The client came to us having already priced a compliance automation subscription at five figures a year. They had assumed, reasonably, that a readiness programme requires one: something to hold the evidence, track the controls, and produce a readiness percentage for the board.
They did not buy it. The programme ran on our workspace instead, which we do not charge for, and that changed the shape of the budget before any control work started.
What the tooling was supposed to do
Stripped of the marketing, a compliance platform does four things. It holds a control set for the framework you are pursuing. It stores evidence against those controls. It tracks policies and who has acknowledged them. And it renders the whole thing as a percentage so somebody can report progress upward.
All four are genuinely useful. None of them is worth a recurring licence for a company running one readiness programme, which is what most first-time candidates are actually doing.
The trap is that the subscription is priced as infrastructure and used as a project tool. You buy it for the programme, the programme finishes, and the renewal arrives anyway. Companies then either pay for a tool nobody opens, or cancel and discover their evidence history lived inside it.
What automation actually automates
This is worth being precise about, because the category name oversells it.
The integrations are real. A platform connected to your cloud provider and your identity provider can genuinely pull configuration state on a schedule and flag when MFA is off for somebody or a bucket goes public. That is useful monitoring and it saves real time on a handful of technical controls.
What it does not do is the part that consumes the programme. It cannot decide whether the artefact you uploaded is the artefact an auditor will accept. It cannot tell you that your access review evidence is a screenshot when the auditor wanted the export with dates and the reviewer's name. It cannot chase the person who owns the vendor list, judge whether your system description matches what is actually in production, or negotiate sampling with the audit firm.
Roughly speaking, the automatable controls are a minority of any framework, and they are the ones companies are usually already doing. The controls that fail an audit tend to be organisational: reviews that never ran, owners who were never named, procedures that exist in someone's head. No integration fixes those.
So the honest description of a compliance platform is a well-organised filing system with monitoring attached to part of it. Priced accordingly, that is a fair product. Priced as the solution to readiness, it sets an expectation it cannot meet.
What the client used instead
The client ran the engagement in the traztech Workspace. It carries guided self-assessments across fourteen frameworks with every control explained in plain English, an evidence register, forty policy templates, a risk register, vendor questionnaires and audit-readiness scoring. There is no card, no trial clock and no paid tier, so nothing about the programme was gated behind an upgrade at the point it got serious.
Three things mattered more than the feature list.
It is the same register we work from. When we request an artefact, it lands against the control it evidences rather than in an email thread. When the auditor samples that control later, the artefact is already attached to it. A separate tool means somebody re-files everything at least once, and that usually happens during fieldwork when nobody has time.
The control explanations are in plain English. A large part of what a first-time candidate is paying for, in any tool, is a translation layer. The control text in the standard is written for assessors. Somebody on your side has to work out what it means for your company specifically, and if the tool does not do that, a person has to, and that person bills.
The client keeps it. When the engagement ends, the evidence, the policies and the assessment history stay in their workspace. That matters at the next cycle, because the expensive part of a second audit is reconstructing what you did during the first one.
Where the saving actually came from
The licence line is the obvious saving, and a five-figure annual commitment avoided is not nothing. It is still the smaller of the two. The larger saving was in not paying twice for the same work.
A compliance platform sold on automation still needs somebody to decide what evidence satisfies a control, to chase the people who own it, and to judge whether what came back is what an auditor will accept. That work does not disappear because the tool has an integration. Companies that buy the subscription frequently end up buying help as well, and the two overlap heavily: you are paying a vendor to hold the evidence and a consultant to tell you what to put in it.
Running both through one place meant the tool and the judgement were the same engagement. The client paid for the programme, not for the programme plus somewhere to keep it.
There is a second-order effect worth naming. When the register and the reviewer are the same system, the gap between "we uploaded something" and "that will pass" closes to zero. In a split setup, that gap is a review cycle, and review cycles are where timelines go.
Where a paid platform is the right answer
Worth being straight about this, because the answer is not always ours.
If you are maintaining several frameworks continuously, with a security team that lives in the tool daily, a genuine need for automated evidence collection across dozens of systems, and a compliance calendar that runs all year rather than in a burst, a commercial platform earns its money. Continuous control monitoring across a large estate is a real product category solving a real problem, and pretending otherwise would be silly.
The signals that you have crossed that line are reasonably clear. You have more than two frameworks live. Somebody's job title contains the word compliance. You are re-certifying on a rolling basis rather than preparing for a first audit. At that point the recurring cost buys recurring value.
For a company running its first or second readiness programme, the subscription is usually solving a problem the engagement already solves. That was the case here.
What to ask before you buy one
If you are being sold a platform during a readiness programme, four questions sort it out quickly.
What happens to my evidence if I cancel? Export format, and whether the assessment history comes with it.
Which controls does the automation actually cover? Ask for the list, not the percentage. Then check how many of those you were failing anyway.
Does this replace a person, or feed one? If the answer involves you still hiring help, price both together and compare that against a programme that includes the tooling.
Will my auditor accept evidence in this form? Ask the auditor, not the vendor.
The traztech Workspace is free to use whether or not you work with us. If you want to see what a control set looks like before committing to anything, that is the least expensive way to find out.
Note. The client is unnamed. Figures are described by what drives them rather than quoted, because audit pricing is specific to scope and we will not publish another firm's numbers.
Where tooling ranks against the other cost lines
It helps to see the licence in proportion. A first readiness programme has five cost lines: the audit firm's fee, the penetration test, engineering time spent on remediation, advisory or programme management, and tooling. For a first-time candidate the audit fee and the engineering time are almost always the two largest, and engineering time is the one nobody budgets because it does not arrive as an invoice.
Tooling is usually the third or fourth line by size, which is why the saving on its own is not the interesting part of this engagement. What made it worth writing up is that the tooling decision moved the lines above it. Evidence that lands against the control it evidences, in a register the reviewer already reads, shortens remediation cycles, and remediation cycles are engineering time.
The audit fee also responds to how well the readiness position is documented, though not in a way vendors advertise. On one engagement the audit firm reduced its own quote by $11,000 once the readiness position was documented, which is written up in our auditor vetting case study. That is one firm on one scope and not a rate card, but it is the direction the incentive runs: an assessor who can see what they are walking into prices less contingency into the engagement.
The costs that are not on the order form
The subscription price is the number buyers compare. It is rarely the number they end up paying, and the gap is not the vendor being dishonest, it is the buyer under-counting what the tool needs from them.
Implementation time. Somebody has to connect the integrations, map the control set to your actual systems, decide which findings are noise, and build the policy set. Two to four weeks of a competent person's part-time attention is normal for a first framework. That person is usually the same engineer who was going to do the remediation.
Integration engineering for the awkward systems. The cloud provider and the identity provider connect cleanly. The self-hosted CI runner, the legacy database, the physical laptop that never enrolled in MDM, and anything acquired rather than built tend not to. Those become manual controls regardless, which is fine, but it means the automation coverage you priced is not the coverage you get.
Framework expansion pricing. The first framework is on the quote. The second is usually an add-on, and companies almost always add a second framework, because the reason you needed the first one was a customer asking, and customers keep asking.
Per-seat policy acknowledgement. Priced per employee, so it scales with hiring rather than with compliance work. A company that doubles headcount during a certification cycle pays twice for a feature that is a signed list.
Alert triage. Continuous monitoring produces continuous alerts. Most of the early ones are configuration decisions you made deliberately and now have to justify or exempt. That work is real and it is not automation.
The readiness percentage is a bad number
Every platform in this category renders a score, and boards love it because it is a single figure that moves. It is worth understanding what it measures, because it is not readiness.
The percentage is a count of controls the tool believes are satisfied over controls in the framework, weighted by nothing in particular. It cannot see whether the artefact attached to a control is the artefact the auditor will accept, whether the review it records actually happened or was backdated, or whether your system description matches production. A programme can sit at 94 per cent and fail on three organisational controls, because the failing ones are the ones the tool cannot assess.
What the percentage is genuinely good for is spotting neglect. If a whole family of controls sits untouched for six weeks, the number surfaces that. Used as a management prompt it earns its place. Used as a readiness signal it produces the specific failure where a board is told the programme is nearly done and fieldwork then runs three months long. If you report the score upward, report alongside it how many controls have evidence a reviewer has actually looked at, which is the number that predicts the audit.
The auditor question nobody asks in the demo
Several platforms operate a network of partner audit firms, with discounts attached. There is nothing improper about that arrangement and the firms in those networks are generally competent. It does change what you are choosing, though, and buyers rarely notice they are choosing it.
An audit firm that works constantly inside one platform gets fast at reading evidence in that platform's format. That is a genuine efficiency and it can shorten fieldwork. The cost is that your assessor selection has quietly narrowed to a marketplace, at the moment when the assessor's fee is your largest line and their sampling approach determines your workload. Choosing the audit firm on its own merits, then asking that firm what evidence format it prefers, is the order that serves the buyer. Choosing the tool and inheriting its audit panel is the order that serves the vendor.
Ask any prospective auditor two questions before you commit to either. Do they have a preferred evidence format, and will they accept an evidence register exported from something other than a named platform? Almost every firm says yes to the second, which quietly removes the strongest argument in the sales deck.
Where the programme hours actually landed
Once the licence decision was off the table, the programme's constraint became what it always is: getting named humans to produce artefacts that describe what actually happens. The work sorted into three kinds, and the proportions are typical.
A small amount was technical configuration, mostly access management tidy-up, logging retention, and encryption settings that were already close to right. This is the part that would have automated well, and it is also the part that took the least time.
A larger amount was writing down procedures that already ran informally. Onboarding and offboarding, change approval, incident handling, vendor selection. None of this was new behaviour. All of it needed a document and an owner, and the document had to match what people did rather than what the template said.
The largest amount was the reviews that had never been performed: access reviews, vendor reassessments, risk register updates, and the first tabletop. These cannot be backdated and they cannot be automated, because the control is a person exercising judgement on a schedule. Any tooling decision that does not shorten this third category has not touched the critical path.
Second year economics, which is where the argument usually lands
The case for a subscription is strongest at renewal, not at purchase, and it is worth arguing it honestly. The pitch is that year two is cheaper because the evidence, the policies and the control mappings are already there and monitoring has been running continuously since the last report.
That is true when the tool has been used continuously. It is not true when the tool was used in a burst before fieldwork and then ignored for ten months, which is the common pattern for a company with no full-time compliance owner. In that situation year two starts roughly where year one did, minus the policy writing, and the twelve months of licence bought a filing cabinet.
The test is simple and you can run it on yourself at renewal. Over the last quarter, did anyone open the tool in a week where no audit was pending? If the honest answer is no, the recurring cost is not buying continuous compliance, and a retainer that includes both the register and a person who reviews it will do more for the same money. That is what our engage options exist for, and the fixed-scope alternatives sit on /pricing.
Three situations where we would tell you to buy it anyway
The first is a contractual or underwriting requirement that names the tooling. Some enterprise customers, and occasionally an insurer, specify acceptable control-monitoring platforms in the agreement itself. That is not an argument worth winning for the money involved, and the honest advice is to buy the named tool and get on with the actual controls.
The second is a parent company or an acquirer that already standardised. If you are one entity inside a group that reports compliance posture centrally, running your programme somewhere else creates a reconciliation job that lands on you every quarter. The licence is cheaper than being the exception on somebody else's board pack.
The third is an estate where the evidence volume is genuinely beyond a register a person reads. Hundreds of production hosts, several cloud accounts and a headcount turning over monthly generate more configuration state than anyone reviews by hand, and continuous monitoring stops being a reporting feature and becomes the only way anybody knows what is running. That threshold is real, it just arrives later than the sales process suggests.
What we would push back on either way is buying the platform in order to answer the question of what good evidence looks like. That question is answered by a person who has sat through fieldwork, and it is answered once. If that is the actual problem, buy a few days of review before you buy twelve months of software, and see whether the software is still needed afterwards. Our compliance work is scoped that way on purpose.
Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself.
Talk to usOr talk about a retainerWhat we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.