Compliance Automation: Build vs Buy for Mid-Market Teams

Last updated: 09/16/2026
Compliance
Compliance Automation: Build vs Buy for Mid-Market Teams

Buy compliance automation when a customer or contract sets your audit date and your stack is SaaS-heavy. Build on tools you already own when you run one cloud or Microsoft 365. Neither works until controls have owners.

A Vanta contract runs a median of $20,000 a year. Drata runs $25,000. Those numbers land on the table the moment your compliance readiness work needs software and someone on your team swears they could script the whole thing over a few weekends. Sometimes they can. A surprising share of compliance automation already comes bundled with the Microsoft 365 and AWS licenses you pay for every month. So is it really build versus buy? Not quite. The better question is what the software, bought or built, will never do for you, and whether anyone at your company has the hours to do it instead once the dashboard turns red.

Those medians come from Vendr's buyer data on 373 Vanta purchases and 233 Drata purchases, which track what companies actually signed rather than list prices. Neither vendor publishes one.

What Does Compliance Automation Actually Automate?

A cloud and key feeding evidence into a folder on one side, and a person at a desk working through a checklist on the other

Compliance automation software connects to your systems, pulls evidence like MFA settings (the second sign-in check after a password) and user access lists, and re-checks those controls on a schedule. It doesn't write your policies, decide who should have access, or fix a control that fails.

Evidence, in audit terms, is proof a control works. A screenshot of your password policy. A list of who can reach the finance share. Vanta advertises 400+ integrations plus an API for building your own, where an API is simply the doorway one piece of software uses to read data from another. That's the job. Collect, test, flag, repeat.

The first two are the platform's job. The last three stay with your people.

  • Pulling configuration evidence from Microsoft 365, Google Workspace, AWS, Okta, and your HR system, automatically
  • Re-testing it daily or hourly, then flagging drift (a setting that quietly changed since the last check)
  • Policy templates. You still have to edit them until they describe how your company actually works.
  • Quarterly access reviews? The tool sends the reminder. A manager still decides whether the intern from 2024 keeps admin rights.
  • Remediation stays manual, every time

None of this is new thinking. NIST said it plainly in Special Publication 800-137 back in September 2011, writing that organization-wide monitoring "cannot be efficiently achieved through manual processes alone or through automated processes alone." Fifteen years later, the sentence still holds. AWS says something close about its own tool. Audit Manager, per its user guide, "doesn't assess your compliance itself."

What Does a Compliance Automation Platform Cost?

Vanta and Drata contracts run $7,500 to about $67,000 a year, with Vanta's median at $20,000 and Drata's at $25,000. The auditor bills separately. So does the internal time to answer what the platform flags.

Table comparing Vanta and Drata median annual costs with separate SOC 2 auditor fees

That last row never shows up on an invoice. It should. A platform that flags 60 failing tests in week one has done its job perfectly, and now somebody on a 4-person IT team owns 60 tickets.

Which platform you pick matters less than vendors want you to believe. When we scored nine compliance automation platforms on software alone, the top six landed within 0.18 points of each other on a 10-point scale. A rounding error, basically. The gaps that separated them were framework coverage and how much help came with the license.

What Building It Yourself Actually Looks Like

Building compliance automation at a company with 20 to 1000 users rarely means writing a platform from scratch. It means stitching together tools you already license, then scripting the gaps. Duct tape, mostly.

Start with what's already paid for. Microsoft 365 tenants get Purview Compliance Manager, and organizations on Microsoft 365 E5, the top enterprise license, can pick up to three premium regulatory templates, NIST 800-53 or ISO 27001 for instance, at no added cost. AWS accounts get AWS Config conformance packs, over 100 prebuilt rule sets including PCI DSS 4.0 and NIST 800-171. And CISA gives away ScubaGear, a free tool that checks seven Microsoft 365 services (Entra ID, Exchange Online, SharePoint, and Teams among them) against federal security baselines and spits the results out as HTML, JSON, or CSV.

Then comes the glue. PowerShell or Python scripts that run those checks on a schedule, a locked storage folder for the output, and a ticket queue for anything that fails. If you want the data to outlive whoever wrote the scripts, store it in OSCAL, NIST's machine-readable format for control catalogs, security plans, assessment results, and remediation plans. It reads as XML, JSON, or YAML, so a future platform or auditor can import it instead of starting over.

The Bureau of Labor Statistics puts the median information security analyst at $129,180 a year as of May 2025. Give a quarter of that person's time to keeping homegrown checks running, updating mappings when a framework revises, and chasing broken API tokens, and you've spent $32,295 in salary alone. That's before benefits. It's also already more than the median Vanta contract.

Build still wins sometimes, though. A company living almost entirely in Microsoft 365 with one framework to meet can get most of the way on Purview and ScubaGear for close to nothing extra. Nobody needs a $20,000 dashboard to read a free report.

The Cloud-Native Trap

Building on a cloud provider's own compliance service looks safe. It's their product, after all. Then the product changes.

AWS moved Audit Manager into maintenance mode in 2026. Since April 30, new accounts can't set it up, and AWS says it won't add new frameworks or new versions of existing ones. Its recommended replacement, Config conformance packs, has no template for SOC 2 or for ISO 27001. Existing users can keep running Audit Manager, but when PCI DSS or NIST publishes a new version of a framework, AWS has said plainly that the tool won't be updated to follow it. Free native tools aren't permanent. Plan for that.

Where Build and Buy Fail the Same Way

Both approaches monitor controls. Neither one creates a control, assigns an owner, or fixes what's broken. A green dashboard over a missing process is the most expensive kind of green.

Microsoft's own FAQ takes on the question directly. Does a high Compliance Manager score mean you're fully compliant? Microsoft's answer is no, and it adds that the score "shouldn't be interpreted as a guarantee in any way." AWS goes further in its Audit Manager transition FAQ. A PCI DSS conformance pack covers only the technical controls, and "there is no Config Rule that verifies that the organization has documented its Security Policies." Then AWS points readers to Vanta and Drata for the rest.

That's a cloud provider admitting its own tooling can't carry an audit.

And the platforms can't carry one either, for a different reason. They'll confirm that a quarterly access review happened. They can't tell you whether the reviewer clicked approve on 140 accounts in 11 minutes. Big difference. Compliance was never the same thing as security, and a dashboard that turns every check green on schedule just makes the gap between the two easier to miss for another full audit cycle. What closes it is a working compliance program, with named owners, written procedures, and someone checking that the procedures match reality.

Should You Build or Buy Compliance Automation?

A balance scale weighing a compliance software dashboard against a toolbox

Buy when a customer contract or sales deal sets the audit date, you're running two or more frameworks, or your stack spans dozens of SaaS tools (subscription software you log into on the web). Build when you're mostly Microsoft 365 or one cloud with a single framework. Fix the program first when controls have no owners.

Decision matrix showing when to buy, build, or fix the compliance program first

If you already employ a GRC analyst (the person who runs governance, risk, and compliance day to day) and you only answer to one framework, a $20,000 platform is closer to a convenience than a necessity. Not sure how many frameworks you're actually on the hook for? Work out which standards apply to you before you count integrations.

How Does Your Framework Change the Answer?

SOC 2 favors buying. The report is an opinion issued by a CPA firm under AICPA standards, and every major platform ships a prebuilt SOC 2 control mapping. Whether you need SOC 2 Type I or Type II changes how long the evidence has to run, not which tool collects it.

CMMC is pickier. Under 32 CFR 170.17, a Level 2 certification assessment comes from an accredited third-party assessor, known as a C3PAO. The results filed with the Department of Defense list every evidence artifact by name alongside its hash value, a digital fingerprint that proves the file wasn't altered afterward. A senior official then affirms compliance at the assessment and every year after it. Any open remediation items have 180 days to close. So whatever you build or buy has to keep evidence files untouched and traceable. Screenshots in a shared drive? Not enough. Platform coverage is uneven too. In our August scoring, one platform advertising 200+ frameworks never named CMMC or NIST 800-171 on its frameworks page. Map your CMMC certification timeline first, then ask each vendor to show Level 2 evidence mapping live in a demo.

ISO 27001 leans buy once you're outside Microsoft 365, since AWS has no conformance pack for it. PCI DSS 4.0 can go either way. Follow the cardholder data.

Run a 30-Day Test Before You Sign or Start Building

  1. List every system in scope. Email, identity, file storage, endpoints, HR, payroll, and whatever cloud hosts customer data.
  2. Count the evidence items your framework needs, then mark each one automatable or manual. Expect the manual column to be longer than the sales demo suggested.
  3. Put a name next to every control. Not a team. A person.
  4. Trial a platform against your real Microsoft 365 or cloud environment, not the vendor's sandbox, and at the same time run ScubaGear or Purview Compliance Manager against it. Compare what each one actually catches.
  5. Export everything on day 30. Can you get evidence out in CSV, JSON, or OSCAL? If leaving means losing a year of audit history, you've learned the real price of the contract.

Step 3 is where the answer usually shows up. Companies that can't fill that column don't have a build-or-buy problem yet.

Who Owns Each Control Today?

Consilien is a security-first managed IT and cybersecurity provider for companies with 20 to 1000 users nationwide, with a lot of manufacturers, distributors, and professional services firms among them. Our compliance readiness work is its own service, separate from managed IT. That means gap assessments against NIST, CMMC, PCI DSS, SOC 2, and ISO 27001, remediation plans tied to real controls, policy work, and audit prep alongside your external auditor, whether evidence ends up in a platform, in tools you already own, or in both.

If your 30-day test turns up a controls column with no names in it, that's the conversation to have before anyone signs a contract.

Questions Buyers Ask Before Signing

Can Microsoft Purview Compliance Manager replace Vanta or Drata?
Sometimes, for a company that lives almost entirely in Microsoft 365 and answers to one framework. E5 tenants get up to three premium regulatory templates included. It gets thin once your evidence sits in AWS, Google Workspace, an HR platform, and a dozen SaaS tools, because stitching those in becomes your job, usually on top of the help desk tickets that were already there.
Will a compliance automation platform make us SOC 2 compliant?
A CPA firm decides that, not software. Code can't sign an audit opinion. The platform collects and organizes the evidence the auditor reviews.
Is GRC automation the same thing as compliance automation?
Close cousins. GRC automation covers governance and risk management too, like risk registers and vendor reviews, while compliance automation tends to mean evidence collection against a specific framework. Vendors use the terms loosely, so read the feature list instead of the category label.
If we switch platforms later, do we lose our evidence?
Only if you wait until the final month to find out how exports work. Test it during the trial. Ask for the evidence, the control mappings, and the test history in a format another tool can read, CSV or JSON at minimum, OSCAL if the vendor supports it. CMMC adds a wrinkle here. Assessors record each artifact's hash, so a file that gets re-saved during a migration no longer matches what was assessed. Plan the move before an assessment, not in the middle of one. And get the export terms in the contract, because a sales rep's verbal promise doesn't survive a renewal negotiation.
Are open-source compliance tools ready for a 150-person company?
For a company with developers on staff, parts of them are. Projects like Openlane, Probo, and GovReady aim at the platform layer, while InSpec and OpenSCAP scan system settings against security benchmarks. All of them assume someone technical will install, patch, and maintain them, which puts you right back in the build column. That's a real job.
Do we still need outside help if we buy a platform?
$20,000 buys the evidence plumbing. That's all. It doesn't buy anyone to write the policies, assign owners, or fix the 60 failed tests from week one. Some companies handle that internally, and plenty don't have the hours.

Related Articles

Stay ahead with expert tips, industry trends, and actionable strategies.