As a business, you give up control for critical infrastructure to be managed by dedicated engineers who are experts in those areas, who can let you reuse their already-audited and compliance-certified infrastructure so that you don't have to do that yourself.
I agree it's not hard. It's also not hard to accidentally store your logs unencrypted, ruining your FIPS or HIPAA compliance and putting your company in legal risk.