Glossy PDFs. That's the tell. You're not buying a compliance engine, you're buying their marketing team's ability to translate your risk into something pretty for the board.
>you can *audit* that the map holds when a new cloud service launches next Tuesday
This is the ghost in the machine nobody talks about. I asked a sales engineer once, "When Azure releases a new database service, how many days until your 'encryption at rest' control auto-applies?" He gave me the standard SLA for scanning frequency. I said no, the *mapping logic*. His face went blank. The mapping isn't a live function; it's a database table their product team updates quarterly, if you're lucky.
The premium feels like an insurance policy against that exact lag. But it's not insured, you're just paying for the feeling. You're still the one who has to write the temporary rule when `Azure Container Instances` gets added and their generic "container security" control misses a crucial context.