Abuelos EN Red

Why a $20,000 Compliance Platform May Be Too Much Tool for a Small SaaS Company

Software for compliance is designed aid in audits. Small companies are often in a difficult spot. Before they can implement their SOC 2 controls they must first install, configure, and learn an extensive software for compliance. This brings up a fascinating question. What is the point at which the instrument designed to decrease compliance become a separate project that is its own?

CertAssist resulted from that frustration. Its founders had worked on compliance-related implementations and audits for SOC 2, ISO 27001 and other frameworks. They had to deal with platforms that were packed with integrations and features while firms still rely on spreadsheets for crucial elements of auditing process. Simpler SOC 2 compliance software is often the best option for smaller organizations.

Start With the Job That Needs to Be Done

If you take away the terms used in software it is much easier to comprehend. It is crucial that businesses know the Trust Services Criteria. This includes setting appropriate controls, collecting evidence, tracking progress and documenting policies. Platforms can handle these functions without having to be connected to all cloud services or identity systems the company uses.

Automated integrations can be very valuable. A large organization collecting evidence in a constantly evolving environment may save significant time via automation. However, this doesn’t mean the same technology is required for SOC 2 in startups. If a startup operates in limited technology resources it might be better to create evidence by hand and avoid having many integrations.

The Audit and Software are Two Different Costs

Budgeting becomes difficult when companies treat each compliance expense as an individual number. The SOC 2 cost includes more than software. Internal staff have to spend time preparing policies, addressing weaknesses in control, arranging proof as well as cooperating with auditors. The independent audit also comes with its own fees.

In researching SOC 2 costs, businesses must be aware of a important distinction in terminology. SOC 2 produces a report that is not a certification and not a certification as defined by ISO 27001. Nevertheless, “certification cost” is often used by businesses searching for pricing data. Whatever the terminology used in the budget, software can’t take the place of an independent auditor.

The Middle Ground Doesn’t Need to Be a Spreadsheet

Spreadsheets can be cheap and easy to use, but they become cumbersome when they are spread across many files.

The alternative doesn’t need to be an enterprise platform. CertAssist centralizes the SOC2 control and allows users to edit policies and templates for proving. It also provides auditors with progress management as well as access only to read. Multi-factor authentication is essential to secure the platform. The advertised launch price of $225 is followed by regular pricing at $375 per month, or $3,999 annually.

The same kind of integration that decreases exposure can also be achieved through removing the need for it

CertAssist deliberately does not connect to the company’s operational systems. The evidence is presented without giving the compliance platform access to cloud environments and identities environments.

This approach is not without its drawbacks. Information that could have been taken automatically should instead be supplied by the company. The additional manual work is reasonable for a smaller group in exchange for easier setup, less expense and less ties with third parties.

If Complexity Solves a Problem, Buy It

In an organization that is growing it is possible that manual evidence collection will end up being inefficient. That’s when continuous monitoring and extensive integrations could pay their price.

It’s not required to purchase the most complicated compliance system until later. It’s to get the compliance process organized, maintain reliable evidence, and ensure that the independent audit is manageable. Software that’s well designed will make this process simpler. The implementation of the compliance platform could appear more like a job rather than preparing the SOC 2 itself. It might be that the company does not need the same tools.

Recent Post