Realising the benefits of an advanced SAM programme takes two things: effective technology, in the form of a tool, and effective process, in the form of services delivered by internal or external people.
Which services you need depends on your approach to SAM and how mature it already is. The objective does not change: value-for-money delivery of cost savings, compliance, licence optimisation, better control, less risk, higher productivity and decisions made on evidence.
So what should you look for when choosing a SAM services provider?
1. A comprehensive services portfolio
A partner who can only offer a narrow range of services will eventually constrain you.
You want one provider with a portfolio broad enough to cover what comes up — from a full managed service down to specific pieces of work: discovery and inventory, software recognition and normalisation, baselines and effective licence positions, licence optimisation, vendor audit response, SAM maturity assessment, advisory and due diligence, and education.
The reason this matters is not convenience. It is that a provider who only sells one thing will recommend that thing.
2. A managed service that fits
Requirements vary with the size, nature and capability of the organisation.
At one end, you may be starting out and need a guiding hand through the process. At the other, you may already have mature processes and internal capability and simply need better tooling. A single fixed offering will not serve both, so look for a provider with a range of offerings that scale and can be tailored to your circumstances.
What a well-matched managed service does is compress time. NHS South West London ICB describe the effect directly:
Certero’s SAM managed service allowed us to significantly mature our license posture at a fast pace, something that would have taken 3-4 years without their involvement.
— Reece Emson, ITAM Asset/PSL Manager, NHS South West London ICB
3. Automated technology, not manual process
In our experience many SAM service providers lean heavily on manual process, older tooling, or both.
That approach is slower, more open to error, and needs a lot of skilled consultancy time — the cost of which is passed to you, usually with margin on top. It also leaves you dependent, because the knowledge lives in the consultant rather than in the system.
Services delivered on current, highly automated technology give you better value and leave you in a stronger position if you later want to run SAM yourself. It is worth being concrete about what “automated” should mean now:
- Discovery that does not need chasing. Ten discovery methods — agent, command-line, agentless, standalone, Active Directory, network scan, third-party import, cloud connector, browser monitoring and file metering — all landing in one schema, across six operating system families on one agent.
- A licence position that is continuous. Purchased, used, available, required, variance and exposure, computed on an ongoing basis rather than reconstructed for a quarterly report.
- Recognition that is maintained for you. A Software Recognition Database of over 3.5 million titles, with publisher normalisation, version recognition and end-of-support dates, kept current centrally.
- Coverage of the things people now buy without IT. 47 SaaS connectors pulling authoritative user and licence lists from the vendor, and 26 named cloud optimization checks, each with its own thresholds and exclusions.
If a provider’s answer to any of these is a consultant with a spreadsheet, you are paying for labour rather than for outcome.
4. Flexible deployment
Any technology involved in delivering SAM services has to be quick to implement and flexible enough to align with your existing infrastructure strategy.
Look for real deployment choice — on-premises, cloud or hybrid — so the tooling fits what you already run instead of forcing an infrastructure decision you did not intend to make. Alignment minimises disruption and protects the investment you have already made.
5. Genuine multi-tenancy
If you are implementing a SAM managed service, check that the provider offers true multi-tenancy, and that it gives you a consistent, complete experience.
We have seen cases where multi-tenancy meant reduced functionality for the customer — restricted access to inventory data, for instance. Multi-tenancy is an architectural convenience for the provider. It should not cost you visibility of your own data.
6. Process and people that stand up to scrutiny
Services are people and process. You need confidence in both.
Ask whether the provider applies recognised best practice and holds the certifications that matter for handling your data. Ask about the people: the right skills, real experience, and a consultative approach that understands your problem before proposing anything.
For reference, Certero holds ISO 27001:2022 for information security management, Cyber Essentials Plus — the highest level of the UK NCSC scheme — and a SOC 2 Type 1 attestation. CerteroX Cloud Management is a FinOps Certified Platform, and Certero is a FinOps Certified Service Provider with the FinOps Foundation. Ask any prospective provider for the equivalent list, and ask when each was last renewed.
7. Evidence of quality and customer satisfaction
A provider’s customer satisfaction and quality record is the best available indicator of the service you will get.
Check whether they run a regular customer satisfaction survey. Ask for references you can actually speak to, in your sector and at your scale. Look for independent, verifiable recognition rather than self-assessment.
Certero was named the sole Customers’ Choice in the 2024 Gartner® Peer Insights™ Voice of the Customer for Software Asset Management Tools — the only vendor in the category to reach that position, and the fourth Customers’ Choice recognition Certero has held.
8. Independence
Many SAM services providers also resell software licences. That is a potential conflict of interest on precisely the questions you are hiring them to answer.
As your SAM partner their objective is to reduce your software spend. As a reseller their objective is to sell more software. Similarly, some providers are engaged by publishers to run audit or baselining work on the publisher’s behalf. There are ways to manage this — separation of duties, confidentiality agreements — but the cleanest answer is a partner with no reseller or publisher allegiance to manage in the first place.
Certero has been privately owned and independent since it was founded in 2007. Whoever you are considering, ask the question directly and ask it in writing.
9. Global coverage and local support
It is increasingly normal to operate across several countries and many locations.
Where that applies, a provider with regional presence and staff who can support local requirements is a real advantage — faster response, and technical or service issues resolved in your working day rather than someone else’s.
Certero operates from Warrington in the UK, Chicago in North America and North Sydney in APAC.
10. Help becoming self-sufficient
If your objective is to reduce reliance on third-party support, you need a partner willing to transfer knowledge and bring your team up to speed as quickly as possible — not one whose commercial model depends on you never learning.
As in point 3, this only works alongside genuinely automated tooling. Ideally it is the same tooling the provider is already using, so what you inherit is a working system and the knowledge to run it, rather than a set of outputs you now have to reproduce by hand.
That last point is the one to weigh most heavily. A good services provider makes itself progressively less necessary. Ask any prospective partner how they would expect the engagement to change over three years. If the answer does not involve you doing more of it, you have learned something useful.
GARTNER is a registered trademark and service mark, and PEER INSIGHTS is a trademark and service mark, of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates.