Programme Economics·~19 min read·4,157 words

The compliance industrial complex: what you actually need and what you are being soldPremium

Practitioner reference for founders, CISOs, CFOs, GCs, and anyone who has just been quoted ₹40 lakh for a compliance programme they suspect could cost a tenth of that · 2026-05-25 · Written from twelve years of watching the compliance and GRC market expand, of recommending some of it to clients, of recommending against most of it, and of being the consultant called in to clean up the spend when the budget ran out and the programme was somehow still incomplete


The industry exists to sell you things

There is a compliance and GRC industry. It includes consultants, certification bodies, GRC platform vendors, audit firms, training providers, automation tooling, virtual CISO firms, fractional DPO practices, security questionnaire automation tools, third-party risk platforms, dedicated audit prep services, and the entire ecosystem of “compliance enablement.” It is large. It is well-funded. It is well-marketed. And its business model depends on you spending more on compliance than you would otherwise spend.

This is not a conspiracy. The industry is not malicious. The individual consultants, vendors, and auditors are mostly competent and well-intentioned. But the structural incentive of the entire ecosystem is to expand the perceived requirement, multiply the deliverables, and increase the spend. Vendor reps are paid on the size of the deal. Consultancies bill on engagement hours. Audit firms generate revenue from audit scope. Each of these actors, individually rational, collectively produces a market where the marketed minimum compliance programme costs an order of magnitude more than the actual minimum.

I have made my own living for much of the last twelve years from this market. I am writing this guide partly as penance and partly because the most useful thing I do for clients now is tell them which parts of what they are being sold they do not need. The guide is opinionated. The opinions are uncomfortable for some parts of the industry to read. They are also the closest thing to honest practitioner consensus I can produce, and they are what I tell founders and CISOs when they ask me where to spend and where to push back.


What you actually need

Before any of the industry’s offerings make sense, you need a baseline answer to “what do I actually need.” The answer varies by company stage and by the regulatory environment you operate in. A pre-revenue startup with ten employees does not need the compliance programme of a regulated bank, and pretending otherwise wastes money.

A workable framing, by stage:

Pre-revenue / pre-product-market-fit. What you need: a basic acceptable-use policy, MFA on all employee accounts, password manager, cloud-account hygiene, basic data inventory (“we collect X for purpose Y”), no production access for departed employees. What you do not need: a GRC platform, a virtual CISO, ISO 27001 certification, SOC 2 certification, formal risk assessments. Total annual spend: under ₹1 lakh, mostly in tooling subscriptions.

Early commercial / first few customers. What you need: written security policies, customer-facing security overview document, completed major customer questionnaires, basic vendor risk process, written incident response runbook, basic privacy notice and consent capture for any personal data processing. What you do not need yet: full certifications, dedicated GRC headcount, vendor risk platform, automated compliance tooling. Total annual spend: ₹2-8 lakh.

Growth / mid-market enterprise customers. What you need: SOC 2 Type 2 or ISO 27001 certification (driven by customer demand, not regulatory requirement), formal vendor risk programme, dedicated security or compliance lead (full-time or fractional), proper DPIA process if processing meaningful EU or Indian personal data, working risk register, formal access reviews. What you may or may not need: a GRC platform (often delivered cheaper as spreadsheets plus discipline), automated compliance tooling. Total annual spend: ₹15-50 lakh including the first audit.

Enterprise / regulated sector / large customer base. What you need: full certification stack including ISO 27001, SOC 2 Type 2, ISO 27701 if processing personal data at scale, sectoral-specific compliance (RBI, SEBI, IRDAI, PCI as applicable), dedicated CISO and dedicated DPO, GRC platform, third-party risk platform, dedicated internal audit function, board-level governance forum, regular penetration testing, regular tabletop exercises. Total annual spend: ₹1-5 crore depending on scale.

Large enterprise / multinational / highly regulated. Everything in the previous tier plus segmented compliance programmes per jurisdiction, dedicated regional privacy and security leads, harmonised global control framework, formal audit and assurance team, regulatory affairs function. Total annual spend: ₹5 crore and up.

The interesting cases are at the transitions between tiers, where founders and CISOs get oversold on the next tier’s spend pattern before they have the next tier’s revenue and regulatory exposure to justify it. The vendor reps and consultants in your inbox are uniformly trying to move you to the next spend tier, often two tiers up.


The GRC platform reality

The GRC platform market is large. In India it includes MetricStream, KavachOne, SAFE Security, Cyforge, several others. Globally it includes ServiceNow GRC, OneTrust, AuditBoard, Hyperproof, Vanta, Drata, Scrut, Sprinto, Secureframe, and dozens more. The pitch is uniform: automate your compliance evidence collection, reduce audit prep time, get audit-ready faster, manage multiple frameworks from one platform.

The reality is more nuanced.

For pre-revenue and early commercial companies, GRC platforms are usually a bad spend. The platforms require setup time and ongoing configuration that exceeds the work they save. The “automation” they offer is largely about pulling evidence from your existing tools (cloud accounts, identity providers, ticketing systems), and the pulled evidence still needs manual curation to be audit-ready. A spreadsheet-plus-discipline approach is faster and cheaper at this stage.

For growth-stage companies pursuing first certification, GRC platforms in the Vanta / Drata / Sprinto / Scrut tier are useful, with caveats. The useful function is the evidence collection and continuous monitoring; the timesaving on the first SOC 2 or ISO audit is real, in the range of 30-50% of audit prep effort. The caveats are: the platform produces “compliance” against pre-mapped frameworks, which is not the same as security, and over-reliance produces a programme that looks audit-ready on the dashboard but has not actually internalised the controls. Use the platform; do not let it be the programme.

For mid-market and enterprise, the platform decision shifts to integration depth and multi-framework support. ServiceNow GRC, AuditBoard, and OneTrust target this segment with deeper integrations and broader framework coverage. The cost moves into the ₹40-80 lakh annual range. The platform is now genuinely useful for managing the operational compliance workload at scale; the implementation, however, is now genuinely a six-month project that needs proper change management.

For multinational and highly regulated, multiple platforms typically coexist — one for general GRC, one for third-party risk, one for privacy specifically, one for sectoral compliance. The total spend is multi-crore. The value is real because the compliance workload genuinely cannot be managed in spreadsheets at this scale.

The recurring oversell pattern: pre-revenue and early commercial companies being sold the growth-stage tier platform. The platform exists; the pitch is plausible; the company spends ₹15-25 lakh annually on tooling they could have done without. The fix is for the founder or CISO to ask the simple question: “what does this platform automate that I am currently doing manually?” If the honest answer is “not much, because we are not doing it at all,” the platform is not solving your problem.

The other recurring pattern: companies treating the GRC platform as the security programme. The dashboard shows green; the company is audit-ready; the company is not actually secure. GRC platforms measure compliance posture; they do not measure operational security. The distinction matters and the platforms rarely point it out.


The certification stacking trap

The certification market has expanded materially in the last decade. ISO 27001 is the baseline. ISO 27701 is the privacy-specific extension. ISO 42001 is the AI-specific extension. ISO 27017 and 27018 cover cloud-specific controls. SOC 2 covers service organisations. PCI DSS covers card payment processors. HITRUST covers healthcare. The list goes on. There is a market dynamic where holding more certifications is treated as a signal of security maturity, and consultants and certification bodies are happy to recommend additional certifications.

The honest reading: most organisations are over-certified relative to what their customers require. The customer questionnaires that drive certification demand usually ask for one or two specific certifications (SOC 2, ISO 27001 are the most common). Holding additional certifications produces little additional commercial value and consumes meaningful additional cost.

The certification math:

  • ISO 27001 initial certification: ₹8-25 lakh in India depending on scope and certification body, US$30,000-80,000 internationally. Annual surveillance: ₹3-8 lakh.
  • ISO 27701 added on: ₹4-12 lakh additional, surveillance ~₹2-5 lakh.
  • ISO 42001 added on: ₹4-12 lakh additional, surveillance ~₹2-5 lakh.
  • SOC 2 Type 2: ₹15-40 lakh annual depending on scope and audit firm.
  • ISO 27017/27018: ₹2-5 lakh additional each.

Total annual cost for the full stack: easily ₹50-80 lakh. For most growth-stage companies this is excessive relative to the commercial value the certifications produce. The right approach is to certify against what customers actually require, and to defer additional certifications until specific customer demand justifies them.

A useful diagnostic: ask the sales team what certifications customers are asking for in security questionnaires. If the answer is “SOC 2 Type 2,” that is the certification to invest in. If a specific customer is asking for ISO 27001 in addition, get ISO 27001. If nobody is asking for ISO 27017, do not get ISO 27017. The certification driven by abstract maturity arguments rather than specific customer demand is rarely worth the cost.

A second useful diagnostic: certifications that the regulator actually requires. RBI does not require ISO 27001 of regulated entities; some regulators effectively require it through how they interpret cybersecurity adequacy. SEBI CSCRF does not require any specific external certification. The IRDAI Information and Cyber Security Guidelines do not mandate any certification. Most “the regulator wants ISO 27001” claims I encounter are inferences rather than direct requirements; verify them before committing.


The compliance consulting market

Compliance and security consulting is a large fragmented market. It ranges from the Big Four cybersecurity practices through the mid-tier specialist firms through the independent practitioners. Each tier targets different audiences and produces different value at different cost.

The straightforward observation: most clients pay more for the tier they have hired than they need to.

Big Four engagement (PwC, Deloitte, EY, KPMG) costs ₹3-15 lakh per month for a mid-sized programme, often more. The work product is professional, the team is large, and the brand on the report has procurement-friendly weight. The team that does the actual work tends to be early-career, with senior partners involved at the proposal stage and at the report-sign-off stage. The value is in the procurement-friendliness, not in the depth of the security advice. Use them when you need the brand on the report or you are managing political risk in a procurement-driven decision.

Mid-tier specialist engagement costs ₹1.5-6 lakh per month for similar scope. The team is smaller, more senior, more security-experienced. The work product is less polished but more useful. The brand is less procurement-friendly. Use them when you want the depth of advice and your decision-makers do not require the Big Four label.

Independent practitioner engagement costs ₹50,000-2.5 lakh per month. The advisor is one person; the value depends entirely on their specific expertise. The work product is direct; the procurement-friendliness is lowest. Use them when you trust the named individual specifically, you want depth, and you are not buying the report’s optics.

The cost differential between tiers can be 5-10x for similar work product on substance. The optics differ; the substance does not necessarily. Most early-stage and growth-stage companies are best served by the mid-tier or independent practitioner; the Big Four engagement is rarely the right cost-value point until the company is large enough that procurement optics matter.

The recurring oversell: founders being convinced that “we need a Big Four name” for the audit committee, when the audit committee is happy with the mid-tier firm and only the founder thinks the optics matter. The fix is to ask the audit committee directly. They often surprise the founder with a more pragmatic answer than expected.

The other recurring oversell: long engagements where the value tapers off after the first few months. A six-month consultancy that produced significant value in months 1-2 is usually still billing in month 6 because the relationship was not properly scoped. The right move is to scope consulting engagements as deliverable-based rather than time-based; pay for the audit-readiness review, the gap analysis, the policy library, rather than for ongoing presence.


The auditor relationship

The audit firm market is less competitive than the consulting market, partly because auditing requires accreditation and partly because audit independence rules constrain which firm can do which work. The market for ISO 27001 certification bodies, SOC 2 audit firms, and sectoral audit firms is large but with meaningful barriers to entry.

A few practitioner notes about navigating this market:

Audit firms are not interchangeable. Two ISO 27001 certification bodies with the same accreditation produce materially different audit experiences. Some are deeper; some are friendlier; some are slower; some are stricter. The reputation of specific certification bodies matters in the markets where the certificate will be presented to customers; UK, German, and certain US-based certification bodies carry more weight than smaller country-of-origin bodies for some customer audiences.

Auditor selection is a strategic choice. The audit firm you pick will be auditing you for three years before the certificate cycles. Switching mid-cycle is possible but expensive. The right time to evaluate audit firms is before the first audit, and the evaluation should include the firm’s reputation, the auditor’s seniority, the firm’s pricing structure for surveillance years, and the firm’s responsiveness during the prior year.

The audit firm’s incentive is to find findings. This is not negative; it is the structural reality. An audit with zero findings produces a less-useful report and a worse compliance posture. The CISO who tries to argue every finding into withdrawal is missing the point. The findings are the value of the audit; the question is whether the findings are real and material, not whether they exist.

Rotation is healthy. After three years with the same audit firm, the audit gets stale. The same auditor sees the same controls in the same way; new findings are rare; the audit becomes a renewal rather than an examination. Rotation every 3-6 years is good practice. Some sectoral regulators require it (the RBI ITGRCA framework references the value of auditor independence and periodic rotation).

The recurring oversell pattern: companies signing long-term audit relationships with no exit option. Negotiate the audit contract on annual terms with a clear option to switch firms. The contract that locks you in for three years removes leverage and produces a worse audit relationship.


The vendor questionnaire treadmill

A significant portion of compliance and security workload at growth-stage and mid-market companies is responding to customer security questionnaires — SIG, SIG Lite, CAIQ, custom questionnaires from individual enterprise customers. The questionnaire workload can consume 20-40% of a small security team’s time.

The market response has been a category of vendor — Whistic, ProcessUnity, OneTrust Vendorpedia, Vanta Trust Center, Drata Trust Center, several others — that automate questionnaire response by pre-populating answers, maintaining a questionnaire library, and producing trust-portal pages that customers can review without sending a custom questionnaire.

The honest reading: these tools save real time in the 6-15 lakh annual cost range, and the trust-portal approach genuinely reduces inbound questionnaire volume when customers find what they need without asking. The trust portal is one of the legitimate wins in the GRC tooling space; it produces measurable reduction in questionnaire response load.

The over-investment pattern: companies adopting the questionnaire automation tooling before they have enough questionnaire volume to justify it. Pre-revenue and early commercial companies often have low questionnaire volume; the tooling cost exceeds the time saved. Wait until you are doing more than one questionnaire per month before investing in the tooling.

The under-investment pattern: companies that have crossed the threshold but are still responding to questionnaires from scratch every time, producing inconsistent answers and consuming security team hours. The threshold for adopting tooling is roughly when questionnaire response is consuming more than 8-12 hours per week of security team time.


What works for early-stage companies

A specific guide for founders and early CISOs, since this audience is most aggressively oversold:

Do these things first, in priority order:

  1. MFA everywhere. Force-deploy MFA on all employee accounts (workspace, email, code repositories, cloud accounts, critical SaaS). Cost: low; impact: highest single thing you can do.
  2. Password manager mandated for the team. Cost: low; impact: high.
  3. Cloud account hygiene. Use the cloud provider’s free security tools (AWS Trusted Advisor, Azure Defender free tier, GCP Security Command Center free tier). Cost: zero; impact: high.
  4. Endpoint protection on all employee devices. Cost: low; impact: high.
  5. Basic access discipline. Single sign-on if affordable; SAML to all critical SaaS where available; provisioning and deprovisioning workflows that survive employee changes.
  6. Backup discipline. Daily backups of critical data, tested restore quarterly. Cost: low; impact: high.
  7. Written incident response runbook. One page. Names, phone numbers, decision tree. Cost: zero; impact: high.
  8. Written privacy notice and consent capture for any personal data processing. Cost: low; impact: high.
  9. Customer-facing security overview document. One to two pages. Used for security questionnaires.

The total cost of the above for a 10-30 person company is under ₹2 lakh annually in tooling subscriptions. There is no consulting engagement, no GRC platform, no certification, no virtual CISO. This is the baseline that works for pre-revenue and early commercial companies.

Add these when customer demand or risk justifies it:

  1. SOC 2 Type 2 or ISO 27001 certification, picked based on customer requirement. Add when you have customer requests for it that you cannot win without.
  2. Vendor risk process. Add when you have more than 10-15 third-party SaaS vendors processing meaningful data.
  3. Pen test, annual. Add when you have customer demand for it, or when you have a meaningful internet-facing product.
  4. DPIA process for personal data processing. Add when you are processing meaningful EU or Indian personal data.

Defer these until clear signal:

  • Multiple certifications stacked
  • GRC platform (use spreadsheets until they break)
  • Virtual CISO or fractional DPO (unless you have a specific use case and the budget)
  • Third-party risk platform (use spreadsheets until they break)
  • Automation tooling beyond what the cloud provider gives you free

The deferred items are not bad; they are not the right spend at this stage. The market will tell you when you have crossed the threshold by the volume of work; you do not need consultants to tell you.


What works for mid-stage companies

The mid-stage company has crossed into the territory where the deferred items start to make sense. The discipline at this stage is to add capabilities deliberately rather than sequentially.

The right adds at this stage:

  • SOC 2 Type 2 plus ISO 27001 (often both, if the customer base requires it)
  • Dedicated CISO (in-house or fractional, depending on company size)
  • GRC platform (Vanta, Drata, Sprinto, Scrut tier — pick one)
  • Trust portal for customer questionnaires
  • Annual penetration testing programme
  • Vendor risk programme with formal classification
  • Privacy programme with DPIA, ROPA, breach response
  • Tabletop exercises annually
  • Cyber insurance coverage

Total annual spend: ₹40-100 lakh depending on scale and rigour. This is meaningful but proportionate; the same spend at an early-stage company would be excessive, at the mid-stage it is competitive baseline.

What to push back on at this stage:

  • Multiple GRC platforms claiming to cover the same scope
  • Consultancies recommending the full Big Four engagement model
  • Certification stacking beyond customer-required certificates
  • Virtual CISO firms pitching as a replacement for in-house leadership; they are useful as supplemental capacity, not as the CISO function itself
  • “Enterprise” pricing on tooling that is overkill for current scale

What works for enterprise companies

Enterprise companies have the budget and the regulatory exposure to justify the full compliance programme stack. At this stage the cost discipline shifts from “what to add” to “how to consolidate.”

The recurring pattern at enterprise scale: tool sprawl. The security organisation accumulates tools faster than it consolidates them. Each tool was the right choice at its purchase moment; the cumulative footprint is excessive. Enterprise CISOs should run a tooling consolidation review annually, evaluating which tools have overlapping capability and which can be retired.

The second pattern: consulting spend that does not produce institutional capability. Engagements that produce reports rather than capabilities; recommendations that the internal team has to operationalise on top of their existing workload. The enterprise should require consulting engagements to produce transferable capability, not just reports. “We hired the consultancy and our internal team is now able to do X” is the success metric, not “we have a report on X.”

The third pattern: certifications maintained from inertia rather than from current value. The enterprise that holds five certifications because they have always held five certifications, including some that no current customer requires. An annual review of certification value catches this; some certificates can be allowed to lapse.


The signals that you are being oversold

A short list of phrases and patterns that indicate the vendor or consultant is pushing you to a tier you do not need:

“Every company at your size needs…” Categorical claims about what “every company” needs are usually wrong. Every company is specific; the right spend depends on customer base, regulatory environment, and risk profile.

“You will need this for [future event].” Sales-led timing. The future audit, the future customer ask, the future regulation. These are sometimes real; often they are speculative. Verify the specific need before buying capability for hypothetical future requirements.

“This will save you N hours per week.” Quantification of time savings is rarely calibrated to your actual workflow. Ask for specifics: what tasks specifically, on what tools you currently use, with what data integration that you currently have. The math usually evaporates under scrutiny.

“Your competitors are all using this.” Social proof claims that you can verify. Ask which competitors specifically. The named-competitor list is often shorter than the categorical claim implies.

“You cannot get certified without our tool.” False except in specific narrow circumstances. ISO 27001 certification has no required tooling. SOC 2 has no required tooling. The “you cannot get certified without us” claim is almost always commercially-driven rather than technically true.

“The regulator will require this.” Specific regulator citations should be specific. “The RBI requires ISO 27001” is not true. “RBI’s ITGRCA framework references the value of certification” is true but materially weaker. Verify the regulatory citation before accepting it as a requirement.

“This is industry best practice.” “Best practice” is rarely defined precisely. Ask what the practice is, who follows it, what the alternative would be, and what the consequence of not adopting it would be. The honest answer is often that the practice is one option among several, not the categorically correct choice.

The fix for being oversold is not aggressive procurement; it is informed buying. Read the spec sheets carefully. Ask for the specific value the offering produces. Compare to what you would do without the offering. Decide. The discipline is unfashionable in a market that rewards fast purchases, but it produces durable cost control.


What this guide does not cover

Three areas worth their own treatment:

  1. Specific vendor or consultancy recommendations. I have deliberately not named specific vendors as good or bad. The right vendor depends on context; recommendations would age badly. The diagnostics in this guide help you evaluate any specific offer.

  2. The buyer-side of compliance — what customers actually want. This guide is from the seller’s compliance posture perspective. The customer side — how to read other companies’ security postures, how to design vendor risk programmes that get useful data without burdensome questionnaires — is its own topic.

  3. The compliance career market. The same dynamic applies to careers as to vendor purchasing. The compliance industry has expanded the certifications, the credentialing, the role specialisations. What you actually need as a compliance professional is more limited than the credentialing market suggests. Worth its own treatment.


This guide is a practitioner reference, not procurement advice. It reflects how the compliance and GRC market operates as of May 2026 in India and internationally, and is not affiliated with any specific vendor, certification body, or consulting firm. Compliance teams should adapt the framework to their specific circumstances, customer requirements, and regulatory environment.

ControlForge synthesises compliance requirements across major frameworks to surface the strictest-clause specification underlying defensible posture. The synthesis approach is itself a response to the over-stacking problem this guide describes; the goal is one specification, not many overlapping ones.