Envoy Research Report · 2026

The State of Physical Security & Compliance

Why the enterprise can't say who's in the building

Download the PDF
Illustration of a large padlock with a keyhole in the center, a magnifying glass, a gear, a checklist with checkmarks, and a building, symbolizing security, inspection, and compliance.
Envoy Research Report 2026 · 1,076 leaders across two separate studies
Key statistics
71%

of enterprises give contractors no single identity across their sites

Compliance study, n=782

79%

report at least one unauthorized or unverified person in a workspace where they shouldn't be in the past year

Sensitive-workspace study, n=294

44%

cannot confidently say who was in their building yesterday

Sensitive-workspace study, n=294

62%

are sure they would pass an audit today, yet most had an incident

Compliance study, n=782

The big picture

Two studies, one security challenge

Organizations have invested heavily in physical security. They have access controls, visitor systems, security teams, policies, and compliance programs. Yet many still struggle to answer one of the most fundamental questions in physical security: who was actually here?

That disconnect is at the heart of this report. The challenge isn't simply whether security controls exist. It's whether identity, authorization, access, presence, and evidence connect well enough to give teams a clear picture of what happened and the proof to back it up.

We saw that challenge emerge from two separate surveys conducted in 2026. One examined the tooling and compliance practices of 782 enterprise leaders. The other focused on 294 leaders protecting some of the country's most sensitive workplaces, including frontier AI labs, defense technology companies, and biotech and medical R&D organizations.

The studies asked different questions of different populations. We expected them to tell different stories. Instead, they surfaced a similar pattern.

Organizations have security controls in place, but those controls do not always operate as a continuous chain. Identity may be verified in one system, authorization determined in another, access granted somewhere else, and presence recorded separately. Different workplaces require different safeguards, but fragmentation can make it harder to answer the questions that matter: Who is this person? What are they authorized to access? Are they onsite now? When should their access change or end? And can the organization demonstrate afterward that the appropriate controls were followed?

Throughout this report, every figure is tagged with the study it came from. The datasets are analyzed separately and compared, never combined into a blended result. Where similar patterns emerge, they reflect two distinct populations answering different questions and pointing in a similar direction.

The research doesn't reveal a lack of security. It reveals how difficult it can be to connect the pieces of security into a complete picture.

Sophisticated security programs still face a fundamental challenge: connecting identity, authorization, presence, and evidence. Confidence is high. The opportunity is to make the chain easier to verify.

01 — The confidence gap

They feel secure. Are they?

A shield emblem with a blue top and white bottom containing a green circle with a white question mark, alongside a blue padlock and a user profile icon card on a light blue circular background.
01 — The confidence gap

Ask the leaders doing some of the most sensitive work in the world whether their program would stop an intruder, and most say yes. Ask what is actually instrumented behind that confidence, and the number drops. A net 58% believe their program would prevent unauthorized physical access, yet only 52% have badge control on sensitive doors and only 47% escort visitors at all times.

The belief is running ahead of the build. And confidence is not universal. The same question that produces a 58% majority also leaves 42% who will not say their program would stop an intruder, including 35% who actively doubt it. The picture splits two ways: a slight majority who feel protected but have not built the controls to be, and a large minority who already know they are exposed.

Source: Sensitive-workspace study, n=294

What lab and R&D leaders believe about their own program

Thinking about your organization’s overall physical security program for sensitive areas, to what extent do you agree with each of the following? (net agree, strongly + somewhat)

Tools well-matched to sensitivity
59%
Program would prevent unauthorized access
58%
Could say who was in the building yesterday
56%
Contractor access revoked in 24 hrs
55%
Physical as mature as cybersecurity
52%
0
20
40
60
80

In practice, the security controls in place vary considerably. Badge or key-card control on sensitive doors is present at just over half. Escorting visitors, capturing a government ID, revoking a terminated employee’s access within a day, and maintaining an auditable visit record are each used by fewer than half. These controls will not be appropriate in exactly the same way for every environment, but together they show how differently organizations approach identity verification, access governance, and evidence.

Source: Sensitive-workspace study, n=294

What they’ve actually built

Which of the following are currently part of your physical security program for sensitive areas? Select all that apply. (multi-select, exceeds 100%)

Badge / key card on sensitive doors52%Receptionist or guard verifies ID49%Terminated lose access within 24 hrs48%Visitor escorted at all times47%Government ID captured at check-in46%Visit auditable for 12+ months42%Digital tablet or app sign-in40%Watchlist / denied-party screening37%Contractor access governed as employee35%Single visitor record across all sites28%Paper logbook sign-in19%

Regulated frameworks often require longer retention; six years under HIPAA and five under ITAR, so 12 months is a floor, not a compliance bar

The research shows a wide range of physical security approaches. In the sensitive-workspace study, 92% lack at least one of five common controls measured across identity verification, access governance, and documentation. That doesn't necessarily mean those organizations are insecure. Different environments require different controls based on their risks, operations, and compliance obligations.

Confidence stays high across both studies. In the broader compliance study of 782 enterprise leaders, 62% are very confident they could pass a physical-security audit today with no time to prepare, and another 34% are somewhat confident.

Taken together, the findings shift the question from whether organizations have the "right" set of controls to whether the controls they choose work together, are consistently applied, and can be demonstrated when needed.

Source: Compliance study, n=782

The broad enterprise is just as sure

If your organization had to pass a physical security compliance audit today, with no time to prepare, how confident are you? (single-select)

96%
at least somewhat confident
Very confident62%
Somewhat confident34%
Neutral3%
Not very confident1%
Not at all confident0%
Key insight, so what:

58% believe their program would stop an intruder, while 96% of the broader enterprise are at least somewhat confident they would pass an audit today. That confidence may be justified. The bigger question is whether the controls behind it continue to work together as people, access, and risk change.

02 — Accounting for yesterday

Ask who was here yesterday, and 44% can't answer confidently

A circular chart with a large navy blue center circle showing 44%, surrounded by a ring split into two segments: a larger light blue segment and a smaller green segment, with an icon of a person in a circle containing a white question mark in the top right.
02 — Accounting for yesterday

The cleanest test of a physical security program is a simple one: can you say who was inside yesterday?

For 44% of leaders doing some of the most sensitive work across industries, the answer is not a confident yes. That lack of visibility also shows up in day-to-day operations. More than a third (35%) personally saw someone within the past month they didn’t recognize and weren’t sure should be there, while one in five (19%) still rely on paper logbooks for visitor sign-in.

An unfamiliar face is not necessarily a security threat. It could be, but the real question is whether teams can quickly establish who that person is, why they are there, and whether they are authorized to be onsite.

Source: Sensitive-workspace study, n=294

Can you account for yesterday

We could tell you exactly who was in our building yesterday. (single-select)

43%
13%
10%
15%
19%
50% midpoint
Strongly agree 43%
Somewhat agree 13%
Neither 10%
Somewhat disagree 15%
Strongly disagree 19%

The number is not an abstraction. When 44% cannot confidently reconstruct a single day, investigations and audits become harder because teams may have to piece together who was present from multiple records. The security value of presence data is the ability to move from who was expected or approved to who was actually onsite.

Source: Sensitive-workspace study, n=294

When they last saw a stranger inside

When was the last time you personally saw someone in your workplace you didn’t recognize and weren’t sure should have been there? (single-select)

10%
Past week
26%
Past month
22%
Past 3 months
10%
Past 6 months
9%
Past year
13%
1 year+
10%
Never

58% of leaders saw someone they didn't recognize and weren't sure should be onsite within the past three months.

The challenge isn't simply noticing someone unfamiliar. It's having enough visibility to resolve that uncertainty quickly, without piecing together information across systems, locations, or records after the fact.

Key insight, so what:

If you cannot confidently reconstruct yesterday, it becomes harder to investigate an incident or produce evidence afterward. Nearly half of these leaders are in that position. The opportunity is not to make every face recognizable; it is to make identity, authorization, and actual presence verifiable when they matter.

03 — When access fails

When uncertainty becomes unauthorized access

Icon of a person with a question mark over their face in front of a desk with a computer monitor, with a large green upward arrow above.
03 — When access fails

An unfamiliar person is not automatically a threat. But the data also captures situations where uncertainty becomes a clear access-control problem. Two in five (39%) leaders have personally seen a visitor or contractor reach a restricted physical area, and 28% have seen someone view or photograph work-in-progress on whiteboards, screens, or prototypes. These incidents show why identity must continue to stay connected to authorization after check-in, not stop at the lobby.

Source: Sensitive-workspace study, n=294

What leaders have personally witnessed

In the past year, have you witnessed a visitor or contractor doing any of the following? Select all that apply. (multi-select)

39%
Reached a restricted physical area
28%
Viewed or photographed work-in-progress
20%
Accessed lab equipment or hardware
20%
Accessed sensitive documents
19%
Accessed an unattended workstation

“A contractor that was no longer employed accessed employee areas.”

— Sensitive-workspace study respondent

Ask how often unauthorized or unverified access occurs and the frequency is striking. Four in five leaders (79%) report at least one instance in the past year of an unauthorized or unverified person ending up in a workspace where they should not be. Only 21% say it never happened.

Source: Sensitive-workspace study, n=294

How often unauthorized or unverified people end up where they shouldn't

How many times have unauthorized or unverified people ended up in workspaces where they shouldn’t be, in the last year? (single-select)

21%
Zero this year
32%
1–3 times
26%
4–6 times
17%
7–12 times
4%
12+ times

79% reported at least one unauthorized or unverified person in a workspace where they shouldn't be in the past year.

The broad enterprise reports related failures in different forms. In the compliance study, organizations report visitors not properly signed in (29%), employees unable to identify themselves at check-in (28%), visitors who could not be verified (22%), and unauthorized people in restricted areas (13%). Together, the findings show that access risk can emerge at verification, admission, and movement through the workplace.

Source: Compliance study, n=782

The same failures show up across the whole enterprise

In the past year, has your organization experienced any of the following? (access and verification failures)

Visitor was not properly signed in29%Employee could not identify themselves at check-in28%Visitor could not be verified at check-in22%Visitor escorted into a sensitive area unapproved19%Unauthorized person found in a restricted area13%
Key insight, so what:

Four in five sensitive-workspace leaders report at least one instance of an unauthorized or unverified person ending up where they should not be in the past year, while the broad enterprise reports verification and access failures of its own. The security challenge extends beyond the front door: identity must remain connected to authorization throughout a person's presence.

04 — The identity continuity gap

Cross-site identity remains fragmented

Illustration of a user icon in front of a row of five closed doors on a light blue and purple background.
04 — The identity continuity gap

Identity continuity does not mean access continuity. A contractor known at one facility should not automatically receive the same access at another. Different sites, zones, projects, and types of work may require different approvals, training, screening, escorts, credentials, or time-bound access.

What should carry across locations is the ability to know you are dealing with the same person. Yet 71% of enterprises do not give contractors a single identity across locations, while 72% of sensitive-workspace organizations do not maintain a single visitor record across sites.

These findings come from two different studies and measure different populations, but they point to a similar challenge: maintaining enough identity continuity to understand who someone is while adapting authorization to the context. Who someone is can remain consistent while what they are permitted to access changes based on their role, location, risk, and purpose.

Identity continuity also does not require every record to be centralized or retained indefinitely. In regulated environments, privacy, data segmentation, retention, and facility-specific requirements may shape how identity information is managed across locations. The security objective is to maintain enough continuity to recognize and appropriately govern the same person while applying the controls each environment requires.

Source: Both studies

The same gap in both studies: no identity that follows a person

Share of organizations with no persistent identity or visitor record across all their sites, measured in each study

71%

No single identity across sites (Compliance)

72%

No single visitor record across sites (Sensitive-workspace)

The two studies used different instruments and never shared a respondent, so the near-match is not an artifact of pooling. It is two separate samples pointing to the same challenge: identity continuity across locations remains uncommon. The rest of this chapter stays inside the compliance study, where the larger sample lets us see how that challenge varies by industry and scale.

Source: Compliance study, n=782

How contractors are recognized across sites

When contractors return to a different site, are they recognized as the same person? (single-select)

29%
16%
34%
17%
One identity everywhere 29%
Depends on the role 16%
Some sites, not others 34%
From scratch each site 17%
Not sure 4%

The compliance study shows meaningful differences across industries. Identity continuity is least common in healthcare, where 22% give contractors a single identity across sites, followed by manufacturing at 26% and financial services at 31%. These figures should not be read as a universal security score: some organizations deliberately require site-specific credentialing. The operational question is whether teams can recognize the same person while still applying the right site-specific controls.

Source: Compliance study, n=782

One identity across sites, by industry

Share giving contractors a single persistent identity everywhere, by industry

31%
Financial Services
30%
Technology
26%
Manufacturing
22%
Healthcare

These figures should not be read as a universal measure of security maturity. Lower cross-site identity continuity may reflect deliberate choices around privacy, data segmentation, credentialing, retention, and facility-specific requirements, particularly in regulated environments. The survey does not tell us why organizations chose a particular architecture.

The more important security question is whether teams can recognize and appropriately govern the same person across locations while maintaining the controls each environment requires. Identity continuity does not require universal access, identical policies, or every record to be centralized and retained indefinitely.

Scale doesn't eliminate the challenge. The largest estates report slightly more identity continuity, but even at twenty or more sites, most organizations do not give contractors one identity across locations. As environments grow more complex, organizations must balance cross-site visibility with site-specific authorization, privacy, retention, and compliance requirements.

Source: Compliance study, n=782

Identity continuity barely improves with scale

Share giving contractors one identity across all sites, by number of sites

28%29%32%2–4 sites5–19 sites20 or more sites

Four percentage points separate the smallest multi-site operators from the largest.

Fragmentation is part of the operational challenge. 74% of enterprises run two or more visitor-management systems and 46% run six or more. As sites, acquisitions, and local processes accumulate, identity and access records can end up distributed across multiple tools.

Source: Compliance study, n=782

Most enterprises run many visitor systems at once

How many visitor management systems does your organization operate across all sites? (single-select)

23%
1 system
28%
2–5
18%
6–10
14%
11–15
7%
16–20
7%
20+
Key insight, so what:

The research reveals a gap between identity continuity and access. With 71% of enterprises not giving contractors a single identity across sites, security teams may have to piece together records to determine who someone is and what they’re authorized to access. The opportunity is verifiable identity with access that adapts by location and role, while accounting for privacy, retention, and data-sharing requirements.

05 — Incidents everywhere

Access breaks down beyond the front door

Illustration of an open door with a user profile icon next to it and a red circle with a white X, representing denied access or no entry.
05 — Incidents everywhere

Access risk shows up across both studies, although each measures it differently. In the compliance study, 68% of organizations reported at least one physical-security incident in the past year. In the sensitive-workspace study, 78% reported an unauthorized person reaching a restricted area.

Source: Both studies

Most organizations had an incident this year, in both studies

Share reporting at least one incident or unauthorized entry in the past year, measured in each study

68%

Had a real physical-security incident (Compliance)

78%

Had an unauthorized person in a restricted area (Sensitive-workspace)

High security does not buy safety. It raises the cost of getting it wrong. Organizations protecting sensitive research, technology, infrastructure, and intellectual property still report unauthorized-access incidents. Their security requirements may be more rigorous than those of a typical workplace, but higher sensitivity also increases the importance of applying the right controls to the right people, places, and situations. The frontier AI labs and defense-tech firms in the sensitive-workspace study report incidents at rates even with, or above, the ordinary offices in the compliance study.

The entry-level failures are only half of it. A second cluster of incidents comes from access that should have ended and lingered: a compliance gap surfaced during an audit (24%), a former contractor who kept access after the work ended (21%), a former employee who kept access after leaving (20%). The front door held. The memory behind it lapsed.

Source: Compliance study, n=782

When access outlives the person

In the past year, has your organization experienced any of the following? (access persistence and audit gaps)

Compliance gap discovered during an audit24%Former contractor kept access after work ended21%Former employee kept access after departure20%

Access that outlives an engagement shows up in both studies, measured in different ways. In the compliance study, 33% reported a former contractor or employee retaining access. In the sensitive-workspace study, 31% are not confident a departed contractor loses access promptly. Together, the findings point to the importance of time-bound access and reliable revocation.

Source: Both studies

Departed contractors keep access in both populations

Share reporting retained access by a former contractor or employee, measured in each study

33%

Former contractor or employee kept access (Compliance)

31%

Not confident a departed contractor loses access (Sensitive-workspace)

Key insight

Two studies, two populations, the same result: most organizations had a real incident this yearStrong physical security requires more than admission controls. Authorization should be tied to identity, role, location, and time, with access changing or expiring as those conditions change. The data shows lifecycle gaps in both populations, even though the studies measure them differently.

06 — The operational tax

The hidden cost of running security by spreadsheet

Illustration of a calculator with a magnifying glass highlighting a dollar sign, symbolizing financial analysis or cost calculation.
06 — The operational tax

Between incidents sits a daily operational burden. When identity, access, and presence data live across separate systems, security teams become the integration layer. Pulling access logs in a normal week means checking six or more separate systems for 49% of enterprises.

Source: Compliance study, n=782

Systems a team must check just to pull access logs

How many separate systems must your team check to pull physical access logs in a normal week? (single-select)

7%
1 system
44%
2–5
24%
6–10
14%
11–15
7%
16–20
4%
20+

93% must check two or more systems to answer a single access question.

That reconciliation costs real hours. 56% of teams spend six hours a week or more on manual physical-security tracking, before an audit even begins. During an active audit, the burden spikes. The issue is not only efficiency: fragmented evidence can slow the team's ability to establish what happened and demonstrate that the right controls were followed.

Source: Compliance study, n=782

Hours per week lost to manual tracking

Roughly how many hours per week does your team spend on manual physical-security tracking? (single-select)

9%
Under 1 hr
34%
1–5 hrs
36%
6–10 hrs
15%
11–20 hrs
5%
20+ hrs

“Protocol is to immediately shut down the building, lock all exits and entries, and perform head count, badge count, and screen each employee in the building in each room.”

— Sensitive-workspace study respondent, on responding to an intruder

The pain of audit prep is not the paperwork itself. It is the scramble to assemble evidence that lives in too many places at once. A connected security chain makes that evidence easier to produce on demand.

Source: Compliance study, n=782

The biggest pain in preparing for an audit

What challenges do you experience when preparing for a physical security audit? (multi-select)

Time-consuming: pulls people off other work45%Chasing down records from multiple teams32%Afraid of missing something28%Information scattered across too many sites27%Information scattered across too many systems26%Consequences of failure are stressful25%
Key insight, so what:

Some of that system is still paper and pen, with someone typing the day's sign-in sheet into a spreadsheet at the end of a shift. Manual processes can work, but they become harder to reconcile as volume, complexity, or urgency rises. The opportunity is to make identity, access, and presence evidence easier to retrieve without depending on one person to reconstruct it.

07 — Confidence vs. evidence

The gap between confidence and proof

Shield emblem with a star in the center, set against a blue circular background with a brick wall pattern.
07 — Confidence vs. evidence

Here is where the data gets interesting. Confidence remains high even as organizations continue to experience physical security incidents. In the sensitive-workspace study, 58% believe their program would stop an unauthorized person, while 83% say their physical-cyber budget balance is about right. In the compliance study, 62% are confident they could pass an audit today with no preparation. Yet 63% of that very-confident group also experienced an incident this year.

An incident doesn't necessarily mean a security program failed. But the findings raise a more important question: when something does happen, can organizations quickly demonstrate who was involved, what they were authorized to access, and whether the right controls were followed?

Source: Both studies

Confidence runs high in both studies

Share expressing confidence in their program, across the two studies

62%

Sure they would pass an audit today (Compliance)

83%

Say their physical/cyber balance is right (Sensitive-workspace)

In the compliance study, audit confidence is highest among single-site organizations at 71%, falls to 58% among organizations with two to four sites, then rises to 63% for five to 19 sites and 61% for 20 or more. The pattern suggests that multi-site complexity may affect confidence, but the survey does not establish fragmentation as the cause.

Source: Compliance study, n=782

Audit confidence is highest at single-site orgs, then dips

Share very confident they could pass an audit today with no prep, by number of sites

71%58%63%61%1 site2–4 sites5–19 sites20+ sites

Audit confidence is highest among single-site organizations; multi-site organizations report somewhat lower levels, with variation by estate size.

Ask more specific questions and the evidence challenge becomes clearer. 44% of sensitive-workspace leaders cannot confidently say who was in their building yesterday. At the same time, 83% say their physical-cyber budget balance is about right and only 12% say they underinvest in physical security. The takeaway is not necessarily that budgets are wrong; it is that investment alone does not guarantee connected visibility or proof.

Source: Sensitive-workspace study, n=294

Where the worry concentrates

How concerned are you about each of the following physical security threats? (very + somewhat concerned)

Insider — intentional exposure
67%
Contractors without supervision
66%
Insider mistakes — accidental
66%
Unauthorized visitors in restricted areas
65%
Tailgating
65%
Other unverified individuals
62%
Terminated employees retaining access
56%
Foreign persons gaining access
56%
40
50
60
70
80

Physical and cyber teams 'coordinate closely' at 82% of compliance-study organizations, yet the research still finds gaps in presence visibility and access lifecycle management. The threats leaders rank highest, including insiders and unsupervised contractors, reinforce the need to connect identity with authorization and ongoing presence rather than treating entry as the end of the security process.

Key insight, so what:

Confidence and evidence are different things. Leaders may have good reason to trust their programs while still facing difficulty proving who was present, what they were authorized to access, and whether access ended when it should. The opportunity is to make those controls easier to connect, verify, and demonstrate when the stakes are highest.

08 — What's at stake

The security chain protects the work that matters most

 Open safe with a large diamond displayed inside on a pedestal.
08 — What's at stake

This gap would matter anywhere. It matters most here, where teams are developing the most sensitive work in the world. When we asked what these leaders most fear losing, AI models and training data top the list, narrowly ahead of client data and proprietary research. No single asset dominates, which means the physical program has to defend a wide front.

Source: Sensitive-workspace study, n=294

What leaders fear losing first

Which types of IP are you most concerned about protecting? (share ranking each #1)

18%
AI models & training data
17%
Client or customer data
16%
Proprietary research, algorithms
16%
Financial / strategic information
13%
Personnel data
11%
Product roadmaps
8%
Manufacturing / lab processes

And the worry runs inward. Two-thirds are concerned about contractors in spaces unsupervised and about insiders exposing information, whether by intent or by mistake. These threats reinforce why identity alone is not enough: organizations also need appropriate authorization, visibility into actual presence, and reliable access lifecycle controls around sensitive work.

Key insight, so what:

67% are concerned about insiders intentionally exposing information and 66% about contractors accessing spaces unsupervised, while fewer than half report revoking terminated-employee access within 24 hours. The findings point to a lifecycle challenge: security teams need to connect identity to the right access, keep that authorization current, and retain evidence of what happened around sensitive assets.

09 — Why gaps persist

Budget isn't the only barrier.

A large green eye partially obscured by a blue and white striped barrier, set against a blue circular background.
09 — Why gaps persist

Cost is not the leading reason respondents give for missing controls. In the sensitive-workspace study, 58% say they had considered missing capabilities but had not prioritized them, compared with 31% citing implementation resources and 21% citing expense. Another 9% did not know the more advanced capabilities were an option at all. The findings suggest that prioritization and implementation capacity matter alongside budget.

Source: Sensitive-workspace study, n=294

Why the gaps stay open: prioritization leads price

Why haven’t you implemented the solutions you didn’t select? Select all that apply. (multi-select)

Considered but not prioritized58%Lack of resources to implement31%Too expensive21%Don't think we need it20%Tools can't support it13%Didn't know it was an option9%

The compliance study adds another dimension. When leaders rank what is blocking better physical security, complexity of compliance requirements tops the list at 39%, followed by budget constraints at 32%. Fragmented or outdated tools (26%) and fragmentation across sites (25%) also rank among the barriers. The data points to a mix of complexity, resources, prioritization, and tooling rather than a single cause.

Source: Compliance study, n=782

What’s blocking better security: complexity leads budget

What’s getting in the way of improving physical security? (share ranking each in their top two)

39%
Complexity of compliance requirement
32%
Budget constraints
26%
Fragmented or outdated tools
25%
Fragmentation across our sites
25%
Leadership doesn't prioritize it
22%
Lack of dedicated staff

Asked what they need most, teams point to capabilities across the full security chain: real-time visibility into who's on-site, integration between physical and cyber, faster incident response, automated compliance logging, better visitor and contractor verification, and a single identity record across sites. Taken together, the priorities are less about one missing tool than about connecting identity, authorization, presence, response, and evidence.

Source: Compliance study, n=782

What teams say they need most

What physical security capabilities does your organization need most? (share ranking each in their top two)

Real-time visibility into who's on-site30%Integration between physical and cyber28%Faster incident response27%Automated compliance logging25%Better visitor / contractor ID verification25%A single identity record across all sites25%
Key insight, so what:

The case for improving physical security is already visible inside these organizations, but the barriers are multidimensional. Prioritization leads the sensitive-workspace responses, while compliance complexity leads the broader enterprise study and budget remains a meaningful factor in both. The opportunity is to make stronger security practices easier to implement, connect, and prove.

Close the gap.
Know who is in your building.

The conviction is already there. The fix is connecting the front door, not spending more: one visitor record, modern sign-in, watchlist screening, and access that ends the moment someone leaves. Envoy protects the places the world relies on most.

Talk to Envoy →

Who we surveyed

Two separate studies, nearly 1,100 leaders, analyzed separately and compared.

Research powered by
Gather logo
Compliance study, n=782

Seniority

Senior Director / Director52%C-level / Chief36%VP / SVP10%Head / VP2%

Department

Physical or corporate security49%IT / IT Security26%Compliance, GRC, or risk23%Facilities2%

Industry

Technology26%Financial Services21%Manufacturing19%Other17%Healthcare11%Energy / Utilities3%Government3%

Company size

1,000–4,999 employees56%5,000–24,99934%25,000+10%

Number of sites

5–19 sites43%2–4 sites28%20+ sites22%1 site7%

79% were the primary decision maker for physical security, and 86% described their knowledge of protocols and spend as extensive.

Sensitive-workspace study, n=294

Seniority

C-level53%Director29%Chief5%Head of function4%SVP / EVP4%VP4%

Research domain

Frontier AI / ML41%Applied AI / ML35%Defense / national-security tech9%Medical device R&D7%Other regulated R&D4%Pre-clinical / gene-editing4%

Geography by region

Northeast62%South35%West2%Midwest1%

All respondents worked in technical departments, product and engineering, per the study’s screening criteria, and all held direct physical-security responsibility. 87% operate under formal hybrid or flexible work policies. Company size skewed mid-market to enterprise, with roughly three-quarters at 501 or more employees. Geographic breakdown is drawn from panel-provider data for this sample.

Methodology

This report draws on two separate surveys Envoy commissioned in 2026, analyzed separately and compared rather than pooled. Where both asked a comparable question, the two figures are shown side by side and never combined into a single blended number.

The State of Physical Compliance study surveyed 782 US-based enterprise leaders in physical security, compliance and GRC, IT security, and facilities, fielded June 2–30, 2026. Respondents were Director level or above at organizations with 1,000+ employees operating multiple physical sites, and were the primary decision maker for or a significant influence on physical security tools, vendors, or compliance programs. Cross-tabs are available by team, accountability, industry, company size, and number of sites.

The Sensitive-Workspace Threat study surveyed 294 Director-and-above leaders at US organizations operating labs, R&D, and other high-sensitivity facilities, including frontier and applied AI, defense and national-security technology, and medical-device and pre-clinical research, fielded May 27–June 7, 2026. This study segments by research domain rather than industry.

Percentages reflect unique respondents who selected each option, rounded to whole numbers. Multi-select and ranking questions can sum above 100% and are labeled accordingly; single-select breakdowns sum to 100% within rounding. Net-agree and net-concerned figures combine the top two response options. The five controls referenced in Chapter 1 are badge or key-card control on sensitive doors, ID verification at check-in, visitor escorting, government ID capture, and revocation of terminated-employee access within 24 hours; they reflect security best practices rather than any single framework's requirements. All numbers trace to the structured survey data. Research powered by Gather.