Skip to content
    July 29, 2026| Top Floor Team| 10 min read

    Build or Buy: Should You Run Compliance In-House?

    Skip the either-or question. For most companies between 30 and 500 employees, the right answer is neither a fully in-house compliance program nor a fully outsourced one. It's a hybrid: your company owns the program (the risk decisions, the policy sign-offs, the accountability to customers and regulators) while an outside team runs the execution (evidence collection, control monitoring, auditor management, the weekly grind). Both vendor camps will tell you otherwise. GRC platform vendors say software plus your existing staff is all you need. Managed compliance firms say hand over the whole thing. Notice that each pitch conveniently matches what the vendor sells.

    We sell outsourced compliance for a living, so read what follows knowing that. We'll also tell you plainly when building in-house is the better call, because sometimes it is.

    Key takeaways

    • Skip the either-or. For most companies between 30 and 500 employees the answer is a hybrid: you own the program, an outside team runs the execution.
    • Both vendor camps push the answer that happens to match what they sell. Score your own situation instead.
    • Five variables decide it: distance to your audit deadline, number of frameworks carried, security headcount, regulatory exposure, and whether compliance is customer-facing.
    • Under six months to an audit, outsource execution. There is no time to hire, and an enterprise GRC platform deployment runs six to twelve months from purchase to a program that functions.
    • Accountability never outsources. Risk acceptance, policy approval, budget authority, incident declaration, and every regulator or customer relationship sit with an employee whichever model you pick.

    What "build" actually costs

    Start with headcount, because this is where the in-house math breaks for smaller companies. A functioning compliance program needs four to five distinct roles: compliance platform vendor Carbide puts it as "a robust security program requires four or five different roles". In practice that means someone who owns the program, someone who writes and maintains policy, someone who implements technical controls, someone who collects and manages evidence, and someone who runs audits and customer security reviews. At an enterprise those are five different people, sometimes five teams. At a 60-person startup, the pitch is that your CTO absorbs all five. She won't. She'll handle the technical controls, sign whatever gets put in front of her, and the other three roles will sit unstaffed until three weeks before the audit.

    Put rough numbers on it. A dedicated compliance manager runs $150,000 to $220,000 a year fully loaded (the same Carbide-benchmarked, BLS-loaded arithmetic we work through in our hiring-versus-outsourcing piece); a GRC analyst adds another $90,000 to $120,000. That's $240,000 to $340,000 a year before you've paid for a compliance automation platform, the audit itself, or a penetration test. (The analyst figure is our estimate from scoping these engagements every week, not survey data; your market may differ.) A single-framework outsourced program typically costs less than one mid-level hire.

    Then there's the timeline problem. Buying the platform is not the same as having a program, and the gap between them is measured in months, not weeks. We are not going to attach a market-wide number to that gap, because we could not find one we trust: the vendors who publish deployment timelines are pricing their own onboarding (ZenGRC, for instance, advertises being "up and running within weeks, not months or years"), and none of them is measuring the thing that actually takes time. That thing is not vendor incompetence; it's the honest cost of tailoring the control framework, wiring up integrations, and training control owners. If your biggest prospect just asked for a SOC 2 report and your audit window is 90 days out, build-it-yourself isn't a strategy. It's a missed deal.

    The five questions that decide it

    Ignore the ideology from both camps. Five variables determine which way you should go, and you can score yourself on them in ten minutes.

    1. How far away is your audit deadline?

    Under six months: outsource execution, full stop. There isn't time to hire (a decent compliance hire takes three to four months to source and onboard) and there isn't time for a GRC deployment to mature. Twelve months or more of runway: building becomes viable, if the other four axes support it.

    2. How many frameworks are you carrying?

    One framework, say SOC 2 alone, is manageable in-house with a competent generalist. Two or three overlapping frameworks (SOC 2 plus ISO 27001 plus HIPAA) is where cross-mapping controls, deduplicating evidence, and running a shared audit calendar start to reward specialist experience. Teams that live in multi-framework programs have already made the mistakes you're about to make.

    3. What's your security headcount?

    Zero dedicated security staff means you can't build; there's nobody to build with. One or two security engineers should be doing security engineering, not chasing screenshots of MFA settings. We see this constantly in first audits: a capable engineer spending a third of their year on evidence collection that a specialized team would knock out in a fraction of the time. Five or more, and in-house execution starts to make real sense.

    4. What's your regulatory exposure?

    Customer-driven compliance (SOC 2 to close enterprise deals) tolerates outsourcing well; the worst case is a delayed deal. Regulator-driven compliance is different. HIPAA with real OCR exposure, CMMC as a condition of DoD contracts, state money-transmitter exams: these carry fines, contract disbarment, and personal liability for officers. Higher exposure argues for more in-house ownership and more senior oversight. Note that this means ownership, not necessarily more in-house labor.

    5. Is compliance customer-facing?

    If your sales team fields security questionnaires weekly and your SOC 2 report is a closing document, compliance is a revenue function. Someone internal has to speak to it credibly on sales calls. That person doesn't need to run the program day to day, but they can't be a name on an org chart who forwards emails to a vendor.

    Tally it up. Deadlines close, frameworks few, headcount thin: buy execution. Deadlines distant, frameworks many, headcount real, regulator watching: build, and buy point services. Most mid-market companies score somewhere in between, which is exactly why the hybrid exists.

    Three companies, three answers

    CompanyWhat the five axes sayThe call
    40-person SaaS, 90-day deadlineDeadline critical, one framework, zero security headcount, low regulatory exposure, heavily customer-facingBuy execution
    300-person fintech, three frameworksMultiple frameworks, a three-person security team, regulator contact, no near-term crunchHybrid
    1,200-person healthcare platform with defense contractsHigh regulatory exposure, multiple frameworks, an eight-person security organization, compliance facing both customers and regulatorsBuild, and buy point services rather than a managed program

    The 40-person SaaS company with a 90-day deadline. Series A. First enterprise prospect is demanding SOC 2, and procurement wants at least a Type 1 this quarter. No security hires; the CTO is the security team. Score the axes: deadline critical, one framework, zero headcount, low regulatory exposure, heavily customer-facing. This is the clearest buy case there is. Outsource execution and audit management, name the CTO as the accountable owner, and have her spend two hours a week reviewing decisions instead of twenty hours doing the work. Building here means either a panic hire or losing a quarter of your engineering leadership's attention. Neither is worth it. (For what that first audit runs, see our SOC 2 cost breakdown.)

    The 300-person fintech with three frameworks. SOC 2 and PCI DSS for customers, state money-transmitter exams for regulators. A three-person security team, annual audits, no near-term crunch. This is hybrid territory, and it's where most mid-market companies belong. Keep a full-time compliance lead in-house who owns the risk register, signs the policies, and faces the examiner. Outsource the execution layer: evidence operations, control monitoring, auditor wrangling, questionnaire responses. The in-house lead directs; the outside team does. The failure mode to avoid is hiring three GRC analysts to do evidence collection internally. You'd pay $300,000 or more for work an outsourced team does faster, because they run the same playbook across dozens of clients instead of one.

    The 1,200-person healthcare platform with defense contracts. HIPAA with genuine OCR exposure, CMMC Level 2 required for the DoD work, an eight-person security organization. Every axis points the same direction: high regulatory exposure, multiple frameworks, real headcount, compliance facing both customers and regulators. Build. This company should run compliance in-house with a named owner per framework, and buy point services rather than a managed program: an annual penetration test, a readiness assessment before the C3PAO arrives, surge support in audit season. Outsourcing the whole program at this size just inserts a coordination layer between your team and your auditors. We'd happily take their money for the point engagements and tell them not to buy the managed service.

    What the hybrid looks like in practice

    The division of labor matters more than the label. Here's the split we run with compliance-as-a-service clients, and it's the split we'd recommend even if you buy from someone else.

    Stays in-house:

    • An accountable executive with real authority (CTO, COO, or a compliance lead)
    • Risk acceptance decisions and the risk register
    • Policy approval (drafting can be outsourced; signing cannot)
    • Budget and vendor selection
    • Incident declaration and regulator or customer notification
    • The relationships: your auditor knows your executive, not just our team

    Gets outsourced:

    • The evidence collection calendar and the chasing that goes with it
    • Control monitoring and drift detection between audits
    • Audit project management, from kickoff through report delivery
    • Security questionnaire responses, with internal review on the sensitive ones
    • Gap remediation tracking (your engineers still fix the gaps)

    If you don't have a senior security voice internally, a vCISO covers the oversight half of this split without a full-time executive hire; we've written about when that model fits in our virtual CISO guide. And one procurement tip whichever direction you go: ask any managed compliance vendor for their transition plan before you sign. A well-run outsourced program documents everything in your systems, under your accounts, so you can take it in-house later without starting over. If the vendor squirms at that question, they're selling lock-in, not a program.

    Where we'd tell you not to hire us

    Three cases. First, if you're a single-framework shop with twelve-plus months of runway and an employee who genuinely wants to own compliance as a career move, build it. The program will be slower to stand up and rougher in year one, but institutional knowledge compounds, and by year three that person knows your environment better than any vendor could.

    Second, if you're at enterprise scale where compliance is a differentiator (a security company selling to banks, say), the credibility of a large in-house GRC function is part of the product. Buy tooling, not management.

    Third, if your leadership plans to treat an outsourced program as a way to stop thinking about security entirely, don't buy from us or anyone. An outsourced program with a disengaged owner produces a certificate and nothing else, and as of August 2026 the customers reading your SOC 2 report have gotten noticeably better at telling the difference.

    Frequently asked questions

    What has to stay in-house no matter what?

    Accountability and decisions. Risk acceptance, policy approval, budget authority, incident declaration, and every regulator or customer relationship must sit with an employee, whichever model you choose. When a prospect's CISO or an OCR investigator asks who owns security at your company, the answer has to be a name on your payroll. You can delegate the work; you cannot delegate the ownership, and any vendor who implies otherwise is misrepresenting how audits and enforcement work.

    How fast can an outsourced compliance program stand up?

    Weeks, not quarters. A typical sequence: gap assessment in the first two to three weeks, remediation plan by day 30, evidence collection running by day 45 to 60, and a SOC 2 Type 1 audit achievable around the 90-day mark from a standing start if the remediation load is light. Compare that with three to four months just to hire a compliance manager, which is before that hire has built anything. We deliberately do not attach a number to how long an in-house GRC deployment takes to mature, for the reason given earlier in this article: the vendors who publish deployment timelines are describing their own onboarding, not the tailoring and training work that actually sets the pace. The honest caveat: outsourcing compresses program management, not engineering. If your gaps include an MFA rollout or centralized logging, your team still has to build those, on your timeline.

    Will auditors or enterprise customers penalize an outsourced program?

    No, provided ownership is internal. Auditors work with outsourced compliance functions constantly; what they flag is an organization where nobody internal can explain the controls. In sales conversations the same rule applies: a founder who can speak fluently about their security posture, backed by an outside team doing the operational work, reads far better than an in-house program nobody can articulate.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.