If you run a collaboration tool startup, whether it’s a project management platform, shared inbox, video conferencing app, or document workspace, enterprise buyers will likely ask for your SOC 2 report before discussing your product roadmap. Today, SOC 2 is no longer a competitive advantage. Instead, it has become a basic requirement for selling to larger organizations.
Choosing the wrong SOC 2 vendor can delay your compliance journey by months and significantly increase costs. On the other hand, the right partner helps you achieve compliance faster and turns your SOC 2 report into a valuable sales asset.
Collaboration tools handle highly sensitive business information every day. For example, they often store customer messages, shared files, calendar data, and personal information for entire teams. As a result, a single security incident can affect far more than one customer. It can damage the trust of every organization using your platform. Therefore, enterprise procurement teams increasingly treat SOC 2 as a mandatory requirement for collaboration and productivity software.
Here we compare the top SOC 2 compliance vendors for collaboration tool startups. We evaluate each vendor based on its services, key features, pricing, strengths, limitations, and ideal use cases. Whether you’re preparing for your first SOC 2 audit or looking to switch providers, this guide will help you identify the best partner for your startup’s security, compliance, and growth goals.
Top 12 SOC 2 Compliance Vendors for Collaboration Tool Startups
1. Vanta

Vanta is a compliance automation platform that connects to your cloud infrastructure, identity provider, HR systems, and code repositories to run automated tests against the SOC 2 Trust Services Criteria and dozens of other frameworks. It has held the top position in G2’s Security Compliance category for multiple consecutive quarters and serves thousands of customers, including well-known SaaS companies. For collaboration tool startups, Vanta’s appeal is breadth: its integration library covers virtually every tool a modern SaaS stack uses, from AWS and GitHub to Slack and Okta.
Features
- Automated evidence collection across 300+ integrations, including cloud infrastructure, identity providers, and HR platforms
- Continuous control monitoring with real-time alerts when a control drifts out of compliance
- An AI agent that drafts security policies, completes vendor questionnaires, and flags gaps in evidence
- A customer-facing Trust Center for sharing your compliance posture with prospects
- Access to a network of vetted third-party CPA auditors for the actual SOC 2 examination
- Support for reusing evidence across ISO 27001, HIPAA, GDPR, and PCI DSS
Pricing
Custom pricing. Contact sales.
Pros
- Broadest integration library among the major automation platforms
- Strong brand recognition, which some enterprise buyers view as a positive signal during vendor security reviews
- AI-assisted questionnaire responses reduce the burden of inbound customer security reviews
Cons
- Vanta does not perform the audit itself; you still need to engage a separate CPA firm
- Multiple independent buyer reports describe renewal price increases year over year
- Smaller teams with simple, all-cloud stacks may pay for integration depth they don’t use
Best Fit
Vanta suits collaboration tool startups with a standard cloud-native stack (AWS or GCP, GitHub, an SSO provider, a common HRIS) that want the broadest possible integration coverage and are comfortable negotiating pricing directly with a sales team.
Overall Verdict
Vanta is a strong default choice for teams that want maximum integration coverage and don’t mind a heavier platform. If your priority is the lowest possible entry cost, Sprinto is worth comparing before you commit. If you want the audit and the platform from a single vendor, Thoropass is the more direct alternative.
2. Drata

Drata is a compliance automation platform that has grown into one of the two most widely shortlisted platforms in this category, alongside Vanta. It differentiates itself with unlimited users per contract tier (competitors often price by headcount) and a deep control-mapping engine that many reviewers describe as particularly strong for organizations pursuing SOC 2 and ISO 27001 together, a common pairing for collaboration tools selling into Europe.
Features
- Pre-mapped frameworks covering SOC 2, ISO 27001, HIPAA, GDPR, and Cyber Essentials
- Continuous control monitoring with guided remediation workflows
- Third-party risk management with automated vendor assessment workflows
- Unlimited users included at every published tier, rather than per-seat pricing
- Support for custom controls and custom frameworks at higher tiers
Pricing
Custom pricing. Contact sales.
Pros
- Unlimited users per contract removes a common cost surprise as your team grows
- Strong reputation for ISO 27001 control mapping, useful if European enterprise customers require it alongside SOC 2
- High customer satisfaction scores on independent review platforms
Cons
- The audit engagement with a CPA firm is a separate cost and process, coordinated but not included
- Entry pricing sits above the very cheapest automation platforms in this category
- Some reviewers report renewal increases when headcount crosses a pricing tier threshold
Best Fit
Drata fits collaboration tool startups that expect to pursue SOC 2 and ISO 27001 in the same 12-to-18-month window, especially teams with 25 to 250 employees and a meaningful in-house engineering function that wants API-driven, developer-friendly evidence collection.
Overall Verdict
Drata is a close peer to Vanta and edges ahead specifically on multi-framework mapping and the unlimited-user pricing structure. If your roadmap is SOC 2 only, on a tight first-year budget, Sprinto or Secureframe may be more cost-effective starting points.
3. Secureframe

Secureframe is a compliance automation platform founded in 2020 that positions itself as a hybrid of software and advisory services. It condenses the SOC 2 control set into a guided, step-by-step process and pairs its automation with more hands-on human support than some competitors, which reviewers consistently note as a differentiator for teams without an in-house compliance function.
Features
- A Common Control Layer that maps a single control across SOC 2, ISO 27001, HIPAA, and other frameworks to avoid duplicate work
- Automated evidence collection from 150+ cloud and SaaS integrations
- Vendor risk management with automated reminders when a third party’s certifications expire
- Built-in employee onboarding and offboarding workflows tied to access reviews
- Trust AI tools that automate vendor questionnaire responses and risk scoring
Pricing
Custom pricing. Contact sales.
Pros
- More advisory support bundled into the platform than pure self-serve competitors
- Broad framework library (45+) with prebuilt templates maintained by compliance staff
- Solid integration coverage for common cloud, HR, and identity tools
Cons
- Smaller auditor network compared to Vanta’s marketplace, so confirm your preferred auditor supports Secureframe evidence exports before signing
- Some users report a less intuitive interface for bulk operations
Best Fit
Secureframe is a good match for collaboration tool startups whose founding team has never managed a compliance program before and wants more guided hand-holding than a pure self-serve platform provides, without hiring a full-time compliance hire.
Overall Verdict
Secureframe earns its reputation on support quality and cross-framework efficiency. Teams that are highly technical and prefer to self-serve with minimal advisory touch may find equivalent or better value in Vanta or Drata at a similar price point.
4. Sprinto

Sprinto is widely recognized as one of the top SOC 2 compliance vendors for collaboration tool startups because it offers a full-featured compliance automation platform at a competitive price. The platform is particularly suited to startups with fewer than 25 employees and complements its automation capabilities by partnering with established U.S. CPA audit firms to perform the official SOC 2 examination.
Features
- Automated, stack-aware onboarding that scans your environment and outputs a prioritized task list on day one
- Entity-level continuous monitoring that names the specific user, device, or repository behind a failing control
- A single-click, customer-facing Trust Center
- Built-in security awareness training and policy templates included in the base subscription
- No paid add-on modules; core capabilities are bundled into one quote
- A dedicated onboarding manager assigned to every account
Pricing
Custom pricing. Contact sales.
Pros
- Consistently the lowest realistic entry point among full-featured automation platforms for sub-25-employee startups
- Bundled pricing model avoids the surprise add-on costs common elsewhere in this category
- High customer satisfaction ratings on independent review platforms, particularly for support responsiveness
Cons
- Integration library is smaller than Vanta’s, which can matter for teams on a less common tech stack
- The audit remains a separate CPA engagement, priced and scheduled independently
- Some reports describe steeper renewal-year price increases than peers
Best Fit
Sprinto is the strongest option for pre-Series A or early Series A collaboration tool startups with a lean, cloud-and-SaaS-only stack (AWS, GitHub, Google Workspace, Slack, Okta) that need to close their first enterprise deal without a large compliance budget.
Overall Verdict
For budget-conscious first-time SOC 2 buyers, Sprinto is hard to beat on value. Teams that expect rapid growth into a complex, multi-region infrastructure within the first year may outgrow its integration depth faster than they would with Vanta or Drata.
5. Thoropass

Thoropass is widely regarded as one of the top SOC 2 compliance vendors for collaboration tool startups because it combines compliance automation software with a licensed, AICPA peer-reviewed CPA firm under one organization. Unlike most providers, Thoropass enables startups to purchase both the compliance platform and the official SOC 2 audit through a single bundled contract, eliminating the need to manage separate vendor relationships.
Features
- A single platform combining evidence collection, policy management, and direct in-platform communication with your assigned auditor
- First Pass AI and Smart Sort AI, which pre-screen evidence before the formal audit begins
- In-house audit capability across SOC 1, SOC 2, ISO 27001, HITRUST, PCI DSS, HIPAA, and GDPR
- A “connected audit” workflow where your evidence and your auditor operate in the same system, with no handoff between a readiness tool and a separate audit firm
- A standalone audit module for companies that already use a different GRC platform and only need the CPA engagement
Pricing
Custom pricing. Contact sales. Thoropass is unusual in that its bundled model combines the platform subscription and the audit fee into one contract, so ask specifically whether your quote covers both.
Pros
- Eliminates the coordination overhead of managing a separate software vendor and audit firm
- The CPA entity is AICPA peer-reviewed and holds additional accreditations, including PCI QSA and HITRUST Authorized External Assessor status
- Strong fit for companies that expect to add HITRUST or PCI DSS alongside SOC 2
Cons
- Because the platform and audit are bundled, switching to a different CPA firm later (for example, to a Big Four brand ahead of an IPO) requires migrating off the platform entirely
- Some enterprise procurement policies require a fully arms-length audit firm with no commercial ties to the readiness vendor; confirm this isn’t a blocker for your buyers before signing
- Fewer third-party integrations than Vanta or Drata
Best Fit
Thoropass fits collaboration tool startups pursuing their first SOC 2 who want a single vendor relationship rather than coordinating a software platform and a separate CPA firm, especially teams also anticipating HITRUST or PCI DSS requirements from healthcare or payments customers.
Overall Verdict
The single-vendor bundle is a genuine convenience, and the audit quality is credible and AICPA-recognized. If your enterprise buyers have strict independence requirements for the audit firm, or if you’re set on a specific CPA brand, a platform-plus-separate-auditor approach like Vanta or Sprinto paired with A-LIGN or Schellman may be the safer structural choice.
6. Scytale

Scytale is an AI-driven compliance platform that pairs its automation software with dedicated human compliance experts assigned to every account. Among the platforms in this list, Scytale leans furthest into bundling advisory hours directly into the subscription rather than treating expert guidance as a paid add-on.
Features
- An AI GRC agent (“Scy”) that automates evidence review, risk management tasks, and policy generation
- A dedicated compliance expert assigned to guide readiness, interpret auditor feedback, and coordinate audit logistics
- Support for 60+ security, privacy, and AI governance frameworks, including SOC 2, ISO 27001, ISO 42001, and GDPR
- A Built-In Audit option that connects clients with a pre-vetted network of audit partners and negotiated bundle pricing
- Penetration testing coordination and a customer-facing Trust Center included in the platform
Pricing
Custom pricing. Contact sales.
Pros
- The bundled advisory layer is genuinely differentiated; it functions as a partial compliance-manager hire rather than a pure software tool
- Strong customer satisfaction scores, with reviewers frequently naming individual account managers by name
- Broad framework coverage, useful for teams anticipating ISO 42001 (AI governance) requirements as AI features become part of their product
Cons
- Integration reliability has been flagged by some users as inconsistent for less common tools
- Pricing is entirely custom-quoted with no published floor
Best Fit
Scytale suits collaboration tool startups without a dedicated compliance or security hire that want a vendor to function as an extension of their team, not just a dashboard, particularly companies planning to add ISO 27001 or AI governance frameworks alongside SOC 2.
Overall Verdict
Scytale’s bundled advisory model offers real value for resource-constrained teams, and it directly addresses the most common bottleneck in first-time SOC 2 programs: internal judgment, not technology. Teams with an experienced in-house CISO who only need automation, not guidance, may find the advisory layer redundant relative to its cost.
7. A-LIGN

A-LIGN is recognized as one of the top SOC 2 compliance vendors for collaboration tool startups and serves thousands of organizations worldwide. As a licensed CPA firm and cybersecurity compliance partner, it offers a broad portfolio of compliance services, including SOC, ISO 27001, PCI DSS, HITRUST, FedRAMP, and CMMC. The firm delivers these services through its proprietary audit management platform, A-SCEND, making it a strong choice for startups planning to scale their compliance programs beyond SOC 2.
Features
- SOC 2 readiness assessments to identify control gaps before the formal audit begins
- The A-SCEND platform, which maps evidence once and reuses it across multiple frameworks and future audit cycles
- Accreditation as a Licensed SOC Auditor, PCI QSA, HITRUST CSF Assessor, FedRAMP 3PAO, and CMMC C3PAO
- A dedicated audit team structure (senior manager, manager, and auditor) assigned to every engagement
- Support for audit harmonization across multiple simultaneous frameworks (for example, SOC 2 and ISO 27001 in the same cycle)
Pricing
Custom pricing. Contact sales. Independent industry estimates place typical SOC 2 engagements for growth-stage companies in a broad range depending on scope and Trust Services Criteria selected, but A-LIGN does not publish an official rate card.
Pros
- Among the widest accreditation lists of any single audit firm, useful if you expect to need FedRAMP, HITRUST, or CMMC down the road
- A-SCEND’s multi-framework evidence mapping meaningfully reduces duplicate work for companies pursuing more than one certification
- Well-established relationships with major compliance automation platforms, including Vanta, for a smoother handoff
Cons
- As a larger, multi-service firm, the engagement experience can feel less personal than a boutique specialist for a very small, early-stage team
- Full end-to-end timelines, including the required observation period for a Type 2 report, typically run five to seven months
- Pricing requires a direct sales conversation with no published floor
Best Fit
A-LIGN fits collaboration tool startups that anticipate needing more than just SOC 2 within the next two to three years for example, a company selling into both commercial and government-adjacent markets that will eventually need FedRAMP or CMMC alongside its core SOC 2 report.
Overall Verdict
A-LIGN’s accreditation breadth is a genuine long-term advantage for companies with an expanding compliance roadmap. For a startup that only needs a single, straightforward SOC 2 Type 2 report and values a smaller, more boutique feel, Johanson Group or Prescient Assurance may deliver a faster, more startup-tailored experience.
8. Schellman

Schellman is a licensed CPA firm has built a reputation as the only Top 50 U.S. CPA firm to specialize exclusively in IT audit and cybersecurity attestation rather than general financial audit work. Notably for early-stage companies, Schellman created SOC Essentials, a SOC 2 examination product specifically scaled to the control maturity of early-stage organizations rather than importing enterprise-grade evidence expectations.
Features
- SOC Essentials, a right-sized SOC 2 report built for companies new to the compliance journey, using a standardized control set appropriate to early-stage maturity
- Full accreditation across SOC 1/2/3, ISO 27001, ISO 42001, HITRUST CSF, PCI DSS, and FedRAMP
- A clear path to graduate from SOC Essentials into a more customized SOC 2 report as the company matures
Pricing
Custom pricing. Contact sales. Schellman does not publish a rate card; scope, number of Trust Services Criteria, and system complexity determine the final quote.
Pros
- SOC Essentials is a genuinely differentiated product for first-time SOC 2 buyers who don’t want to over-invest in enterprise-grade scope before they need it
- Strong brand recognition among enterprise buyers, given its Top 50 CPA firm status and deep government-sector credentials
- Explicit independence policy, avoiding any appearance of conflicts of interest tied to platform partnerships
Cons
- As a larger national firm, typical engagement timelines can run longer than a boutique specialist for straightforward, single-framework startups
- No published starting price point, unlike some boutique competitors
- Best value is realized when a company plans to eventually pursue additional frameworks Schellman also covers; a company with no multi-framework roadmap may not need this level of accreditation depth
Best Fit
Schellman is an excellent fit for collaboration tool startups pursuing their very first SOC 2 report who want a nationally recognized CPA brand behind a scope calibrated to their actual current maturity, rather than a generic enterprise-sized audit.
Overall Verdict
SOC Essentials directly solves a real problem: many first-time SOC 2 buyers are quoted scope designed for companies five times their size. For teams that specifically need the fastest possible turnaround above all else, a boutique firm like Johanson Group may still edge out Schellman on speed.
9. Coalfire

Coalfire is recognized as one of the top SOC 2 compliance vendors for collaboration tool startups, combining more than two decades of cybersecurity and compliance expertise with technology-enabled audit services. Through its licensed CPA affiliate, Coalfire Controls, the firm conducts hundreds of SOC assessments each year. It also has extensive experience working with cloud-focused organizations, including SaaS, IaaS, and PaaS providers, making it a strong option for collaboration tool startups operating in cloud environments.
Features
- SOC 1, SOC 2, SOC 3, SOC for Cybersecurity, and SOC for Supply Chain examination services
- Compliance Essentials, a coordinated-assessment platform supporting 50+ frameworks to reduce duplicate audit work
- Accreditation across PCI DSS, HITRUST, FedRAMP (with DoD IL4–IL6 experience), and ISO 27001
- Readiness assessments that identify control gaps and establish policies before the formal SOC 2 examination
Pricing
Custom pricing. Contact sales.
Pros
- Deep, documented experience specifically with cloud service providers, which describes the majority of collaboration tool startups
- Broad framework support means a single relationship can scale from SOC 2 alone into FedRAMP or PCI DSS if your customer base expands into regulated sectors
- Established, long-tenured firm with substantial audit volume and AICPA peer review standing
Cons
- Less startup-specific public positioning than Prescient Assurance or Johanson Group
- No published pricing floor for smaller engagements.
Best Fit
Coalfire is best suited to collaboration tool companies past their earliest startup phase typically Series B or later that are scaling into government, healthcare, or payments verticals and need a single firm capable of handling SOC 2 alongside FedRAMP, HITRUST, or PCI DSS.
Overall Verdict
Coalfire’s scale and framework breadth make it a strong long-term compliance partner once your company outgrows boutique specialists. For a very early-stage team seeking a fast, low-friction first SOC 2 Type 1, a smaller specialist firm will typically move faster and at a more approachable price point.
10. Johanson Group

Johanson Group, LLP is a licensed CPA firm based in Colorado Springs that has built its reputation specifically around speed and predictability for SOC 2 engagements. The firm commits publicly to delivering final audit reports within four to six weeks of the audit start date, a timeline that stands out among the firms in this list.
Features
- SOC 1, SOC 2, SOC 3, ISO 27001, HIPAA, PCI DSS, GDPR, CCPA, and NIST assessment services
- A stated three-step audit methodology: consultation and scoping, audit execution, and certification recommendation
- A dedicated auditor and customer success team member assigned to each client engagement
- Full integration with Drata’s evidence-collection workflow, described by the firm as eliminating manual spreadsheet-based evidence handling.
Pricing
Custom pricing. Contact sales.
Pros
- A committed 4–6 week report delivery window is unusually specific and startup-friendly compared to firms that only say “it depends”
- Deep, direct integration with Drata’s platform for streamlined evidence handoff
- Strong reputation among reviewers for consistent, repeat-engagement client relationships
Cons
- Best experience reported by clients already using Drata; teams on a different platform should confirm evidence-export compatibility first
- Less brand recognition among very large enterprise buyers compared to nationally ranked firms
Best Fit
Johanson Group is an excellent choice for collaboration tool startups on a tight enterprise-deal deadline that need a fast, no-frills Type 1 report from a licensed CPA firm, especially if the team is already using Drata for evidence collection.
Overall Verdict
Johanson Group’s committed turnaround time is a genuine advantage when a specific enterprise contract is waiting on your SOC 2 report. If your company anticipates needing FedRAMP, HITRUST, or CMMC in the next few years, a firm with those additional accreditations, like A-LIGN or Coalfire, will save you a future vendor switch.
11. Prescient Assurance

Prescient Assurance is one of the top SOC 2 compliance vendors for collaboration tool startups, combining licensed CPA audit services with deep cybersecurity expertise. Formerly known as Prescient Security, the firm was founded by cybersecurity practitioners, including CREST-certified penetration testers, rather than traditional accountants. As a result, Prescient Assurance takes a security-first approach, with a strong understanding of cloud architectures and modern application security instead of relying solely on compliance checklists.
Features
- SOC 1, SOC 2, SOC 3, SOC 2+ CSA STAR, HIPAA, and GDPR audit and attestation services
- Confirmed SOC 2 engagements starting at a stated entry price point, an unusually transparent disclosure for this market
- Deep, verified working relationships with Vanta, Drata, and Secureframe, including Slack-based, same-day audit communication
- CMMC C3PAO authorization, alongside FedRAMP 3PAO, PCI QSA, and HITRUST accreditations
Pricing
Prescient Assurance has publicly confirmed that SOC 2 engagements start at approximately $10,000, making it one of the few firms in this category to disclose a specific entry price point rather than requiring a sales call for a ballpark figure. Full scope-based pricing still requires contacting the firm directly.
Pros
- Genuine cybersecurity practitioner background, useful for collaboration tools with complex cloud-native architectures
- One of the only firms on this list to publicly confirm a specific starting price
- Strong, verified integration relationships with all three major compliance automation platforms
Cons
- Not the right choice for public companies or IPO candidates that specifically require Big Four brand recognition on the audit report
Best Fit
Prescient Assurance is a strong match for cloud-native collaboration tool startups, particularly Series A through growth-stage companies, that are already running Vanta, Drata, or Secureframe and want a technically fluent auditor who can move quickly without sacrificing thoroughness.
Overall Verdict
The combination of a confirmed starting price, deep platform integrations, and a genuine security-practitioner pedigree makes Prescient Assurance one of the strongest specialist choices for cloud-native startups. Companies that need a recognizable Big Four or Top 50 brand name specifically for investor or IPO optics should look to Schellman or A-LIGN instead.
12. BARR Advisory

BARR Advisory is a cybersecurity compliance firm that occupies a genuinely rare position in the market: together with its affiliated certification body, BARR Certifications, it is one of only a handful of firms in the United States accredited to both issue SOC 2 reports and certify organizations against ISO 27001. For collaboration tool startups selling into both U.S. and European markets, where SOC 2 and ISO 27001 are respectively the dominant local standards, this dual accreditation is a meaningful efficiency advantage.
Features
- SOC 1, SOC 2, SOC 3, ISO 27001 (including the 27001:2022 standard), HITRUST, PCI DSS, and CSA STAR services
- ANAB accreditation for ISO 27001 certification body status, held alongside AICPA accreditation for SOC 2
- A stated policy of on-time delivery, with a documented track record of finishing audits early
- Client services staff holding CISA, CISSP, ISO Lead Auditor, and HITRUST CCSFP certifications
Pricing
Custom pricing. Contact sales. BARR describes its rates as fixed and competitive, scaled for organizations from early-stage startups through larger enterprises, but does not publish specific figures.
Pros
- Genuinely rare dual accreditation for both SOC 2 and ISO 27001 under one coordinated audit team
- Strong, documented track record of on-time or early report delivery
- Deep experience specifically with cloud-based and remote-first organizations, a natural fit for collaboration tool companies
Cons
- Smaller firm footprint than A-LIGN, Schellman, or Coalfire, with less brand recognition among the largest enterprise buyers
- No published starting price point
Best Fit
BARR Advisory is the clear choice for collaboration tool startups that know they need both SOC 2 (for U.S. enterprise buyers) and ISO 27001 (for European or internationally expanding customers) and want to run both audits through one coordinated team instead of two separate vendor relationships.
Overall Verdict
For dual-framework programs, BARR’s rare accreditation combination genuinely reduces duplicated audit effort in a way most competitors can’t match. If your roadmap is SOC 2 only, with no near-term ISO 27001 requirement, a SOC 2-only specialist like Johanson Group or Prescient Assurance may be a simpler, equally capable choice.
Conclusion: How to Choose a SOC 2 Compliance Vendor for Collaboration Tool Startups
Choosing from the top SOC 2 compliance vendors for collaboration tool startups begins with understanding two separate decisions: selecting a compliance automation platform to streamline evidence collection and choosing a licensed CPA firm to perform the official SOC 2 audit. With the exception of Thoropass, which offers both under one contract, most providers specialize in one or the other.
Next, choose a vendor that matches your business needs and customer requirements. If you need a fast SOC 2 report to close an enterprise deal, prioritize firms known for quick turnaround times. If you’re in the early stages, a right-sized audit can help you avoid unnecessary costs. Also, consider whether your customers require additional certifications, such as ISO 27001 or HITRUST, as selecting a provider that supports multiple frameworks can save time and reduce the need for additional vendors.
Ultimately, there is no one-size-fits-all solution among the top SOC 2 compliance vendors for collaboration tool startups. The best choice depends on your startup’s stage, budget, timeline, and compliance goals. Before signing, request a fixed-fee proposal, confirm renewal pricing, and ensure the audit scope aligns with your customers’ actual requirements rather than unnecessary recommendations.