Name a category the market feels but cannot buy, enter through the lowest-friction customer, and let expansion plus always-on data make the product impossible to remove.
Vanta
Vanta is a compliance automation platform that connects to a company's cloud, code, HR, and device systems to continuously monitor security controls, most famously getting a startup "SOC 2 ready" in weeks instead of months. Founded in 2018 by Christina Cacioppo out of Y Combinator, it took a chore buyers dreaded and nobody had productized, then rode a cheap, fast wedge from startup SOC 2 into a multi-framework system of record. The through-line: name a category the market feels but cannot buy, enter through the lowest-friction customer, and let expansion and always-on data make the product impossible to rip out.
Category Creation: turning "hire an auditor" into "buy a Vanta"
The problem. Before Vanta, "automated compliance" was not a budget line. Buyers thought in terms of auditors, consultants, and spreadsheets, and the closest existing software category, GRC (governance, risk, and compliance), was essentially spreadsheets in a browser that mapped controls but did not actually check anything. There was no default product a startup could point to when an enterprise demanded a SOC 2 report.
The approach. Cacioppo and her co-founder embedded at Segment's office for weeks reading SOC 2 reports, and their first artifact was a color-coded (red/yellow/green) spreadsheet of everything Segment needed to do. From that they built continuous, always-on monitoring rather than point-in-time audit prep, and positioned the entire manual status quo of consultants and screenshots as the thing they replace. In the early days, before competitors existed, Vanta deliberately tried to make "SOC 2" and "Vanta" synonymous in buyers' minds.
How it solved it. The reframing worked so thoroughly that the market Vanta named is now a crowded, well-funded field, the strongest evidence a category was created. By April 2026 Vanta reached an estimated $300M ARR, up 69% year over year, serving 16,000+ customers including Snowflake, Atlassian, Duolingo, Ramp, and Cursor, with the buyer's mental model shifted from "hire a consultant" to "buy a Vanta."
GTM: a self-serve SOC 2 wedge sold bottom-up into engineers
The problem. The buyer of compliance at a startup is a busy engineering or founding team with no security staff, no budget for a six-figure consulting engagement, and an enterprise deal blocked on a report they cannot produce. A traditional top-down enterprise sales motion would have been too slow and too expensive for a $10K-range initial contract.
The approach. Vanta led with a low-friction, fast-time-to-value SOC 2 product that engineers could adopt bottom-up, then layered multi-product cross-sell on top of the installed base. It went where the buyers already were: Y Combinator, becoming the de facto compliance solution for roughly three-quarters of YC companies.
How it solved it. The efficient wedge compounded: Vanta grew from about $10M ARR in 2021 to $100M ARR by January 2024, and by July 2025 raised a $150M Series D at a $4.15B valuation led by Wellington, notably raising despite not needing the cash. Implied ARR per customer climbed from roughly $17K in mid-2025 toward $19K by April 2026, showing growth from both new logos and expansion, not discounting.
Land and Expand: one SOC 2 account becomes a shelf of frameworks
The problem. SOC 2 alone is a modest, one-report sale. To build a large, durable business, Vanta needed each customer to be worth far more over time than the price of its first certification, without acquiring a new customer for every dollar of growth.
The approach. Vanta landed with cheap, fast SOC 2, then expanded the same accounts horizontally into ISO 27001, HIPAA, GDPR, PCI, FedRAMP, ISO 42001, vendor and third-party risk, security questionnaire automation, a customer-facing Trust Center, and AI risk management. The same continuous-monitoring engine that produced one framework's evidence could produce the next at low marginal cost to the customer.
How it solved it. The expansion motion is visible in the numbers: rising ARR per customer (roughly $17K to $19K over 2025 into 2026) alongside a customer base that grew from 7,000 in FY24 to 16,000+ by April 2026, meaning much of the 69% year-over-year ARR growth came from selling more into existing accounts rather than logos alone.
Beachhead: small startups needing SOC 2 as the entry point
The problem. Attacking the whole compliance market head-on, including large enterprises with entrenched consultants and complex requirements, would have been slow and unwinnable for a young company. Vanta needed a narrow segment where the pain was acute, the sales cycle short, and the incumbent solution weak.
The approach. It chose small B2B startups that needed SOC 2 to close their first enterprise deals: a segment with universal, revenue-blocking pain, no in-house security team, and no attachment to the consultant status quo. This was the low-friction, fast-time-to-value entry point before any horizontal expansion.
How it solved it. Owning the startup beachhead, anchored by near-total penetration of Y Combinator companies, gave Vanta a dense, referenceable base from which to expand across frameworks and upmarket into larger customers. From that foothold it grew into a platform now used by public and scale-up companies while retaining the startup segment that seeded it.
Switching Costs: the pain returns the moment you leave
The problem. Compliance software could in principle be a low-stakes, swappable purchase. If a customer could trivially move to a competitor, Vanta's expanding category would compress into a price war and its land-and-expand economics would erode.
The approach. By making compliance live software rather than a one-time audit, Vanta embedded itself in the customer's operations: continuous monitoring wired into cloud, code, HR, and device systems, an accumulating history of evidence, and a public Trust Center that customers use to prove security to their own buyers. Each additional framework and module sold into the account deepens that integration.
How it solved it. Once continuous monitoring, evidence history, and the Trust Center all live in Vanta, ripping it out re-introduces the exact manual, screenshot-gathering pain the customer bought Vanta to eliminate. That stickiness underpins the expanding ARR-per-customer trend and helped Vanta sustain 69% year-over-year growth to an estimated $300M ARR by April 2026.