Home/Platform vs engineer

Vendor decision

Compliance platform vs security engineer

Compliance platforms are good products that do a specific job well: they tell you which controls are failing and they collect evidence from the systems they integrate with. What they do not do is fix anything. That gap is not a flaw in the software; it is the boundary of what software can do. The question is who covers it.

Updated 17 August 20268 min readWritten for AWS-native teams

Position stated up front

We work alongside any compliance platform, and we do not sell one. If you already pay for Vanta, Drata, Secureframe, or anything similar, keep it. Nothing on this page argues you should cancel a subscription. It argues that the subscription and the engineering work are two different line items, and that only one of them is usually on the budget.

What each one actually does

JobCompliance platformSecurity engineer
Tell you which controls are failingYes. This is the core product and it is good at itYes, via a point-in-time scan
Continuous monitoring and drift alertsYes. Genuinely valuable, especially post-reportOnly if they build it, which is a real project
Deploy logging, detection, and encryption baselinesNoYes. Infrastructure-as-code into your account
Tighten IAM policies your application depends onNoYes, as specified fixes your engineers apply and we verify
Provide policy templatesYes, generic. You customizeYes, written to how your team actually operates
Collect evidence automaticallyYes, for integrated systemsYes, including the systems with no integration
Run your quarterly access reviewReminds you. Does not run itYes, facilitated, with the record produced
Separate production from developmentNoYes, as an architecture engagement
Argue with your auditor on your behalfNoYes
Cost shapeAnnual subscription, ongoingProject cost, front-loaded, then a retainer if you want one

Where the gap shows up

The pattern is consistent enough to predict. A team buys a platform, connects AWS and the identity provider, and gets a dashboard with a lot of red. The red items divide into three groups:

  1. Things a setting fixes. Enable this, turn on that. The platform's guidance is sufficient, and a competent engineer clears them in an afternoon. Maybe a fifth of the list.
  2. Things that need writing. Twenty-plus policies, an incident response plan, a risk register. Templates exist, but customizing them to how your company actually operates, and getting them approved and acknowledged, is real work that nobody wants to own. This is where most teams stall for months.
  3. Things that need engineering. The wildcard IAM policy your service depends on. The unencrypted RDS instance from 2024. The single AWS account holding production and development. These are code changes, migrations, and architecture work, and no dashboard reduces them.

Group one is easy, group two is slow, group three is where timelines die. A platform is excellent at telling you all three exist and equally unable to do any of them.

The integration boundary

Platforms collect evidence from systems they integrate with. Every startup has systems they do not integrate with, and those are exactly the ones auditors ask about.

The classic version: a data warehouse holding customer data, accessed through a mechanism the platform cannot see. The dashboard shows green across identity and access because it is reading the identity provider, and the tool with the most sensitive data is not connected to any of it. That surfaces in fieldwork rather than on the dashboard.

The fix is dull and effective: inventory every critical tool that touches customer data or production, on day one, and decide per tool whether evidence is automated or manual. The ones that are manual need an owner and a calendar entry for the entire observation window. Green dashboards measure integrated coverage, not real coverage.

The honest cost comparison

Platform pricing varies enormously by headcount and discount, so compare structure rather than list prices:

ApproachCash costYour engineering timeElapsed time to ready
Platform aloneSubscription onlyHigh. All remediation, writing, and evidence chasingOpen-ended. Three to six months is common
Platform plus your engineersSubscription plus internal costHigh, roughly 0.25 to 0.5 FTE for 3 to 6 months3 to 6 months, competing with the roadmap
Engineer-led readiness, no platformFrom $10,000 fixed with usLow. Application-level fixes, ticketed and scheduled6 to 8 weeks
BothSubscription plus readinessLow6 to 8 weeks, with continuous monitoring afterwards

The row that moves the number is engineering time, not the subscription. Half an engineer for four months at loaded cost is real money that never appears on the compliance budget because it appears on payroll instead.

Which to choose

Your situationSensible move
A security-experienced engineer with spare capacity, no hard deadlinePlatform alone. You have the scarce ingredient already
A blocked enterprise deal and no spare engineering capacityEngineer-led readiness. Add a platform when the Type 2 window opens
Already paying for a platform, stalled after months of redKeep the platform, add engineering. This is the most common call we take
Post-report, running an annual cycleBoth. Continuous monitoring plus someone owning the cadence
Not AWS-native, or multi-cloudPlatform plus a provider matched to your stack. We are AWS-only by design

How they work together

When both are in play the division is clean. The platform is the shared source of truth for control status and the collector for integrated systems. We fix what it flags, cover what it cannot see, write and customize the policy program, run the cadences, and handle the auditor. The platform stays useful long after readiness ends, which is exactly when a project-shaped engagement would otherwise leave a gap.

What we do not do is duplicate it. If your platform collects an artifact well, we use its output rather than building a second pipeline for the same evidence.

Frequently asked questions

Is a compliance platform enough to get SOC 2?

It is enough to know what is wrong and to keep evidence flowing from integrated systems. It is not enough to fix anything. Whether that is sufficient depends entirely on whether you have an engineer with the time and background to do the remediation. If you do, a platform alone is a reasonable path. If you do not, the platform will accurately document your lack of progress.

Do we need a platform if we hire a readiness engineer?

Not for a first Type 1. A platform earns its cost in the Type 2 observation window and afterwards, where continuous monitoring and automated collection meaningfully reduce manual work. Many teams start without one and add it when the window opens.

We already pay for a platform. Are we wasting that money if we hire you?

No. We work alongside it and use its evidence output rather than duplicating it. The subscription covers monitoring and collection; the engagement covers remediation, the policy program, the cadences, and the auditor. Different jobs.

Which compliance platform is best?

We do not rank them and we have no referral arrangement with any of them. For a first SOC 2 on AWS the differences that matter are which of your specific tools they integrate with, and how their evidence exports line up with your auditor's request format. Ask both vendors those two questions with your actual tool list in hand and the choice usually makes itself.

Keep the platform. Get the work done.

We scan your environment against 35 controls, deploy the baseline as infrastructure-as-code you own, write the policy program, ticket the application-level fixes to your engineers, and organize the evidence for your auditor. Six to eight weeks, fixed price, quoted after the scan.

Book a 30-minute scoping call

No pitch deck. We look at your stack and tell you exactly what an audit would flag.