The client came to us having already priced a compliance automation subscription at five figures a year. They had assumed, reasonably, that a readiness programme requires one: something to hold the evidence, track the controls, and produce a readiness percentage for the board.
They did not buy it. The programme ran on our workspace instead, which we do not charge for, and that changed the shape of the budget before any control work started.
What the tooling was supposed to do
Stripped of the marketing, a compliance platform does four things. It holds a control set for the framework you are pursuing. It stores evidence against those controls. It tracks policies and who has acknowledged them. And it renders the whole thing as a percentage so somebody can report progress upward.
All four are genuinely useful. None of them is worth a recurring licence for a company running one readiness programme, which is what most first-time candidates are actually doing.
The trap is that the subscription is priced as infrastructure and used as a project tool. You buy it for the programme, the programme finishes, and the renewal arrives anyway. Companies then either pay for a tool nobody opens, or cancel and discover their evidence history lived inside it.
What automation actually automates
This is worth being precise about, because the category name oversells it.
The integrations are real. A platform connected to your cloud provider and your identity provider can genuinely pull configuration state on a schedule and flag when MFA is off for somebody or a bucket goes public. That is useful monitoring and it saves real time on a handful of technical controls.
What it does not do is the part that consumes the programme. It cannot decide whether the artefact you uploaded is the artefact an auditor will accept. It cannot tell you that your access review evidence is a screenshot when the auditor wanted the export with dates and the reviewer's name. It cannot chase the person who owns the vendor list, judge whether your system description matches what is actually in production, or negotiate sampling with the audit firm.
Roughly speaking, the automatable controls are a minority of any framework, and they are the ones companies are usually already doing. The controls that fail an audit tend to be organisational: reviews that never ran, owners who were never named, procedures that exist in someone's head. No integration fixes those.
So the honest description of a compliance platform is a well-organised filing system with monitoring attached to part of it. Priced accordingly, that is a fair product. Priced as the solution to readiness, it sets an expectation it cannot meet.
What the client used instead
The client ran the engagement in the traztech Workspace. It carries guided self-assessments across fourteen frameworks with every control explained in plain English, an evidence register, forty policy templates, a risk register, vendor questionnaires and audit-readiness scoring. There is no card, no trial clock and no paid tier, so nothing about the programme was gated behind an upgrade at the point it got serious.
Three things mattered more than the feature list.
It is the same register we work from. When we request an artefact, it lands against the control it evidences rather than in an email thread. When the auditor samples that control later, the artefact is already attached to it. A separate tool means somebody re-files everything at least once, and that usually happens during fieldwork when nobody has time.
The control explanations are in plain English. A large part of what a first-time candidate is paying for, in any tool, is a translation layer. The control text in the standard is written for assessors. Somebody on your side has to work out what it means for your company specifically, and if the tool does not do that, a person has to, and that person bills.
The client keeps it. When the engagement ends, the evidence, the policies and the assessment history stay in their workspace. That matters at the next cycle, because the expensive part of a second audit is reconstructing what you did during the first one.
Where the saving actually came from
The licence line is the obvious saving, and a five-figure annual commitment avoided is not nothing. It is still the smaller of the two. The larger saving was in not paying twice for the same work.
A compliance platform sold on automation still needs somebody to decide what evidence satisfies a control, to chase the people who own it, and to judge whether what came back is what an auditor will accept. That work does not disappear because the tool has an integration. Companies that buy the subscription frequently end up buying help as well, and the two overlap heavily: you are paying a vendor to hold the evidence and a consultant to tell you what to put in it.
Running both through one place meant the tool and the judgement were the same engagement. The client paid for the programme, not for the programme plus somewhere to keep it.
There is a second-order effect worth naming. When the register and the reviewer are the same system, the gap between "we uploaded something" and "that will pass" closes to zero. In a split setup, that gap is a review cycle, and review cycles are where timelines go.
Where a paid platform is the right answer
Worth being straight about this, because the answer is not always ours.
If you are maintaining several frameworks continuously, with a security team that lives in the tool daily, a genuine need for automated evidence collection across dozens of systems, and a compliance calendar that runs all year rather than in a burst, a commercial platform earns its money. Continuous control monitoring across a large estate is a real product category solving a real problem, and pretending otherwise would be silly.
The signals that you have crossed that line are reasonably clear. You have more than two frameworks live. Somebody's job title contains the word compliance. You are re-certifying on a rolling basis rather than preparing for a first audit. At that point the recurring cost buys recurring value.
For a company running its first or second readiness programme, the subscription is usually solving a problem the engagement already solves. That was the case here.
What to ask before you buy one
If you are being sold a platform during a readiness programme, four questions sort it out quickly.
What happens to my evidence if I cancel? Export format, and whether the assessment history comes with it.
Which controls does the automation actually cover? Ask for the list, not the percentage. Then check how many of those you were failing anyway.
Does this replace a person, or feed one? If the answer involves you still hiring help, price both together and compare that against a programme that includes the tooling.
Will my auditor accept evidence in this form? Ask the auditor, not the vendor.
The traztech Workspace is free to use whether or not you work with us. If you want to see what a control set looks like before committing to anything, that is the least expensive way to find out.
Note. The client is unnamed. Figures are described by what drives them rather than quoted, because audit pricing is specific to scope and we will not publish another firm's numbers.
What we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.