat confident they would pass an audit today. That confidence may be justified. The bigger question is whether the controls behind it continue to work together as people, access, and risk change.
Ask who was here yesterday, and 44% can't answer confidently
The cleanest test of a physical security program is a simple one: can you say who was inside yesterday?
For 44% of leaders doing some of the most sensitive work across industries, the answer is not a confident yes. That lack of visibility also shows up in day-to-day operations. More than a third (35%) personally saw someone within the past month they didn’t recognize and weren’t sure should be there, while one in five (19%) still rely on paper logbooks for visitor sign-in.
An unfamiliar face is not necessarily a security threat. It could be, but the real question is whether teams can quickly establish who that person is, why they are there, and whether they are authorized to be onsite.
Can you account for yesterday
We could tell you exactly who was in our building yesterday. (single-select)
The number is not an abstraction. When 44% cannot confidently reconstruct a single day, investigations and audits become harder because teams may have to piece together who was present from multiple records. The security value of presence data is the ability to move from who was expected or approved to who was actually onsite.
When they last saw a stranger inside
When was the last time you personally saw someone in your workplace you didn’t recognize and weren’t sure should have been there? (single-select)
58% of leaders saw someone they didn't recognize and weren't sure should be onsite within the past three months.
The challenge isn't simply noticing someone unfamiliar. It's having enough visibility to resolve that uncertainty quickly, without piecing together information across systems, locations, or records after the fact.
If you cannot confidently reconstruct yesterday, it becomes harder to investigate an incident or produce evidence afterward. Nearly half of these leaders are in that position. The opportunity is not to make every face recognizable; it is to make identity, authorization, and actual presence verifiable when they matter.
When uncertainty becomes unauthorized access
An unfamiliar person is not automatically a threat. But the data also captures situations where uncertainty becomes a clear access-control problem. Two in five (39%) leaders have personally seen a visitor or contractor reach a restricted physical area, and 28% have seen someone view or photograph work-in-progress on whiteboards, screens, or prototypes. These incidents show why identity must continue to stay connected to authorization after check-in, not stop at the lobby.
What leaders have personally witnessed
In the past year, have you witnessed a visitor or contractor doing any of the following? Select all that apply. (multi-select)
“A contractor that was no longer employed accessed employee areas.”
— Sensitive-workspace study respondent
Ask how often unauthorized or unverified access occurs and the frequency is striking. Four in five leaders (79%) report at least one instance in the past year of an unauthorized or unverified person ending up in a workspace where they should not be. Only 21% say it never happened.
How often unauthorized or unverified people end up where they shouldn't
How many times have unauthorized or unverified people ended up in workspaces where they shouldn’t be, in the last year? (single-select)
79% reported at least one unauthorized or unverified person in a workspace where they shouldn't be in the past year.
The broad enterprise reports related failures in different forms. In the compliance study, organizations report visitors not properly signed in (29%), employees unable to identify themselves at check-in (28%), visitors who could not be verified (22%), and unauthorized people in restricted areas (13%). Together, the findings show that access risk can emerge at verification, admission, and movement through the workplace.
The same failures show up across the whole enterprise
In the past year, has your organization experienced any of the following? (access and verification failures)
Four in five sensitive-workspace leaders report at least one instance of an unauthorized or unverified person ending up where they should not be in the past year, while the broad enterprise reports verification and access failures of its own. The security challenge extends beyond the front door: identity must remain connected to authorization throughout a person's presence.
Cross-site identity remains fragmented
Identity continuity does not mean access continuity. A contractor known at one facility should not automatically receive the same access at another. Different sites, zones, projects, and types of work may require different approvals, training, screening, escorts, credentials, or time-bound access.
What should carry across locations is the ability to know you are dealing with the same person. Yet 71% of enterprises do not give contractors a single identity across locations, while 72% of sensitive-workspace organizations do not maintain a single visitor record across sites.
These findings come from two different studies and measure different populations, but they point to a similar challenge: maintaining enough identity continuity to understand who someone is while adapting authorization to the context. Who someone is can remain consistent while what they are permitted to access changes based on their role, location, risk, and purpose.
Identity continuity also does not require every record to be centralized or retained indefinitely. In regulated environments, privacy, data segmentation, retention, and facility-specific requirements may shape how identity information is managed across locations. The security objective is to maintain enough continuity to recognize and appropriately govern the same person while applying the controls each environment requires.
The same gap in both studies: no identity that follows a person
Share of organizations with no persistent identity or visitor record across all their sites, measured in each study
No single identity across sites (Compliance)
No single visitor record across sites (Sensitive-workspace)
The two studies used different instruments and never shared a respondent, so the near-match is not an artifact of pooling. It is two separate samples pointing to the same challenge: identity continuity across locations remains uncommon. The rest of this chapter stays inside the compliance study, where the larger sample lets us see how that challenge varies by industry and scale.
How contractors are recognized across sites
When contractors return to a different site, are they recognized as the same person? (single-select)
The compliance study shows meaningful differences across industries. Identity continuity is least common in healthcare, where 22% give contractors a single identity across sites, followed by manufacturing at 26% and financial services at 31%. These figures should not be read as a universal security score: some organizations deliberately require site-specific credentialing. The operational question is whether teams can recognize the same person while still applying the right site-specific controls.
One identity across sites, by industry
Share giving contractors a single persistent identity everywhere, by industry
These figures should not be read as a universal measure of security maturity. Lower cross-site identity continuity may reflect deliberate choices around privacy, data segmentation, credentialing, retention, and facility-specific requirements, particularly in regulated environments. The survey does not tell us why organizations chose a particular architecture.
The more important security question is whether teams can recognize and appropriately govern the same person across locations while maintaining the controls each environment requires. Identity continuity does not require universal access, identical policies, or every record to be centralized and retained indefinitely.
Scale doesn't eliminate the challenge. The largest estates report slightly more identity continuity, but even at twenty or more sites, most organizations do not give contractors one identity across locations. As environments grow more complex, organizations must balance cross-site visibility with site-specific authorization, privacy, retention, and compliance requirements.
Identity continuity barely improves with scale
Share giving contractors one identity across all sites, by number of sites
Four percentage points separate the smallest multi-site operators from the largest.
Fragmentation is part of the operational challenge. 74% of enterprises run two or more visitor-management systems and 46% run six or more. As sites, acquisitions, and local processes accumulate, identity and access records can end up distributed across multiple tools.
Most enterprises run many visitor systems at once
How many visitor management systems does your organization operate across all sites? (single-select)
The research reveals a gap between identity continuity and access. With 71% of enterprises not giving contractors a single identity across sites, security teams may have to piece together records to determine who someone is and what they’re authorized to access. The opportunity is verifiable identity with access that adapts by location and role, while accounting for privacy, retention, and data-sharing requirements.
Access breaks down beyond the front door
Access risk shows up across both studies, although each measures it differently. In the compliance study, 68% of organizations reported at least one physical-security incident in the past year. In the sensitive-workspace study, 78% reported an unauthorized person reaching a restricted area.
Most organizations had an incident this year, in both studies
Share reporting at least one incident or unauthorized entry in the past year, measured in each study
Had a real physical-security incident (Compliance)
Had an unauthorized person in a restricted area (Sensitive-workspace)
High security does not buy safety. It raises the cost of getting it wrong. Organizations protecting sensitive research, technology, infrastructure, and intellectual property still report unauthorized-access incidents. Their security requirements may be more rigorous than those of a typical workplace, but higher sensitivity also increases the importance of applying the right controls to the right people, places, and situations. The frontier AI labs and defense-tech firms in the sensitive-workspace study report incidents at rates even with, or above, the ordinary offices in the compliance study.
The entry-level failures are only half of it. A second cluster of incidents comes from access that should have ended and lingered: a compliance gap surfaced during an audit (24%), a former contractor who kept access after the work ended (21%), a former employee who kept access after leaving (20%). The front door held. The memory behind it lapsed.
When access outlives the person
In the past year, has your organization experienced any of the following? (access persistence and audit gaps)
Access that outlives an engagement shows up in both studies, measured in different ways. In the compliance study, 33% reported a former contractor or employee retaining access. In the sensitive-workspace study, 31% are not confident a departed contractor loses access promptly. Together, the findings point to the importance of time-bound access and reliable revocation.
Departed contractors keep access in both populations
Share reporting retained access by a former contractor or employee, measured in each study
Former contractor or employee kept access (Compliance)
Not confident a departed contractor loses access (Sensitive-workspace)
Two studies, two populations, the same result: most organizations had a real incident this yearStrong physical security requires more than admission controls. Authorization should be tied to identity, role, location, and time, with access changing or expiring as those conditions change. The data shows lifecycle gaps in both populations, even though the studies measure them differently.
The hidden cost of running security by spreadsheet
Between incidents sits a daily operational burden. When identity, access, and presence data live across separate systems, security teams become the integration layer. Pulling access logs in a normal week means checking six or more separate systems for 49% of enterprises.
Systems a team must check just to pull access logs
How many separate systems must your team check to pull physical access logs in a normal week? (single-select)
93% must check two or more systems to answer a single access question.
That reconciliation costs real hours. 56% of teams spend six hours a week or more on manual physical-security tracking, before an audit even begins. During an active audit, the burden spikes. The issue is not only efficiency: fragmented evidence can slow the team's ability to establish what happened and demonstrate that the right controls were followed.
Hours per week lost to manual tracking
Roughly how many hours per week does your team spend on manual physical-security tracking? (single-select)
“Protocol is to immediately shut down the building, lock all exits and entries, and perform head count, badge count, and screen each employee in the building in each room.”
— Sensitive-workspace study respondent, on responding to an intruder
The pain of audit prep is not the paperwork itself. It is the scramble to assemble evidence that lives in too many places at once. A connected security chain makes that evidence easier to produce on demand.
The biggest pain in preparing for an audit
What challenges do you experience when preparing for a physical security audit? (multi-select)
Some of that system is still paper and pen, with someone typing the day's sign-in sheet into a spreadsheet at the end of a shift. Manual processes can work, but they become harder to reconcile as volume, complexity, or urgency rises. The opportunity is to make identity, access, and presence evidence easier to retrieve without depending on one person to reconstruct it.
The gap between confidence and proof
Here is where the data gets interesting. Confidence remains high even as organizations continue to experience physical security incidents. In the sensitive-workspace study, 58% believe their program would stop an unauthorized person, while 83% say their physical-cyber budget balance is about right. In the compliance study, 62% are confident they could pass an audit today with no preparation. Yet 63% of that very-confident group also experienced an incident this year.
An incident doesn't necessarily mean a security program failed. But the findings raise a more important question: when something does happen, can organizations quickly demonstrate who was involved, what they were authorized to access, and whether the right controls were followed?
Confidence runs high in both studies
Share expressing confidence in their program, across the two studies
Sure they would pass an audit today (Compliance)
Say their physical/cyber balance is right (Sensitive-workspace)
In the compliance study, audit confidence is highest among single-site organizations at 71%, falls to 58% among organizations with two to four sites, then rises to 63% for five to 19 sites and 61% for 20 or more. The pattern suggests that multi-site complexity may affect confidence, but the survey does not establish fragmentation as the cause.
Audit confidence is highest at single-site orgs, then dips
Share very confident they could pass an audit today with no prep, by number of sites
Audit confidence is highest among single-site organizations; multi-site organizations report somewhat lower levels, with variation by estate size.
Ask more specific questions and the evidence challenge becomes clearer. 44% of sensitive-workspace leaders cannot confidently say who was in their building yesterday. At the same time, 83% say their physical-cyber budget balance is about right and only 12% say they underinvest in physical security. The takeaway is not necessarily that budgets are wrong; it is that investment alone does not guarantee connected visibility or proof.
Where the worry concentrates
How concerned are you about each of the following physical security threats? (very + somewhat concerned)
Physical and cyber teams 'coordinate closely' at 82% of compliance-study organizations, yet the research still finds gaps in presence visibility and access lifecycle management. The threats leaders rank highest, including insiders and unsupervised contractors, reinforce the need to connect identity with authorization and ongoing presence rather than treating entry as the end of the security process.
Confidence and evidence are different things. Leaders may have good reason to trust their programs while still facing difficulty proving who was present, what they were authorized to access, and whether access ended when it should. The opportunity is to make those controls easier to connect, verify, and demonstrate when the stakes are highest.
The security chain protects the work that matters most
This gap would matter anywhere. It matters most here, where teams are developing the most sensitive work in the world. When we asked what these leaders most fear losing, AI models and training data top the list, narrowly ahead of client data and proprietary research. No single asset dominates, which means the physical program has to defend a wide front.
What leaders fear losing first
Which types of IP are you most concerned about protecting? (share ranking each #1)
And the worry runs inward. Two-thirds are concerned about contractors in spaces unsupervised and about insiders exposing information, whether by intent or by mistake. These threats reinforce why identity alone is not enough: organizations also need appropriate authorization, visibility into actual presence, and reliable access lifecycle controls around sensitive work.
67% are concerned about insiders intentionally exposing information and 66% about contractors accessing spaces unsupervised, while fewer than half report revoking terminated-employee access within 24 hours. The findings point to a lifecycle challenge: security teams need to connect identity to the right access, keep that authorization current, and retain evidence of what happened around sensitive assets.
Budget isn't the only barrier.
Cost is not the leading reason respondents give for missing controls. In the sensitive-workspace study, 58% say they had considered missing capabilities but had not prioritized them, compared with 31% citing implementation resources and 21% citing expense. Another 9% did not know the more advanced capabilities were an option at all. The findings suggest that prioritization and implementation capacity matter alongside budget.
Why the gaps stay open: prioritization leads price
Why haven’t you implemented the solutions you didn’t select? Select all that apply. (multi-select)
The compliance study adds another dimension. When leaders rank what is blocking better physical security, complexity of compliance requirements tops the list at 39%, followed by budget constraints at 32%. Fragmented or outdated tools (26%) and fragmentation across sites (25%) also rank among the barriers. The data points to a mix of complexity, resources, prioritization, and tooling rather than a single cause.
What’s blocking better security: complexity leads budget
What’s getting in the way of improving physical security? (share ranking each in their top two)
Asked what they need most, teams point to capabilities across the full security chain: real-time visibility into who's on-site, integration between physical and cyber, faster incident response, automated compliance logging, better visitor and contractor verification, and a single identity record across sites. Taken together, the priorities are less about one missing tool than about connecting identity, authorization, presence, response, and evidence.
What teams say they need most
What physical security capabilities does your organization need most? (share ranking each in their top two)
The case for improving physical security is already visible inside these organizations, but the barriers are multidimensional. Prioritization leads the sensitive-workspace responses, while compliance complexity leads the broader enterprise study and budget remains a meaningful factor in both. The opportunity is to make stronger security practices easier to implement, connect, and prove.
Close the gap.
Know who is in your building.
The conviction is already there. The fix is connecting the front door, not spending more: one visitor record, modern sign-in, watchlist screening, and access that ends the moment someone leaves. Envoy protects the places the world relies on most.
Talk to Envoy →Who we surveyed
Two separate studies, nearly 1,100 leaders, analyzed separately and compared.
Seniority
Department
Industry
Company size
Number of sites
79% were the primary decision maker for physical security, and 86% described their knowledge of protocols and spend as extensive.
Seniority
Research domain
Geography by region
All respondents worked in technical departments, product and engineering, per the study’s screening criteria, and all held direct physical-security responsibility. 87% operate under formal hybrid or flexible work policies. Company size skewed mid-market to enterprise, with roughly three-quarters at 501 or more employees. Geographic breakdown is drawn from panel-provider data for this sample.
Methodology
This report draws on two separate surveys Envoy commissioned in 2026, analyzed separately and compared rather than pooled. Where both asked a comparable question, the two figures are shown side by side and never combined into a single blended number.
The State of Physical Compliance study surveyed 782 US-based enterprise leaders in physical security, compliance and GRC, IT security, and facilities, fielded June 2–30, 2026. Respondents were Director level or above at organizations with 1,000+ employees operating multiple physical sites, and were the primary decision maker for or a significant influence on physical security tools, vendors, or compliance programs. Cross-tabs are available by team, accountability, industry, company size, and number of sites.
The Sensitive-Workspace Threat study surveyed 294 Director-and-above leaders at US organizations operating labs, R&D, and other high-sensitivity facilities, including frontier and applied AI, defense and national-security technology, and medical-device and pre-clinical research, fielded May 27–June 7, 2026. This study segments by research domain rather than industry.
Percentages reflect unique respondents who selected each option, rounded to whole numbers. Multi-select and ranking questions can sum above 100% and are labeled accordingly; single-select breakdowns sum to 100% within rounding. Net-agree and net-concerned figures combine the top two response options. The five controls referenced in Chapter 1 are badge or key-card control on sensitive doors, ID verification at check-in, visitor escorting, government ID capture, and revocation of terminated-employee access within 24 hours; they reflect security best practices rather than any single framework's requirements. All numbers trace to the structured survey data. Research powered by Gather.
