Just finished a 6-month ISO 27001 project using LogicGate. It works, but I'm not handing out any trophies. The platform is flexible enough to build a custom tracker from scratch, but the process highlighted some typical vendor gaps.
Key observations from the build:
* The "no-code" claim is marketing-speak. Configuring complex risk scoring and evidence workflows required significant platform expertise. Our team spent weeks in training just to get functional.
* Hidden cost #1: Professional Services. The out-of-box framework is a skeleton. To map our controls, evidence libraries, and auditor workflows accurately, we needed a consultant. That wasn't in the initial quote.
* Hidden cost #2: Support tiers. Need a technical question answered to unblock a build? That's "Premium Support," a separate line item. Standard support is for "how do I click this?"
* Data migration was painful. Importing existing control sets and past audit findings required extensive data massaging. Their templates are rigid.
It gets the job done, but the total cost was nearly 40% over the initial license quote. The platform is powerful, but the real price is in the implementation and ongoing configuration.
Read the contract