
Most internal requests for compliance spend arrive as a framework name and a price. The person approving it then has no way to work out what saying no costs, so the request goes into the pile marked "next quarter" and the deal it was attached to quietly slips.
The framework name is the least useful part of the case. Here is what to put around it.
Compliance spend gets approved when it is visibly attached to revenue. Name the customer or the tender. State the contract value and the term. Quote the clause or the question that created the requirement, in the buyer's own words, because "they want ISO 27001" and "the framework agreement requires certification to ISO/IEC 27001 by the service commencement date" are read very differently by a finance director.
If more than one deal is affected, list them. A single requirement usually turns out to be sitting across several opportunities, and the case changes shape when the total is on one line.
Approval stalls when nothing forces a decision. Give the date the buyer needs evidence by, then show the sequence that runs backwards from it.
For a certification, that sequence includes steps you do not control, including the certification body's availability and the audit stages that have to happen in order. Setting out how long each standard actually takes converts a vague request into a decision with a deadline, which is the difference between a discussion and an approval.
Where the requirement is a renewal, the date is already fixed and usually closer than people assume. A certificate with three months left on it needs a decision now, not at renewal.
Every finance approver runs the same comparison, so run it for them and do not stack the deck.
Hiring gives you dedicated capacity and full control. It also carries recruitment time before anyone starts, and for most SMEs the workload after the first certification does not fill a full-time role, which is an awkward conversation twelve months later.
Consultancy gets specialist attention on a fixed scope and usually the fastest first certification. When the engagement ends you own a set of documents, and whether you own a working system depends entirely on how the engagement was run.
Doing it internally on spreadsheets and shared drives costs nothing on the budget line and a great deal in engineering and operations time. The failure mode is not the first certification. It is the second framework, the surveillance audit and the customer questionnaire eighteen months later, when nobody can find the evidence or say whether it is current.
A platform gives you a system of record, and the internal time to run it does not disappear. Anyone presenting a platform as though it does the work for you is setting up a disappointing year two.
Present all four with their real costs. A case that acknowledges the weaknesses of the option you are recommending is considerably harder to argue with.
State the outcome plainly and without drama. The buyer awards to a competitor that holds the certificate. The renewal is deferred to the next cycle. The bid is marked non-compliant at the gate and never reaches evaluation. The NHS trust checks a published status and stops the order.
Then give the cost of delay in the same units as the request. Where a certification takes longer than three months, deferring the decision by three months settles the outcome of the deal that prompted it. That decision gets taken without anyone in the room saying it out loud.
What is the recurring cost after year one, and does it fall once the first certification is done? Give the real answer, including the audit fees that recur on their own cycle.
Who owns this internally, and how much of their time does it take? Name the person and be realistic. An approver who suspects the number is optimistic will discount everything else in the paper.
What can we show a customer next month? Something concrete before the certificate arrives matters more than most technical cases allow for. A defined scope, approved policies, a booked audit date and a plan with owners against it are all things a salesperson can send.
What happens to this if the deal it was bought for does not close? The honest answer is usually that the requirement outlives the deal, because the next buyer in that segment asks for the same thing. Say that, and show the second and third opportunities that make it true.
The person who signs is rarely in the discovery calls, and hears about the requirement second hand at the point a decision is needed. That is late.
A short conversation earlier, with the clause, the date and the two options you are weighing, does more than a polished paper delivered at the deadline. It also surfaces the constraint you did not know about, such as a spending freeze or an existing supplier agreement, while there is still time to work around it.
Give your champion something they can forward without editing. One page: the deal, the clause, the date, the options with costs, the recommendation, and what happens if nothing is decided this month.
Naq covers GDPR, Cyber Essentials, Cyber Essentials Plus, NHS DSPT, NHS DTAC, DCB 0129, ISO 27001 and ISO 9001 from one platform, with controls mapped to the requirements they satisfy across every framework at once. Evidence attached to a control counts everywhere that control applies, which is what makes the second and third framework cheaper than the first. For a finance approver, that is the difference between a recurring project cost and a system that absorbs the next requirement.
In-house Clinical Safety Officers and virtual Data Protection Officers are included, so specialist input is not a separate line item to justify. Naq is a Cyber Essentials Certifying Body via IASME, and for ISO 27001 and ISO 9001 the platform gets you audit-ready for the UKAS-accredited body that issues the certificate.
If you are building the internal case now, book a fifteen-minute demo and we will help you put numbers against the sequence.