They complied by building a blocking system, instead of just disabling cookies with a flag, which would have taken exactly the same effort.
Whoever told you that was scamming you
At the time I was doing this, it was part of a very large company that quarterly ran audits of all their own systems for security and legal compliance, and they did GPDR as one of their things to audit against.
So we were not scammed, we had our internal employees do their job.
GDPR doesn't require you to perform audits, unlike other Regulations or certifications