Your compliance platform proves the control exists. Not that it works.

Compliance automation platforms are genuinely good at evidencing your controls. What none of them can show is whether your people behave more securely because of them. This page shows exactly where that line falls — and why the effectiveness regimes ask for both sides of it.

What compliance automation does well

Compliance automation platforms take real pain out of getting and staying certified. Tools like Vanta and Drata connect read-only to your cloud, identity and HR systems, continuously monitor whether your controls stay configured, and collect the evidence an auditor needs — replacing the manual screenshot-and-spreadsheet work that used to surround a SOC 2 or ISO 27001 audit. If your job is achieving and maintaining certification, they are excellent at it.

Source: Vanta and Drata product documentation · Verified July 2026

The line

Here is where it falls. Compliance automation evidences the existence and configuration of a control — that a policy is written, a program is assigned, a setting is switched on and stays on. The effectiveness of a human-layer control is a different question: do people actually behave more securely because of it? That answer lives in behavior over time, and the data sources a compliance platform reads — configuration state, attestations, system integrations — do not reach it.

A control that exists is not a control that works

Compliance automation proves a control is in place and configured. The effectiveness regimes go one step further and ask whether it actually works — and for a human-layer control, that is a behavioral question.

A control that exists is not a control that works
What your reports show What the regulation asks for What closes the gap
Evidence that a security-awareness control exists and policies are attestedGDPR Art 32(1)(d) — a process for regularly testing, assessing and evaluating effectivenessBehavioral evidence that the control changed how people act
Continuous monitoring that controls stay configuredNIS2 CIR Annex §7 — the effectiveness of risk-management measures is evaluatedA behavioral baseline and trend for the human layer of those measures
Audit-ready records that a measure is operatingNIS2 CIR Annex §8.1.3 — awareness and training programs assessed for effectivenessIndependent measurement of whether behavior actually improved

A policy attestation is not an effectiveness test. Compliance automation proves the control exists; behavioral evidence proves it works; the clause asks for both.

See what GDPR Article 32 actually asks for

Peer-reviewed field research

29–55%

of the variation in phishing susceptibility is attributable to organizational-level factors, not individual ones.

Measured across 83,269 employees in 510 organizations, using their real responses to phishing campaigns.

Petrič, G., & Roer, K. (2022). The impact of formal and informal organizational norms on susceptibility to phishing. Telematics and Informatics, 67, 101766. Licensed under CC BY 4.0.

How they fit together

This is a complement, not a displacement. Praxis Navigator produces a behavioral evidence artifact — a baseline, a trend, and a before-and-after around a specific intervention — that slots into your compliance program as the effectiveness evidence for your human-layer controls. Your compliance platform proves the control exists and stays configured; Praxis proves it works; together they answer the whole clause instead of half of it.

Control evidence vs behavioral evidence

Two kinds of evidence for the same program. One shows the control is there; the other shows it changed behavior.

Compliance automation compared to behavioral evidence
Capability Compliance automation Praxis Navigator Together
Continuous control monitoringYesThe compliance platform proves controls stay configured
Automated audit evidence collectionYesThe compliance platform assembles the audit pack
Evidence a control exists and is configuredYesThe compliance platform proves existence
Whether the human layer of a control worksYesPraxis proves behavior actually changed
Behavioral baseline and before/after comparisonYesPraxis supplies the effectiveness evidence
Published pricing, self-serve signupYesPraxis is buyable without a sales call
Dedicated environment per customerYes — dedicated AzureNo pooled tenant data
Evidence independent of the control being testedYesMeasurement that isn't produced by the control itself

Pricing you can see

Our prices are published. Use the calculator, see your number, start a trial — no sales call, no qualification, no quote request. Most platforms in this category will not tell you the price without a meeting first.

See the price

Questions compliance leaders ask

We already have SOC 2 — isn’t that enough?
SOC 2 shows your controls are designed and operating, which is necessary but not the same as showing they change behavior. A SOC 2 report can confirm you run a security-awareness program; it does not show whether people handle real risk more safely afterwards. NIS2, DORA and GDPR increasingly ask for that second thing — a measured change in behavior over time.
Does Praxis Navigator replace Vanta or Drata?
No. They do different jobs. Vanta and Drata evidence that your controls exist and stay configured; Praxis Navigator evidences whether the human layer of those controls actually works. Praxis output is a behavioral evidence artifact you attach to your compliance program, not a replacement for it.
Does Praxis Navigator integrate with our compliance platform?
Praxis Navigator produces exportable behavioral evidence — baselines, trends and before-and-after comparisons — that goes into your compliance program as the artifact for human-layer controls. It reads Microsoft 365, not your compliance tool, so it complements what the compliance platform collects rather than duplicating it.
Can a compliance platform satisfy the effectiveness requirement on its own?
For the existence and configuration of controls, yes. For the effectiveness of a human-layer control — whether behavior actually changed — no, because its data sources measure configuration and attestation, not behavior over time. GDPR Art 32(1)(d) and NIS2 CIR Annex §7 ask for both, and the second is the part a compliance platform does not reach.
What does Praxis Navigator read?
More than 20 security behavior indicators across Exchange Online, SharePoint, OneDrive, Teams and Entra ID — read-only via the Microsoft Graph API, with a zero-storage architecture and a dedicated Azure environment per customer.

Evidence the control actually works

Connect Microsoft 365 in 15 minutes and produce the behavioral evidence your compliance program is missing for the human layer.

Start your free 30-day trial

No credit card. No commitment. Results in 15 minutes, or don't continue.

See the price — published, no sales call required.

Read what GDPR Article 32 requires — testing, assessing and evaluating effectiveness, not just documenting it.