The Cost of Keeping It
You built your own platform. The question now isn’t whether that was the right call — it’s whether continuing to build is.
Companion to “What Curriculum Publishers Actually Need to Own”
Somewhere between three and ten years ago, your organization made a decision. The platforms available at the time didn’t do what your curriculum required, or the ones that did came with tradeoffs you weren’t willing to accept, or the math simply worked out in favor of building. So you built. And it worked — it’s in districts, it’s generating revenue, teachers use it.
That decision deserves more credit than it usually gets in conversations like this one. Most publishers who built their own platform built it because it was the correct answer to the question in front of them at the time.
This piece is about a different question: not whether building was right, but whether continuing to build still is. That question rarely arrives on a schedule you set. It surfaces during a rebuild — when a district asks for something the platform can’t do, when the developer who understands the rostering integration gives notice, when a compliance requirement gates your team from landing a major district sale.
“We’ve already invested too much to walk away from it.”
This is usually the first thing raised, and it often decides the outcome before any analysis happens.
The investment is real. It’s also spent. Whatever your organization has put into the platform is gone in every scenario — including the one where you keep it. That money doesn’t come back by continuing to spend more of it.
This pattern is well documented in software specifically. Mark Keil’s research on IT project escalation, published in MIS Quarterly and IEEE Transactions on Engineering Management and replicated repeatedly since, found that willingness to continue a software project rose with the amount already invested — and that sunk cost was the reason decision-makers most often gave for continuing.
One finding from that work is genuinely useful here: the effect weakens substantially when there’s a concrete alternative on the table. Escalation thrives on a comparison against nothing. So the practical move is to make the forward comparison specific — what do the next three years cost, under each option. That’s the only figure still open to influence.
There’s a second version of this concern that’s more legitimate: we’d be starting over. That depends almost entirely on whether your content moves as structured content or gets rebuilt by hand, and it’s addressed below.
The audit worth running
You have an advantage over a publisher who hasn’t built anything: you don’t have to model total cost of ownership (TCO) hypothetically. You have the actual numbers.
Pull the last twelve months of engineering work and sort it into two buckets. One: rostering maintenance, SSO issues, LTI upgrades, accessibility patches, browser compatibility, standards updates, security review, privacy law changes, district integration troubleshooting, back-to-school escalations. Two: capability that makes your curriculum work better than it did before.
Then ask what the ratio is, and whether it’s moving in the direction you want.
For context on what that ratio tends to look like: Chainguard’s 2026 Engineering Reality Report, a survey of 1,200 engineers and senior technology leaders, found engineers spend roughly 16% of their week building new features, while 79% named code maintenance as a major drain on their time. Two-thirds of technology leaders in the same survey reported worrying about retaining engineers — and tied that concern directly to how much of the work is upkeep. In a small platform team, that isn’t only a capacity problem. It’s how key-person risk gets created.
A few questions surface the same information from another angle:
Who could maintain the rostering integration if the person who wrote it left?
When a district asks for a feature, what’s the honest timeline — and how much of it is the work versus the queue ahead of it?
What’s been on the roadmap for more than a year?
Who signs off that the platform is currently WCAG 2.1 AA compliant, and when was that verified rather than assumed?
None of this is an argument on its own. It’s just data. But it’s your data, which makes it harder to argue with than anyone’s TCO model.
The dependency you were avoiding, and the one you have
The case for building is a case about control: no one else’s roadmap, no one else’s pricing, no one else’s decisions about what matters. It’s worth examining what that control looks like several years in.
A platform your team built is dependent on the architectural decisions that team made at the time — reasonable then, load-bearing now — and on the specific people who understand how it fits together. Engineering has a name for this: the bus factor, the number of people who’d have to become unavailable before the system can no longer be safely changed. For most in-house platforms, honestly assessed, that number is one or two on at least one critical component.
It also remains dependent on everything you still don’t control: cloud providers, browsers, identity systems, LMS APIs, and the standards bodies that set the schedule. When 1EdTech ended support and certification for legacy LTI versions in 2022, every tool provider in the market migrated on a timeline none of them set. That kind of externally imposed work recurs, and whoever owns the integration layer absorbs it every time. When Clever retired Clever 2.0 and moved to Clever 3.0, they provided ample notice, but the upgrade work still had to be done.
Meanwhile the cost of replacing your platform grows each year it’s embedded further into how the organization works.
None of which is a criticism of the build. It’s the observation that “we won’t be locked in” didn’t turn out to mean no lock-in. It meant a different kind, with constraints that are harder to see from inside because they look like normal operating conditions.
The compliance surface keeps moving, and the liability is real
This is where the numbers have changed most since most in-house platforms were designed.
Accessibility now has a federal deadline. The Department of Justice’s April 2024 final rule under Title II of the ADA requires state and local public entities — public K-12 districts included — to bring web content and mobile apps into compliance with WCAG 2.1 Level AA. In April 2026, days before the first deadline, DOJ extended the dates by a year: April 2027 for jurisdictions of 50,000 or more, April 2028 for smaller ones. Two details matter for publishers. The rule’s scope covers content a district makes available through vendors and licensors, which is how these obligations arrive in your contracts even though the rule doesn’t name you; Venable’s analysis notes vendors may be contractually required to meet the standard and carry real risk if they don’t. And as Duane Morris pointed out, the extension delays the WCAG dates only — Title II’s underlying obligations still apply, and private plaintiffs can still sue in the interim.
Student privacy has real settlements attached. Nearly 400 student privacy bills have been introduced across 49 states since 2014, and more than 20 states have vendor-focused laws modeled on California’s SOPIPA. Enforcement has caught up: three state attorneys general reached a $5.1 million settlement with Illuminate Education in November 2025 over a student data breach, and in February 2026 PowerSchool and Chicago Public Schools agreed to a $17.25 million settlement — a class of more than 10 million — over claims that third-party analytics code in Naviance captured student communications without consent. Both denied liability. The proposed terms also require PowerSchool to establish a web governance committee and keep third-party tracking code out of the platform for two years.
The point isn’t that a vendor got sued. It’s where the obligation landed: on whoever shipped the code. CPS separately agreed to require annual privacy compliance certifications from its vendors — a term that will spread through district contracts, and one a publisher running its own platform signs for itself.
Districts screen on this before they evaluate your curriculum. Compliance documentation has stopped working as a differentiator and started working as a gate. Every requirement is satisfied by someone. The question is whether it’s a team whose full-time job is that layer, or yours, alongside everything else.
“Our districts are mid-year. We can’t move.”
This is usually the real blocker, and it’s rarely stated first. It also has little to do with build-versus-buy philosophy. It’s an operational concern and it deserves an operational answer.
Three things determine whether a transition is survivable:
Whether your content moves as structured content or gets rebuilt. This is the largest variable by a wide margin. Content that migrates as a database-to-database transformation — lessons, items, and assessments landing as modular components your editorial team then refines — is a fundamentally different project from content re-entered by hand. The first is a defined technical exercise. The second is what everyone pictures when they say “starting over,” and it’s why a lot of these conversations end early.
Whether rostering and access continuity hold. Districts don’t experience a platform transition as an architecture change. They experience it as whether logins work in August. Rostering, SSO, and LMS connections have to be live before anything else matters, and tested against real district configurations rather than in principle.
Whether the timeline is built around the school calendar. Nothing meaningful moves in October. Transitions get sequenced against adoption cycles, renewal dates, and the back-to-school window, which usually puts the planning conversation and the go-live in different calendar years. That’s not a delay. That’s what a competent sequence looks like.
A phased path also means the answer to “can we move mid-year” is generally that you don’t have to. Pieces move when the calendar allows, and the parts that aren’t moving keep running.
It isn’t all or nothing
The framing that stalls this conversation most often is the assumption that the choice is keep everything or replace everything.
There’s a configuration in between, and for publishers who’ve built a front end their districts know and like, it’s frequently the more sensible starting point: keep the student- and teacher-facing experience you built, and move the layer behind it.
In that arrangement, C2C’s Publisher Suite operates as the content and infrastructure backend. Your editorial team authors and structures content in it. Your existing interface stays as it is, connected through an API layer. What shifts is the content pipeline feeding your product, plus the compliance and integration maintenance underneath it — rostering, SSO, LTI, accessibility, standards alignment, state privacy requirements. The work that looks identical at every publisher regardless of curriculum.
Your front end, your architecture decisions, and your existing systems remain yours. Adopting a CMS is not the same as adopting a delivery platform, and it doesn’t commit you to evaluating one. If C2C’s Classroom Experience becomes interesting later, that’s a separate decision on its own timeline.
The list, inverted
The companion piece to this article lays out what publishers should ask a platform vendor to guarantee: content ownership language, data portability, clear exit terms, current compliance documentation, data minimization, pricing transparency, customization access.
If you built your own platform, you didn’t avoid that list. You became responsible for it.
So the useful exercise is to run it against yourself:
Compliance documentation — could you produce current SOC 2, FERPA, COPPA, and WCAG 2.1 AA documentation this week if a district’s procurement office asked?
Accessibility — verified against WCAG 2.1 AA in the last twelve months, or verified once and assumed since? Do you have a plan that lands before the April 2027 Title II date your districts are working toward?
Data minimization — do you know exactly what student data your platform collects, including anything a third-party script pulls, and can you defend every field?
Privacy certification — if a district asked you to certify annual compliance with state and federal privacy law, who signs it?
Cost predictability — is platform cost forecastable next year, or is it whatever that year’s compliance and maintenance load turns out to be?
Continuity — if the two people who understand the architecture left in the same quarter, what would that cost, and how long would it take?
Roadmap capacity — what percentage of engineering capacity is available for curriculum capability after maintenance is covered?
Every item on that list is guaranteed by someone.
Building was a reasonable decision. Continuing to build is a separate decision, and it should get its own analysis rather than inheriting the first one’s conclusion by default.
Own your content. Own your results. Own your relationships. The infrastructure underneath is a choice you’re allowed to revisit.
Sources
Chainguard, 2026 Engineering Reality Report — survey of 1,200 software engineers and senior technology leaders across the US, UK, Germany, and France (fielded August 2025).
Mark Keil, “Pulling the Plug: Software Project Management and the Problem of Project Escalation,” MIS Quarterly, Vol. 19 (1995).
Mark Keil, Duane P. Truex & Richard Mixon, “The Effects of Sunk Cost and Project Completion on Information Technology Project Escalation,” IEEE Transactions on Engineering Management, Vol. 42, No. 4 (1995).
U.S. Department of Justice, Final Rule, Nondiscrimination on the Basis of Disability; Accessibility of Web Information and Services of State and Local Government Entities (April 24, 2024).
U.S. Department of Justice, Interim Final Rule, Extension of Compliance Dates, 91 Fed. Reg. 20902 (April 20, 2026).
Venable LLP, ADA Title II Website Accessibility Regulations: Will Your Organization Meet the Compliance Deadline? (April 2026).
Duane Morris LLP, DOJ Extends ADA Title II Digital Accessibility Deadlines by One Year (April 2026).
Public Interest Privacy Center, State Student Privacy Laws.
The Record (Recorded Future News), PowerSchool, Chicago Public Schools to Settle Student Data Privacy Lawsuit for $17 Million (February 2026).
Government Technology, PowerSchool, Chicago Schools Agree to Pay $17.25M Settlement (February 2026).
Wilson Sonsini Goodrich & Rosati, EdTech Provider Agrees to $5.1 Million Settlement with Three State Attorneys General over Student Data Breach (November 2025).
1EdTech, Security Update and Deprecation Schedule for Early Versions of LTI.
The SOC 2, EdTech Compliance 2026: FERPA, COPPA, and SOC 2 Requirements Explained (April 2026).