Compliance should just work
A first-principles essay on trust, verification, and the economics of proving you can be trusted — and why the proof is about to be rebuilt.†
There is a very simple way to describe compliance. It is a function. It takes in a company's actual security posture — its access controls, its encryption, its policies, the daily habits of its engineers — and it outputs a single, portable signal that a stranger can rely on. Everything else, all the frameworks and auditors and 110-control checklists, is in service of producing a good version of that function.
If you have ever had a buyer's security team hold a seven-figure deal hostage over a SOC 2 report, you already grasp the problem. The interesting part is why this function exists and what a century of proving trust and compliance is supposed to verify.
§Trust is a technology
This section is starting from first principles. Trust is not a warm feeling; it is a device for cooperating under uncertainty. The sociologist Niklas Luhmann called it a mechanism for reducing complexity: trust lets you act as if you knew what another party will do, when you cannot possibly know.1 In a village, familiarity does this work. In a small industry, personal reputation does. But a defense supply chain has tens of thousands of firms, and a cloud software market has millions of buyers. No one can personally know whom to trust.
So modern economies run on what Luhmann called system trust — trust in mechanisms rather than persons. You do not trust the subcontractor; you trust the certificate. You do not inspect the bank; you trust the audit. Compliance regimes like SOC 2 and CMMC are trust factories: institutional substitutes for the handshake that does not scale.
The economists sharpened this further. Akerlof showed that when buyers cannot observe quality, markets unravel — bad quality drives out good, because no one will pay a premium they cannot verify.2 Spence showed the escape: a costly signal, one that is harder for low-quality firms to fake, lets the good separate themselves from the bad.3 Certification works as a trust signal precisely to the degree that it is expensive and hard to game. This is the strongest argument for the whole apparatus, and any honest critique has to concede it before attacking anything: compliance does real work. The tax buys something.
§A hundred and eighty years of patches
But look at how the function has been computed, and a pattern appears. Every major assurance regime in history was bolted on after a trust failure — and almost none was ever retired.
The statutory audit was born in 1844 to protect railway shareholders from their own directors. The SEC and the audited financial statement arrived in 1934, paid for by the crash of 1929. SAS 70 appeared in 1992 when companies began outsourcing their computing. Sarbanes-Oxley arrived in 2002, a direct invoice from Enron and WorldCom. SOC 2 followed in 2011 for the cloud era, ISO 27001 went global, NIST 800-171 arrived in 2015 to protect controlled unclassified information, and CMMC began binding defense contracts in November 2025.4
Notice what the pattern means: point-in-time, document-heavy assurance is not a law of nature. It is an incumbent paradigm, assembled by accident over 180 years, each layer answering the last crisis with the verification technology available at the time — paper, interviews, sampling, annual visits. The strata were deposited in an era when checking continuously was impossible. That era is over.
§The poverty line
Here is where the accumulated weight lands. Security researcher Wendy Nather coined the term security poverty line: the line below which an organization cannot be effectively protected, held down by four deficits — money, expertise, capability, and influence.5 Compliance has its own poverty line, and it is set by arithmetic, not effort.
Most compliance cost is fixed. The policies must be written, the evidence collected, the assessor paid, whether you have ten employees or ten thousand. Decades of SBA-commissioned research confirm the consequence: per-employee compliance costs fall as firms grow.6 The smallest firms pay the most per unit of output for the same badge. The Department of Defense's own rule estimates a CMMC Level 2 assessment cycle at roughly $105,000 for a small business7 — and that figure deliberately excludes the cost of actually implementing the 110 controls, which industry estimates put at $75,000 to $300,000+ for a first cycle.8
The market is voting. The defense industrial base shrank from roughly 76,700 firms in 2017 to about 60,000 in 2021, and small businesses are the fastest-declining segment.9 Honesty requires the hedge: that decline predates CMMC, and the firms themselves blame acquisition bureaucracy first. But a six-figure fixed cost layered onto a base that is already walking away is an accelerant, not a remedy. And the cruel part is that the requirement itself is rational — supply-chain security is an O-ring function, where one compromised subcontractor can collapse the integrity of a whole weapons program.10 The mission is right. The cost structure of proving it is wrong.
§The theater problem
There is a second, quieter failure. Michael Power called ours the audit society and warned that verification tends to become ritual — organizations reshape themselves to be auditable rather than secure, producing "comfort" rather than demonstrable effectiveness.11 Goodhart's law does the rest: once the metric becomes the target, it stops measuring.12 Every practitioner knows the result. The policies are written the month before the audit. The evidence is gathered in a heroic two-week sprint. The certificate is dated the day the company was at its most compliant — and posture decays from that day forward, invisibly, until next year's sprint.
The philosopher Onora O'Neill put the deepest point on it: piling on accountability rituals does not produce trustworthiness, and can corrode the real thing. What restores trust is not more checking but assessable reasons for trusting — proof that tracks reality.13 The technical world has already made this turn. Zero-trust architecture, codified in NIST 800-207,14 is an entire security doctrine built on the premise that one-time, location-based trust is obsolete: never trust, always verify, continuously, per request. Our networks already live by this philosophy. Our compliance regimes do not — yet.
§Copilots, autopilots, and the cost of getting ready
So why hasn't software fixed this? In a sense it tried. The compliance automation platforms — Vanta, Drata, Secureframe, a multibillion-dollar market — wired monitoring into the stack and built dashboards that tell you 47 controls are failing. What they did not do is fix the controls, write the policies, or sit with the auditor. They built copilots: tools that make a compliance professional more productive. But the companies that need compliance most — the startup three months from its first enterprise deal, the machine shop facing CMMC — do not have a compliance professional. The tool made the monitoring cheaper. The getting ready still costs $50,000 to $150,000 in consulting fees and three to six months of calendar time.
If you sell the tool, you’re in a race against the model. But if you sell the work, every improvement in the model makes your service faster, cheaper, and harder to compete with.Julien Bek · Services: The New Software · Sequoia Capital, 202615
Sequoia’s arithmetic is that for every dollar spent on software, six are spent on services.15 That six-to-one ratio is the whole opening. Compliance readiness is, by our estimate, roughly 70% intelligence — gap analysis, policy drafting, control mapping, evidence collection, rules-based work that AI can now do autonomously — and 30% judgement, which stays human for now.16 AI did not make compliance dashboards better; it made the service deliverable at software margins. The incumbents see it too, and they are adding agents as fast as they can. But they face a real dilemma: selling the work means cannibalizing the tool revenue their existing customers pay for. A pure autopilot has no installed base to protect. The race is on, and it will be decided by trust and by data — which is fitting, given the subject.
§Why it gets cheaper every time
One more piece of arithmetic, because it determines what you should be paying. Frameworks overlap. SOC 2 CC6.1 and ISO 27001 A.5.15 govern functionally the same access controls; across the major frameworks, 40–60% of requirements are shared.17 Yet today each framework is delivered as a separate project — redundant documentation, redundant evidence, redundant pain. GRC teams spend the majority of their time manually crosswalking what is already the same.
This is what compounds: not a template library, but hard-won knowledge of what ready actually looks like — for a Series A fintech on AWS versus a machine shop holding CUI on Azure — and what the assessor across the table will actually accept. Every engagement makes the next company's readiness faster and cheaper. The work is the product.
§Where we come in
Eagle Ridge is not building a compliance tool. We are building a compliance services company that runs on AI — an autopilot, not a copilot. The customer does not buy a dashboard. The customer buys the outcome, in four words: you are audit-ready. The intelligence is the AI's; the judgement — holding every artifact to the standard the assessor will actually apply — stays human. Proof that cannot survive that scrutiny is not proof, which is the whole argument of this essay.
We start where the budget already exists. Companies already pay outside consultants for readiness; there is an existing line item and an accepted habit of buying the outcome externally. We do that work at a fraction of the cost and the calendar time. Getting a company ready teaches the system its stack, its policies, its evidence chain — so the second framework costs less than the first, and staying compliant becomes something the customer never thinks about again. Compliance recedes to where it belongs: infrastructure. Present, load-bearing, and silent.
The deepest version of the thesis is the one the philosophers were pointing at all along. The world does not need more rituals of verification; it needs proof that tracks reality — continuous, cryptographic where possible, and cheap enough that a fifteen-person machine shop can afford to prove it. Trust is the technology that lets strangers cooperate. We intend to make manufacturing it cost almost nothing.
The question has never been whether AI can do this work. The question is whether you sell the tool or sell the work. We sell the work.
Notes & sources
† On form. The first-principles structure of this essay was inspired by Interlatent's essay on modern AI & robotics, A First-Principles View. ↩
- Niklas Luhmann, Trust and Power (Wiley, 1979; reissued Polity, 2017). Trust as a mechanism for reducing social complexity; the shift from personal trust to system trust, trust in mechanisms rather than persons. ↩
- George A. Akerlof, “The Market for ‘Lemons’: Quality Uncertainty and the Market Mechanism,” Quarterly Journal of Economics 84, no. 3 (1970): 488–500. doi:10.2307/1879431. ↩
- Michael Spence, “Job Market Signaling,” Quarterly Journal of Economics 87, no. 3 (1973): 355–374. doi:10.2307/1882010. ↩
- Joint Stock Companies Act 1844 (UK), the first statutory audit requirement; Securities Act of 1933 and Securities Exchange Act of 1934; AICPA Statement on Auditing Standards No. 70 (1992); Sarbanes-Oxley Act of 2002, § 404; AICPA SOC 2 reporting under SSAE 16 (2011); NIST SP 800-171 (2015). CMMC became a binding contract clause when the 48 CFR DFARS final rule took effect on November 10, 2025. On the failure of self-attestation: a 2020 DoD review found widespread noncompliance with 800-171, including remediation plans dated out to 2099. ↩
- Wendy Nather, “Living Below the Security Poverty Line,” RSA Conference (2013); the term originates in her 2011 writing at 451 Research. The four deficits are money, expertise, capability, and influence. ↩
- SBA Office of Advocacy research on regulatory costs by firm size (Crain & Crain and predecessor studies) documents economies of scale in compliance. See also Francesco Trebbi and Miao Ben Zhang, “The Cost of Regulatory Compliance in the United States,” NBER Working Paper 30691 (2022). Precision matters here: Trebbi–Zhang find the compliance share of the wage bill peaks for mid-size firms (~500 employees); the claim in the text is the narrower, well-supported one, that a fixed compliance cost imposes the highest per-unit burden on the smallest firms. ↩
- Cybersecurity Maturity Model Certification (CMMC) Program, Final Rule, 32 CFR Part 170, 89 Fed. Reg. 83214 (Oct. 15, 2024). DoD estimates a Level 2 certification assessment cycle at $104,670 for a small entity over three years. The rule states it does not count the cost of implementing the underlying security requirements, which it treats as already obligatory under FAR 52.204-21 and DFARS 252.204-7012. ↩
- Industry first-cycle estimates, e.g., Summit 7, CMMC Cost Guide. These figures are published by vendors selling CMMC services and should be read as directional, not definitive. ↩
- National Defense Industrial Association, Vital Signs; reported in Federal News Network (Feb. 2023): roughly 76,700 DIB firms in 2017 to about 60,000 in 2021. The decline predates CMMC; in NDIA’s survey, firms named acquisition bureaucracy as the top obstacle, and NDIA president David Norquist attributed it to companies deciding not to do business with DoD rather than to consolidation. ↩
- Michael Kremer, “The O-Ring Theory of Economic Development,” Quarterly Journal of Economics 108, no. 3 (1993): 551–575. doi:10.2307/2118400. ↩
- Michael Power, The Audit Society: Rituals of Verification (Oxford University Press, 1997), 123: “There are tendencies to create ever more formal auditable structure, regardless of demonstrable effectiveness, in order to produce comfort.” ↩
- Charles Goodhart, “Problems of Monetary Management: The U.K. Experience” (1975); the popular formulation, “when a measure becomes a target, it ceases to be a good measure,” is Marilyn Strathern’s (1997). ↩
- Onora O’Neill, A Question of Trust: The BBC Reith Lectures 2002 (Cambridge University Press, 2002). ↩
- NIST Special Publication 800-207, Zero Trust Architecture (August 2020). ↩
- Julien Bek, “Services: The New Software,” Sequoia Capital (March 5, 2026). The quotation is verbatim from the essay, as are the copilot/autopilot distinction, the intelligence/judgement distinction, and the six-to-one services-to-software spending ratio. ↩
- The 70/30 split between intelligence and judgement in compliance readiness is the author’s estimate, applying Bek’s framework to this domain. ↩
- Framework control-overlap estimates vary by source and by which frameworks are compared. Published SOC 2–to–ISO 27001 crosswalks commonly put shared coverage at 60–80%, and the AICPA publishes an official Trust Services Criteria–to–ISO 27001 mapping; SOC 2 CC6.1 (logical access controls) maps to ISO 27001 A.5.15 (Access control). The 40–60% figure used here is a deliberately conservative estimate once CMMC / NIST 800-171 — a more specialized control set — is included alongside SOC 2 and ISO 27001. ↩