An ITAM or SAM platform is how you see, understand and manage technology assets and the growing cost of enterprise software. But how do you know whether you can trust what the vendor tells you, or what the product tells you once you own it? How do you make sure the tool is not itself a security exposure? And where is the line between what technology can do and what still needs human expertise?
Here are four steps worth taking before you commit.
1. Check the vendor’s security credentials
The best SAM platform in the world becomes a serious problem if it opens a vulnerability into your business. Nobody wants that conversation with their CISO, and it is genuinely difficult to see past a vendor’s presentation layer to how they actually operate.
Fortunately there are credentials that do the work for you, because they represent submission to external audit rather than self-description. Look for:
- ISO 27001 — information security management system
- Cyber Essentials Plus — the UK NCSC scheme, at its highest level. You can search the certified vendor register directly rather than take a claim on trust.
- SOC 2 Type 1 — an attestation covering the design of controls at a point in time
The distinction that matters is between certifications a vendor holds and controls a vendor describes. Ask for the certificate and the scope statement. Scope is where these often disappoint — a certification that covers the corporate office but not the hosting environment your data sits in is not the assurance you thought you were buying.
It is also worth remembering that assessing the cloud provider underneath a SaaS product is not sufficient. The vendor handling your data has to be vetted in their own right.
2. Understand what publisher accreditation actually exists
Most software publishers do not formally endorse or recognise any SAM product, despite persistent myths to the contrary — usually propagated by incentivised resellers and salespeople claiming a given tool is automatically accepted or approved. If you are told a publisher approves a tool, ask to see it in writing from the publisher.
The notable exception is Oracle, which provides formal verification through License Management Services. Having been through it, we can tell you it is a stringent process and not easy to pass.
What the verification means in practice is worth stating precisely, because it is routinely overstated:
Being a verified 3rd party toolset means that Oracle’s audit team can accept data from Certero for Oracle during an official audit, as an alternative to installing Oracle License Management measurement tools.
Note the shape of that. Oracle’s audit team can accept the data, during an official audit. It is a conditional permission, not a blanket guarantee, and any vendor presenting it as the latter is telling you something the verification does not say.
The genuine customer benefit is broader visibility into Oracle deployment, sustained continuously rather than captured as a single snapshot when someone runs a script.
Make no mistake, though: in any publisher audit you still need the data behind your compliance position to be accurate, and you will still need to provide evidence. A verified toolset does not remove that obligation.
There is a related case that works differently and is worth understanding. IBM sub-capacity licensing terms mandate the use of ILMT. Those conditions remain in force, and no third-party product changes them. But other measurement alongside ILMT can add insight ILMT does not provide on its own — CerteroX SAM includes an ILMT connector with compliance gap analysis, PVU and Virtual Processor Core metrics, and Component Resolution that matches deployed components to products with a scored, bulk-appliable suggestion. It also enforces the 30-minute inventory cycle that sub-capacity licensing actually requires.
That is not a formal endorsement from IBM, and it should not be presented as one. It is additional evidence, and evidence is what these conversations turn on. A consultant working from ILMT data alone simply has less to work with. Understanding these nuances is most of what separates a well-run tool selection from a badly run one.
3. Seek out independent customer evidence
This is the obvious step, and most buyers take some version of it. The difficulty is that the readily available material is filtered.
Published case studies tell you the half of the story the vendor wants told. That is not dishonesty, it is what a case study is for — but do not mistake it for a representative sample. Shortcomings are rarely publicised by any vendor, though they will certainly be aware of them, which is why specifying the metrics and capabilities you need in your RFP matters so much. It forces the answer into writing.
The filtering runs in the other direction too. Many of the largest wins a vendor achieves cannot be publicised, because of NDAs and because of basic commercial sense. An organisation that has just extracted itself from a very large compliance exposure is not usually keen to draw attention to how it got there.
So look for evidence that neither party controls: verified, anonymised, in-depth reviews from real customers, where you can compare products directly and read the critical reviews as well as the positive ones. Sort by quality rather than volume, and pay particular attention to reviewers whose environment resembles yours.
Certero was named the sole Customers’ Choice in the 2024 Gartner® Peer Insights™ Voice of the Customer for Software Asset Management Tools — the only vendor in the category to reach that position.
When you read reviews, be conscious of the web of commercial relationships and incentives around any source of “impartial” advice. There is no better indicator than the user community, provided the community is genuinely un-incentivised.
4. You need knowledge to verify what the product tells you
No ITAM or SAM platform is a silver bullet. However accurate the inventory and however much intelligence is applied to the data, you still need the knowledge to verify and use the outputs.
What a good platform does is remove an enormous amount of laborious manual processing and complexity — provided you understand what it is doing. The additional insight then translates into cost savings, operational efficiency and better-evidenced decisions.
This is exactly where buyers get caught in a crossfire. On one side, salespeople over-promising what technology can do unassisted. On the other, experienced SAM consultants with a deep mistrust of all toolsets, some of whom get misty-eyed at the sight of a large spreadsheet.
In fairness to the consultants, they are the ones who pick up the pieces when a tool has been mis-sold and an unrealistic expectation set with the business. Internal or external, their expertise is critical to whether a SAM programme succeeds.
So how do you make sure you will actually understand, use and trust what you buy?
Test it thoroughly
Verify the accuracy of the outputs, not just that the interface loads. Concretely:
- Can it identify processor types and core factors correctly?
- Can it distinguish versions and editions of SQL Server? This one catches a lot of products, and getting it wrong leaves you over-licensed on Standard and under-licensed on Enterprise simultaneously.
- Is software recognition correct across your actual application portfolio, including the long tail?
- Can you import licence entitlement data cleanly — a Microsoft Licence Statement, volume licence transactions, agreements and maintenance?
- Does usage metering show you first-used and last-used per title, so you can defend a reharvesting decision?
Ask every one of these as a question, and watch where each answer comes from rather than accepting that it appeared.
Use it to deliver a business outcome
Some problems only surface when a product is used in anger. If your goal is to produce an Effective Licence Position ahead of a renewal negotiation, do that during the evaluation rather than after it — and consider bringing in external help to achieve it as a service.
That approach embeds the platform in your environment and proves business value before the larger procurement decision, rather than after. Given how quickly a SaaS-provisioned platform can be stood up now, this is no longer the months-long implementation project it once was.
Understand the limits of your own resources
You want value, and the scope of what has to be managed keeps expanding. Devices, on-premises software, SaaS subscriptions, cloud consumption and now AI — models, GPU capacity and AI seats. Your approach has to be as dynamic as the demand.
Unifying these under one platform changes how a lot of processes work, because people can get the information they need, when they need it, from one source rather than reconciling three. That is the practical argument for a single data model over a set of separately acquired tools.
It is equally important to recognise where skills and time are stretched thin. Cloud cost management is the obvious example, and AI spend is rapidly becoming the next one — it arrives split across four budgets, with four different owners, and usually nobody with a view of all of them. Where the internal capability is not there, the sensible move is to extend the cloud-first idea of switching on resources as needed to switching on expertise as needed.
The underlying point
Selecting a platform is entering a strategic partnership with a vendor, not buying a licence. Due diligence and non-subjective evidence of capability should be a core part of the process, not a formality at the end of it.
What consistently makes the difference is not only what a product can do, but how the vendor behaves when something is difficult — whether they are focused on delivering value from your investment or on doing things their own way regardless.
If you are looking at ITAM and SAM platforms, bring the four tests above and run them at us. Book a demo and put each one to a technical person with the product open.
GARTNER is a registered trademark and service mark, and PEER INSIGHTS is a trademark and service mark, of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates.