Your compliance platform proves the control exists. Not that it works.
Compliance automation platforms are genuinely good at evidencing your controls. What none of them can show is whether your people behave more securely because of them. This page shows exactly where that line falls — and why the effectiveness regimes ask for both sides of it.
What compliance automation does well
Compliance automation platforms take real pain out of getting and staying certified. Tools like Vanta and Drata connect read-only to your cloud, identity and HR systems, continuously monitor whether your controls stay configured, and collect the evidence an auditor needs — replacing the manual screenshot-and-spreadsheet work that used to surround a SOC 2 or ISO 27001 audit. If your job is achieving and maintaining certification, they are excellent at it.
Source: Vanta and Drata product documentation · Verified July 2026
The line
Here is where it falls. Compliance automation evidences the existence and configuration of a control — that a policy is written, a program is assigned, a setting is switched on and stays on. The effectiveness of a human-layer control is a different question: do people actually behave more securely because of it? That answer lives in behavior over time, and the data sources a compliance platform reads — configuration state, attestations, system integrations — do not reach it.
A control that exists is not a control that works
Compliance automation proves a control is in place and configured. The effectiveness regimes go one step further and ask whether it actually works — and for a human-layer control, that is a behavioral question.
| What your reports show | What the regulation asks for | What closes the gap |
|---|---|---|
| Evidence that a security-awareness control exists and policies are attested | GDPR Art 32(1)(d) — a process for regularly testing, assessing and evaluating effectiveness | Behavioral evidence that the control changed how people act |
| Continuous monitoring that controls stay configured | NIS2 CIR Annex §7 — the effectiveness of risk-management measures is evaluated | A behavioral baseline and trend for the human layer of those measures |
| Audit-ready records that a measure is operating | NIS2 CIR Annex §8.1.3 — awareness and training programs assessed for effectiveness | Independent measurement of whether behavior actually improved |
A policy attestation is not an effectiveness test. Compliance automation proves the control exists; behavioral evidence proves it works; the clause asks for both.
See what GDPR Article 32 actually asks forPeer-reviewed field research
29–55%
of the variation in phishing susceptibility is attributable to organizational-level factors, not individual ones.
Measured across 83,269 employees in 510 organizations, using their real responses to phishing campaigns.
Petrič, G., & Roer, K. (2022). The impact of formal and informal organizational norms on susceptibility to phishing. Telematics and Informatics, 67, 101766. Licensed under CC BY 4.0.
How they fit together
This is a complement, not a displacement. Praxis Navigator produces a behavioral evidence artifact — a baseline, a trend, and a before-and-after around a specific intervention — that slots into your compliance program as the effectiveness evidence for your human-layer controls. Your compliance platform proves the control exists and stays configured; Praxis proves it works; together they answer the whole clause instead of half of it.
Control evidence vs behavioral evidence
Two kinds of evidence for the same program. One shows the control is there; the other shows it changed behavior.
| Capability | Compliance automation | Praxis Navigator | Together |
|---|---|---|---|
| Continuous control monitoring | Yes | — | The compliance platform proves controls stay configured |
| Automated audit evidence collection | Yes | — | The compliance platform assembles the audit pack |
| Evidence a control exists and is configured | Yes | — | The compliance platform proves existence |
| Whether the human layer of a control works | — | Yes | Praxis proves behavior actually changed |
| Behavioral baseline and before/after comparison | — | Yes | Praxis supplies the effectiveness evidence |
| Published pricing, self-serve signup | — | Yes | Praxis is buyable without a sales call |
| Dedicated environment per customer | — | Yes — dedicated Azure | No pooled tenant data |
| Evidence independent of the control being tested | — | Yes | Measurement that isn't produced by the control itself |
Pricing you can see
Our prices are published. Use the calculator, see your number, start a trial — no sales call, no qualification, no quote request. Most platforms in this category will not tell you the price without a meeting first.
See the priceQuestions compliance leaders ask
We already have SOC 2 — isn’t that enough?
Does Praxis Navigator replace Vanta or Drata?
Does Praxis Navigator integrate with our compliance platform?
Can a compliance platform satisfy the effectiveness requirement on its own?
What does Praxis Navigator read?
Evidence the control actually works
Connect Microsoft 365 in 15 minutes and produce the behavioral evidence your compliance program is missing for the human layer.
Start your free 30-day trialNo credit card. No commitment. Results in 15 minutes, or don't continue.
See the price — published, no sales call required.
Read what GDPR Article 32 requires — testing, assessing and evaluating effectiveness, not just documenting it.