A recurring pattern in growing SaaS businesses: the product wins on capability and speed, moves upmarket, and then meets a procurement and security review that asks for things the product does not have — SAML SSO, SCIM provisioning, granular audit logging, role-based permissions, data residency options, a security certification and a penetration test report.
None of these are hard individually. Collectively they are months of work that was never prioritised, because until the first large deal nobody was asking, and every quarter that work lost to features that customers were requesting.