Do You Need a Compliance Platform? Vanta, Drata, and the Honest Answer

A team under SOC 2 pressure lands in a Vanta or Drata trial, and the marketing implies the tool is the compliance. It isn't. The platform automates evidence collection; it does not implement controls. Three honest paths, with real cost math for each.

Template included

Platform vs. consultant vs. DIY decision worksheet

Copy as markdown to paste into your repo, or download a branded PDF for sharing with non-technical stakeholders.

Download PDF

Do you need a compliance platform like Vanta or Drata? Only if your controls already exist. The platform automates evidence collection; it does not implement controls. If SSO, enforced MFA, account separation, and change management are real, buy it. If they aren’t, close those gaps first, or you’re paying $10,000 to $25,000 a year to watch a dashboard stay red.

The Problem

The sequence repeats at nearly every regulated SMB we see. An enterprise prospect sends a security questionnaire, or procurement makes the deal contingent on a SOC 2 report. Within two weeks, someone on the engineering team is in a Vanta or Drata trial watching connectors light up, and the vendor’s marketing is doing exactly what it was built to do: imply that compliance is a software purchase. Buy the platform, work the checklist, get the report.

The platform automates evidence collection. It does not implement controls. That distinction is the entire buying decision, and it is the one thing the sales process is structured to blur. Connect your AWS account and the platform will tell you, accurately and continuously, that three S3 buckets are public, that four IAM users have no MFA, and that CloudTrail is off in two regions. It will not fix any of that. It cannot. Those are engineering projects, and they were engineering projects before you started paying $15,000 a year for a dashboard that describes them.

The failure mode is a signed annual contract and six months of red. The dashboard is beautifully organized, the Slack nags arrive on schedule, and the audit is no closer, because the audit was never blocked on evidence collection. It was blocked on controls that do not exist. When the renewal invoice arrives before the Type I report does, the company has spent $10,000 to $25,000 renting a well-formatted view of its own backlog. This article is meant to intercept that purchase order.

The Approach

Three honest paths exist: DIY, platform now, or an implementation engagement followed by the platform. The right one hangs on a question no vendor demo will ask you directly: are the controls actually implemented?

Yes

No

Named owner with capacity

No owner, no slack

Enterprise deal stalls:

prospect wants SOC 2

Controls actually

implemented?

Buy the platform:

evidence automation is

the real bottleneck now

Who closes

the gaps?

Internal readiness work first,

platform once controls exist

Engagement first:

controls in 60-90 days,

then platform

Select auditor,

open the observation window

What the platforms genuinely do well

No strawmen. These products are good at what they actually do, and what they do has real value.

The connectors are the core of it. Read-only integrations into your IdP (Okta, Google Workspace), your cloud accounts, your MDM (Kandji, Jamf), and your repo host pull evidence automatically and continuously: MFA status per user, encryption settings per bucket, branch protection per repo, disk encryption per laptop. That kills the screenshot ritual. Manual evidence collection for a SOC 2 cycle runs 50 to 100+ hours of engineer time, most of it senior, all of it miserable, and it has to be redone every cycle because auditors need evidence from the current period — screenshots from last year attest to nothing, and console retention often rotates the raw data out anyway. A platform does the collection on a schedule, forever.

The rest of the package is competent glue. Policy template libraries give you a serviceable starting point instead of a blank page (they still need editing to describe your actual practices, more on that below). Task tracking assigns control ownership and deadlines. The auditor-facing dashboard lets your audit firm read evidence in the platform instead of over email attachments, which measurably shortens fieldwork. Multi-framework control mapping means one piece of evidence (MFA enforced at the IdP) satisfies SOC 2 CC6.1, the HIPAA access-control requirement, and ISO 27001 A.8.5 (Secure authentication) simultaneously: collect once, map everywhere.

There is also a subtler benefit: continuous monitoring keeps you honest between audits. A control that silently degrades in March surfaces in March, not during next January’s fieldwork. Structurally, a compliance platform is a commercial evidence pipeline; the self-hosted version of the same idea costs less cash and more engineering time, and the trade runs exactly the way you would expect.

What they cannot do

The platform can observe that MFA is not enforced in your IdP. Enforcing it means turning it on in Okta and surviving the week of locked-out contractors. The platform can record that production and development share an AWS account once you scope it; separating them is a migration project measured in weeks, not a checkbox. It can generate a change-management policy in one click; making deploys actually follow that policy means CI enforcement, branch protection, and a review culture. It can schedule your quarterly access review, assign it, and nag the owner three times, but a human still has to read every entry and decide whether that contractor from 2024 should retain admin.

None of this is a criticism of the products. It is their design. They are observation and workflow tools, and observation does not close gaps.

Which produces the honest framing of the buying decision: the red items on the dashboard are not compliance tasks. They are your engineering backlog, priced in sprints. If the backlog is long, buying the platform first means paying $10,000 to $25,000 a year to watch it stay red while the same engineers who would clear it context-switch into audit prep. Buy in the wrong order and the subscription’s first year is pure rent.

The three paths, and when each wins

DIY spreadsheets. Wins when scope is tiny and budget is near zero: a first Type I, single product, one or two AWS accounts, under roughly 10 people in scope. Software cost is $0. Time cost is real: budget 100 to 150 engineer-hours to build the control matrix, collect screenshots, and shepherd the auditor. You pay the auditor fee on every path regardless ($10,000 to $20,000 for a Type I from a mid-market firm; $20,000 to $40,000 for a Type II). The honest limit: manual collection decays badly past about 20 controls, and a Type II observation window means re-collecting quarterly. DIY is viable exactly once, for the smallest possible audit, and it is painful even then.

Platform only. Wins when the controls already exist. SSO everywhere, MFA enforced, account separation done, change management real, offboarding tight. Score yourself in the template below; if you land here, the vendors’ pitch is simply true for you, and the subscription buys back those 50 to 100 hours per cycle at a good exchange rate. Cost: $10,000 to $25,000 a year for SOC 2 at typical SMB headcount (step-ups come later, see selection notes), plus the auditor fee, plus roughly 100 to 200 internal hours the first cycle even with automation. Someone still owns policy adoption, vendor reviews, and auditor management. The platform reduces that lift; it does not delete it.

Engagement plus platform. Wins when the readiness gap is the actual blocker: no SSO, shared AWS account, change management that amounts to “we’re careful.” Implement the controls first. A structured 90-day readiness sprint exists precisely because this gap is bounded and well understood; it does not require a year of discovery. Then the platform earns its subscription from day one of the observation window, collecting evidence from controls that actually operate. Cost: an engagement in the $30,000 to $60,000 range depending on gap size, plus the platform, plus the auditor. On paper the expensive path. In practice the only one that moves the report date when controls do not exist, and cheaper than twelve months of subscription burn stacked on a stalled seven-figure deal.

Sequencing: controls, then platform, then auditor

Order matters more than tool choice.

Auditor first, controls later, is the worst inversion: the observation window either opens on failing controls (which lands in the report) or gets postponed while the engagement clock runs. Platform first, controls later, is the milder and far more common inversion: red rent, as above. Controls first makes everything downstream cheaper. The platform trial becomes a confirmation scan instead of a wall of findings, the auditor can be chosen from the platform’s marketplace with evidence already flowing, and the observation window opens clean.

The platform-before-auditor half of the sequence is genuinely useful, though mildly so: audit firms in the Vanta and Drata marketplaces already know the evidence format, which shaves fieldwork hours and sometimes fees. It is a tiebreaker, not a strategy.

If you do buy: selection notes

The connector list is the product. Evaluate it against your stack, not the logo wall. An unsupported IdP, a self-hosted GitLab, or a niche MDM converts “automated” controls into manual uploads, and manual uploads inside a platform are the same spreadsheet you were trying to escape, now with a subscription fee. Ask for a connector-by-connector walkthrough of your exact systems and a percentage estimate of automated versus manual evidence for your stack.

Then price the future, not the present. If HIPAA or ISO 27001 sits anywhere on the 24-month roadmap (and for healthcare-adjacent buyers, framework sequencing usually puts it there), get per-framework add-on pricing in writing before signing year one. Framework count and employee tiers are the two step-up axes where the renewal doubles: crossing 50 or 100 employees mid-contract, or adding a second framework at list price, routinely turns a $12,000 first year into a $30,000 second year. Confirm the auditor terms too: whether you can bring your own firm, and what the marketplace firms actually charge.

The Template

Score each factor 0 to 2. Total honestly; the bands below do the rest.

Part 1: score yourself

#Factor0 points1 point2 points
1Controls implemented (of these five: SSO + enforced MFA; prod/dev account separation; documented and followed change management; offboarding within 24h; centralized logging)0-1 of 5 running2-3 of 54-5 of 5
2Internal ownerNobody namedNamed, under 10% of their timeNamed, 25%+ time protected
3Timeline runwayReport needed inside 4 months; deal blocked now4-8 months8+ months
4Frameworks needed, next 24 monthsOne-time Type I onlySOC 2 Type II, annuallyType II plus HIPAA / ISO / others
5Year-one budget (software + outside help, excluding auditor fee)Under $5k$5-20k$20k+

Part 2: read the bands

GATE RULE (evaluate first):
  Q1 <= 1 AND Q2 <= 1  ->  ENGAGEMENT FIRST, THEN PLATFORM.
      No purchase fixes an unstaffed readiness gap. Q3 = 0 makes
      this more true, not less: urgency without capacity is the
      exact case outside help exists for.

  Q1 <= 1 AND Q2 = 2   ->  INTERNAL READINESS WORK FIRST.
      Run the sprint yourselves. Buy the platform when Q1
      would score 2. Trial it now for the gap list (free).

IF Q1 = 2 (controls are in):
  Q4 = 0 AND Q5 = 0    ->  DIY IS VIABLE.
      First Type I, tiny scope, near-zero budget. Accept the
      100-150 hours and know DIY does not survive a Type II
      observation window.

  Otherwise            ->  PLATFORM NOW.
      Evidence automation is your actual bottleneck. Buy it,
      pick an auditor, open the window.

Part 3: questions to ask the platform vendor

  1. Walk through the connector for each of our systems by name: IdP, cloud accounts, MDM, repo host, ticketing. Which of our controls have no connector coverage?
  2. For our exact stack, what percentage of this framework’s controls will be evidenced automatically versus manual upload?
  3. Can we bring our own audit firm? Which firms completed audits on your platform in the last 12 months, and at what fee range?
  4. What does adding HIPAA or ISO 27001 cost at renewal, and how much of our SOC 2 evidence actually maps across?
  5. Where exactly are the price step-ups: employee tiers, framework count, connector count? What happens if we cross a tier mid-contract?
  6. What does the access-review workflow do beyond scheduling and reminders?
  7. At churn, what do we get out: evidence history, format, retention?
  8. What will the year-two renewal say, at list, if nothing about us changes?

Operating Notes

Run the trial as a free gap assessment

Connect the trial read-only, let it scan everything, and export the red list before the trial expires. That list is a legitimate readiness assessment, the kind consultancies charge five figures for, and you are allowed to take it and walk. The vendors know this and price it into the funnel. Signing before the list is mostly green, or before there is a funded plan to make it green, is the mistake this entire article is about.

Green is not the same as compliant

The platform checks what its connectors can see. An auditor samples beyond that: they interview your engineers, pull real tickets, and read your policies against your actual behavior. A policy library adopted in one click that describes a change process nobody follows is worse than no policy, because now the gap is documented. Treat the dashboard as necessary telemetry, not as the audit result. Type II reports are built from operating effectiveness over months, and no connector attests to culture.

The renewal is where the price lives

Year-one pricing is a land grab; year two is the business model. Before signing, get the multi-framework add-on price, the employee-tier boundaries, and the year-two list price in the order form, not the sales thread. Teams that negotiate the HIPAA add-on at initial signature routinely pay half what teams pay when they add it at renewal, for the obvious reason: by renewal, your evidence history lives there, and the vendor knows what migration costs you.

Frequently asked questions

Do I need a compliance platform like Vanta or Drata?

Only if your controls already exist. The platform automates evidence collection continuously, but it does not implement the controls. If SSO, enforced MFA, account separation, and change management are already real, it buys back the 50 to 100 hours of manual evidence collection per cycle; if they aren't, fix the gaps first.

What does a compliance platform actually do well?

It runs read-only connectors into your IdP, cloud accounts, MDM, and repo host to pull evidence automatically and continuously, which kills the screenshot ritual. It also provides policy templates, task tracking, an auditor-facing dashboard, and multi-framework control mapping, so one piece of evidence can satisfy SOC 2, HIPAA, and ISO 27001 at once.

What can a compliance platform not do?

It observes gaps; it does not close them. It can flag that MFA isn't enforced, that prod and dev share an AWS account, or that a change-management policy isn't followed, but enforcing MFA, separating accounts, and building a review culture are engineering projects the platform cannot do for you.

Should I buy the platform before or after fixing my controls?

After, if the backlog is long. Buying first means paying $10,000 to $25,000 a year to watch the dashboard stay red while the same engineers who would clear the backlog context-switch into audit prep. Controls first makes the trial a confirmation scan, lets you pick an auditor with evidence already flowing, and opens the observation window clean.

Can I use the free trial as a gap assessment?

Yes. Connect the trial read-only, let it scan everything, and export the red list before it expires; that list is a legitimate readiness assessment, the kind consultancies charge five figures for. Sign only once the list is mostly green, or once there is a funded plan to make it green.

Why does the platform renewal cost more than year one?

Year-one pricing is a land grab; year two is the business model. The step-ups are employee tiers and framework count: crossing 50 or 100 employees mid-contract or adding a second framework at list price can turn a $12,000 first year into a $30,000 second. Negotiate the HIPAA or ISO add-on and the tier boundaries in the order form before signing.

Dashboard full of red?

The gap between red and green is engineering work, not software.

The red items on a compliance dashboard are an engineering backlog, and no subscription clears it. We run architecture and compliance teardowns that turn the red list into a sequenced plan, and 90-day readiness sprints that execute it. If the report date matters, talk to us before the renewal does.