Best Software for 2025 is now live!
Save to My Lists
Paid
Claimed

Drata Reviews & Product Details

Verified User in Retail
AR
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about Drata?

I really have enjoyed that all the evidence is aggregated in one spot and presented in a way that auditors have understood it. The integrations are also useful, data that syncs up with any changes is especially useful in a fast paced business environment. Review collected by and hosted on G2.com.

What do you dislike about Drata?

The real downside of using drata was the fact that Auditors were reluctant to use it. All the evidence was there in the platform and visible for them to use, but they still wanted us to walk them through all of our controls over video chats. This defeated the purpose of Drata and did not save us time. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

The tedious process of data and evidence collection. Review collected by and hosted on G2.com.

Response from Ashley Hyman of Drata

Hi there!

Thank you for your review. It would be great to connect and discuss your audit experience directly. We have an auditor alliances team that works with customer's audit firms to ensure comfort with Drata and the evidence coming from the system. Please email me at ashley@drata.com so we can discuss your experience and ensure a better path forward.

Thanks so much!

Ashley Hyman

VP of Customer Success

Drata Overview

What is Drata?

Drata is a security and compliance automation platform that continuously monitors and collects evidence of a company's security controls, while streamlining compliance workflows end-to-end to ensure audit readiness. Drata helps thousands of companies streamline their compliance efforts through continuous, automated control monitoring and evidence collection, resulting in lower costs and time spent preparing for annual audits and better overall security posture. Drata's supported frameworks include: SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, CCPA, CCM, CMMC, ISO 27701, ISO 27017, ISO 27018, Cyber Essentials, Microsoft SSPA, NIST 800-53, NIST CSF, NIST AI, FFIEC, NIST 800-171, and Custom Frameworks. Drata is backed by ICONIQ Growth, GGV Capital, SVCI (Silicon Valley CISO Investments), Okta Ventures, Salesforce Ventures, Cowboy Ventures, Leaders Fund, SV Angel, and many key industry leaders.

Drata Details
Product Website
Discussions
Drata Community
Languages Supported
German, French, Spanish
Show LessShow More
Product Description

Drata is the world's most advanced security and compliance automation platform with the mission to help businesses earn and keep the trust of their users, customers, partners, and prospects. With Drata, thousands of companies streamline risk management and over 12 compliance frameworks—such as SOC 2, ISO 27001, GDPR, CCPA, PCI DSS and more—through automation, resulting in a strong security posture, lower costs, and less time spent preparing for audits.

How do you position yourself against your competitors?

Drata is a leading compliance and risk automation platform that continuously monitors and collects evidence of a company's security posture, while streamlining workflows.

Drata provides customers with real-time 24 hour in-app support and expertise from a team of compliance and technical support, to solution architects, and compliance experts.

We ensure ease and quality by partnering with GRC experts to build our product and feature enhancements from the ground up. The results? With Drata, you are collecting the right evidence the first time, no matter which framework you are pursuing. We save you time and money by doing it the first time.

Whether you are brand new and looking to achieve SOC 2 compliance or more advanced with your regulatory and risk needs, Drata is built to scale with you. We meet you where you are with your goals and support you through your entire journey.


Seller Details
Seller
Drata
Company Website
Year Founded
2020
HQ Location
San Diego, US
Twitter
@DrataHQ
1,232 Twitter followers
LinkedIn® Page
www.linkedin.com
639 employees on LinkedIn®
Description

Replace manual GRC efforts, reduce costs, and save time preparing for audits and maintaining compliance. Drata is the world’s most advanced security and compliance automation platform with the mission to help companies earn and keep the trust of their users, customers, partners, and prospects. We help thousands of companies streamline compliance for SOC
, ISO
7001, HIPAA, GDPR, your own custom frameworks, and many more through continuous, automated control monitoring and evidence collection. Drata is backed by ICONIQ Growth, Alkeon, Salesforce Ventures, GGV Capital, Okta Ventures, SVCI (Silicon Valley CISO Investments), Cowboy Ventures, Leaders Fund, Basis Set Ventures, SV Angel, and many key industry leaders. Drata is based in San Diego, CA with team members across the globe.


Adam M.
AM
Overview Provided by:
Co-Founder/CEO at Drata (We're hiring!)

Recent Drata Reviews

Lajah S.
LS
Lajah S.Small-Business (50 or fewer emp.)
5.0 out of 5
"Suuportive and cooperative team"
Althought the support team member, Pablo, worked on a different time zone he did his best to keep up with the issues I was facing and also assistin...
Verified User
A
Verified UserMid-Market (51-1000 emp.)
4.5 out of 5
"The new updates have been bit rickety but otherwise experience with Drata is good"
Ease of use is the best part about drata
Verified User
C
Verified UserSmall-Business (50 or fewer emp.)
5.0 out of 5
"100% Drata support satisfaction"
Ease of use, Ease of implementation, Customer Support, Ease of Integration
Security Badge
Drata Security
Get security information from Drata to help you buy the right software. View Security Information

Drata Media

Drata Demo - Drata's Automated Security Control Monitoring
Automated monitoring of your controls mapped to your framework
Drata Demo - Drata's SOC 2 Framework
Get audit ready with Drata's SOC 2 product. Drata gives you a single view of your security and compliance with 75+ deep integrations, automated monitoring and evidence collection, dashboards with real-time audit readiness, policy templates, compliance monitoring of your personnel, streamlined ven...
Drata Demo - Drata's Automated Security and Compliance Dashboard
With Drata's Dratameter and central dashboard, you will always know your overall control and requirement readiness.
Drata Demo - Drata's Open API
Drata’s Open API allows you to build and configure your security posture with flexible workflows, any integrations, and data exchanges. There is little to no code and the ability to connect to any solution—like security training solutions, background check providers, MDM systems, and more—to brin...
Drata Demo - Trust Center by Drata
Trust Center provides real-time transparency into your organization’s security posture. It seamlessly integrates with your website and allows you to publicly display security reports like vulnerability assessments and penetration test summaries, certifications and attestations like SOC 2, ISO 270...
Drata Demo - Risk Management
Drata's Risk Management is an integrated solution that helps you manage risk and compliance in one place.
Play Drata Video
Play Drata Video
Play Drata Video
Play Drata Video
Play Drata Video

Official Downloads

Answer a few questions to help the Drata community
Have you used Drata before?
Yes

966 out of 967 Total Reviews for Drata

4.8 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
966 out of 967 Total Reviews for Drata
4.8 out of 5
966 out of 967 Total Reviews for Drata
4.8 out of 5

Drata Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons

Overall Review Sentiment for DrataQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
Debra B.
DB
Technical Program Manager
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
(Original )Information
What do you like best about Drata?

I'm a vCISO and work with customers on building their security programs and preparing for an audit. Drata has been amazing in preparing my customer for SOC2. It's amazing in that 85% of the evidence is automatically gathered and tested every 24 hours. No more screenshots and manual gathering of evidence. The best part is knowing the control is actually being enforced on a daily basis. Ali McCormick our Drata Customer Success Manager has been great in helping us use Drata and meet the customer's accelerated SOC2 timeline. Review collected by and hosted on G2.com.

What do you dislike about Drata?

I wish the Risk Assessment and Remediation Plan were more automated. Having to map the Remediation to the control manually was disappointing. The SOC2 system description isn't automated. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

85% automation of gathering the evidence and preparation for SOC2. Pulling everything about SOC2 into one place. Being able to assign controls to specific owners who can then manage the control and receive alerts when it's out of compliance, Easily maintaining daily compliance is critical to lowering a company's risk. Review collected by and hosted on G2.com.

Cassandra M.
CM
Head of Security, CSO
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
(Original )Information
What do you like best about Drata?

It seems dumb to say out loud, but it works as expected, every time, and I have the support I need to do what I need to do, when I need to do it. I don't think I've ever waited on help or an answer, and our entire team finds value in the tool each time we use it. You can't say that about much in the software world. We had an easy implementation, easy integration experience, and I love that the chatbot actually works in the after hours when I need to ask my obscure questions. Turns out they're really not all that out of the ordinary, because there's a ready made and easy to find answer no matter what time I want to ask the question. Review collected by and hosted on G2.com.

What do you dislike about Drata?

I'm a little sad my person moved onto another job (Claire), but we have a lovely new person and I know we're in good hands. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

Drata has made our lives much easier, and while we still haven't started having all of our users use it themselves, it does greatly simplify our lives in that the integrations have saved us a ton of time in evidence gathering, but also system monitoring and having to reconnect the integrations, which was happening a lot with Vanta. I can't count how many times the integrations broke and caused us to have to restart in the middle of an audit. Such a waste of time and effort (and patience). Review collected by and hosted on G2.com.

Rachel B.
RB
Operations and Compliance Manager
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Drata?

We had an awesome experience working with Drata, especially with Elizabeth John, who was incredibly helpful throughout the process. She made setting up everything for our SOC 2 Type 1 and 2 so much easier, guiding us every step of the way and always being available to answer questions. Elizabeth was extremely prompt, responding quickly whenever we needed support, which made the entire process feel smooth and efficient. The platform itself is intuitive and streamlined, taking a lot of the stress out of compliance. Highly recommend Drata if you’re looking for a straightforward compliance journey — and if you get the chance to work with Elizabeth, you’re in great hands! Review collected by and hosted on G2.com.

What do you dislike about Drata?

The only downside we’ve encountered is the lack of integration with Oracle Cloud Infrastructure (OCI), which would make the platform even more versatile for our needs. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

Obtaining SOC 2 Type 1 and 2 Review collected by and hosted on G2.com.

Jared B.
JB
Chief Compliance Officer
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Drata?

1. Drata's compliance automation is a game changer. The available integrations allow a small compliance team to scale to an unlimited size organization. For example, vulnerability scanning, device monitoring, data security testing, policy, network infrastructure, risk assessment, and the list goes on. These were previously controlled and documented in independent places and my compliance team 1) struggled to manage all of the compliance evidence and 2) "pushed" the information to the SOC 2 auditor. Drata consolidates this into one portal and the auditor has on demand access. This truly is automated compliance.

2. Live chat support, compliance library, policy templates, risk assessment guide. The provided tools help you effectively set up a compliance program.

3. My vendor rep has been extremely helpful and available throughout the process. We meet every two weeks to ensure we are progressing sufficiently. But also, I appreciate that she understands everyone works at their own pace so is not pushing us if not necessary. Review collected by and hosted on G2.com.

What do you dislike about Drata?

The vendor management functionality is lacking. Specifically, the questionairre function is very limited and not very useful. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

SOC 2 type 2 certification. We found Drata because of issues we were facing with a SOC 2 type 2 audit and I am so please we did! Review collected by and hosted on G2.com.

CB
Chief Technology Officer
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Drata?

Drata has been great to map from the ISO 27001 framework requirements to actual controls. Whilst it doesn't replace compliance activities, it has sped up our alignment of our existing process to the ISO 27001 framework controls. The in-built policies have been great to use a base for review and sometimes wholly draft new policies. The risk assessment area is also very good for keeping and scoring risks.

Finally the automation of controls is very good and suited to our environment (circa 150 employees + AWS infratructure). The tool makes it easy to disable tests (where not appropriate) or exclude particular items from the test (and justify this). The raw evidence is often very helpful for troubleshootin why our infrastructure may fail a particular test.

Their customer success folk are absolutely excellent and work with you the whole way, and the interface is very intuitive and so it's as 'self-service' as you can imagine. The onboarding of the various integrations/connections was seamless with little need for help.

During the "getting compliant", Drata has been used pretty mcuh every day by the security team in order to keep track of progress. Review collected by and hosted on G2.com.

What do you dislike about Drata?

Dislike is a strong word. Given the relative youngness of the company, there are a few rough edges spread around none of which stop getting the value from the tool. It sometimes feel like the tool is geared more towards "keeping compliant" than "getting compliant" - which of course will be the vast majority of the platform's use.

Occasionally, the platform is a little limited (integrating with Enterprise Intune policies needs to be done in a very particular way) - though this we managed to overcome with the help our Customer Success manager. In other areas, we disagreed with some of the automated monitoring tests and their implementation (for example around production access to Gitlab). but that was overcome by using their API to upload evidence automatically from a small CI/CD job and disabling that single test. On the whole, we use almost every test provided by Drata out of the box. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

It's helping ensuring that as we rework our policies, ways of working, etc, that we are algining to ISO 27001 and helping us formalise and identify activities we were already doing. Ultimately, it will help us with the ongoing compliance by prompting for regular activities to be performed, highlighting where we've departed from standards/policies immediately within 24 hours, etc. Review collected by and hosted on G2.com.

Eric L.
EL
Security Engnieer
Electrical/Electronic Manufacturing
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
(Original )Information
What do you like best about Drata?

Drata supports the most common compliance frameworks. It effectively translates compliance requirements into readable control items. Each control item consists of a set of tests that are defined with clear specifications. For example, if an organization wants to adhere to the compliance NIST CSF, personnel responsible for achieving compliance simply focus on the control items of target compliance that Drata organized. Some tests can be shared across multiple compliance frameworks! It is easier for them to implement other compliances more efficiently in the future. Secondly, the most impressive design is the capability of automated evidence collection. With easy configuration on integrations to popular platforms, it can save effort when collecting the evidence of control items. To manage the overall readiness of compliance continuously, Drata provides efficient monitoring of controls, the status of tests, and the integrity of essential evidence. It provides users with real-time status and benchmarks in the dashboard. That helps internal or external auditors to track progress, identify gaps, and demonstrate compliance to key stakeholders. Finally, when I was new to Drata in the beginning, the Drata support team consistently delivered effective solutions to customer issues. The experience of customer support really touched my heart. Review collected by and hosted on G2.com.

What do you dislike about Drata?

The automated evidence-collection feature is a very productive design. However, it has both pros and cons. The limitations on integrations may become a burden if the target platform is not on the support list. Another thing that needs to be improved is the instructions for fixing the failed/error tests. Sometimes, I can not directly understand the root cause of the failed test. I hope the error information or solution instructions become more transparent or readable. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

Readiness status: make the estimation on the progress of compliance adherence easier and more readable.

Continuous monitoring: easy to track progress and identify gaps, minimize the risk of non-compliance and reduces the likelihood of costly audit findings.

Automation on evidence: Drata automates many of the manual tasks associated with compliance, frees up valuable resource for the security team and product teams Review collected by and hosted on G2.com.

RA
Executive Assistant | Operations
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Drata?

Drata streamlines compliance journey from start to audit-ready and provides professional support from its team of security and compliance experts, specially Ali!

And I would like to take a moment to commend her (Ali) for an exceptional efforts and dedication. She has consistently gone above and beyond in providing assistance, following up on meetings, and keeping us updated on Drata.

Ali’s proactive approach in ensuring that the our team remains as compliant as possible has been invaluable. Her diligence and commitment to excellence are truly commendable and have greatly contributed to the success of our compliance efforts.

We appreciate Ali’s hard work and dedication!

She's truly an asset! Review collected by and hosted on G2.com.

What do you dislike about Drata?

None . Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

Drata helps streamline and simplify the SOC 2 compliance. It continuously monitors the systems and collects evidence needed for SOC 2 audits, reducing manual effort. The platform offers a real-time dashboard to track your compliance status, highlighting any gaps that need attention. It provides templates and frameworks tailored for SOC 2, making it easier to implement and maintain necessary controls.

Drata integrates seamlessly with tools and platforms you already use, such as cloud providers and project management systems, ensuring smooth data collection and monitoring. The security and compliance experts offer support to help you navigate the SOC 2 process and prepare for audits effectively. By automating key tasks and providing expert support, Drata helps you achieve and maintain SOC 2 compliance more efficiently. Review collected by and hosted on G2.com.

AM
Director of Audit Operations
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Drata?

The Drata platform is very user friendly and provides great support and help articles for users to navigate and understand the compliance requirements. The Drata team is also extremely helpful, responsive, and approachable any time they are needed. Review collected by and hosted on G2.com.

What do you dislike about Drata?

I would like to see a feature that requires manual user updates (i.e. marking items ready for audit) as opposed to automatically checking off as green since this could lead to confusion. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

Drata improves the efficiency (time and effort) in maintaining security compliance. The frequent reminders of overdue, quarterly/annual tasks, and overall status dashboard provide great value to users who do not have the time or headcount to manually keep track of these. On the auditor side, it helps with being able to quickly identify which big ticket items are missing and provide some guidance to the user on how to best address those items. Review collected by and hosted on G2.com.

Ernest P.
EP
Partner
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Drata?

It is a very complete package. My team and I do audits and risk management integration daily. It is straight forward to work with. Everything is there, and it is so convenient for us to work with. Risk Management within an organization is a discipline, a commitment within the organization that risk management is more important than internet access. GRC becomes the public face of the collective strategic risk initiatives. It is a place to share risk efforts with auditors, regulators, clients and leads.

The platform is complex, but it makes sense in it's role within risk management. Review collected by and hosted on G2.com.

What do you dislike about Drata?

The interaction with auditors focuses around the DCF (Drata Control Framework) rather than a specific framework control (like SOC2, ISO, etc). I know that Drata is using that to increase coverage of more frameworks. However, forcing auditors to use DCF rather than an ISO control is a bit of a nuisance.

Despite that, auditors have figured it out. This is a small inconvenience and not a major stopper. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

GRC is an agnostic platform that becomes the single source of truth for risk management. If this is accepted, customers, leads, regulators, auditors and more, never have to go further than trusting the information displayed by Drata.

It becomes a place to shape the forward looking risk mission of an organization and then share that with others.

It has to be a trusted platform onto which controls, standards, policies, evidence and SOPs are published. It needs to be the definitive source of this information and this has to be trusted by all without question. Drata is critically used for clients acheiving and maintaining regulatory compliance and security certifications year over year. It has to be a credible and agnostic platform, trusted by external reviewers and auditors.

It excels at those requirements. Review collected by and hosted on G2.com.

Sam S.
SS
Director of Operations
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about Drata?

When it comes to Drata there are two things that have left a lasting impression: continual product improvement and a remarkable level of support.

I've seen Drata push out new features and improvements quarter after quarter, and I am blown away by their growth even after only a year of use. Their "Trust Center" as a resource as well as Docusign and Salesforce integrations help automate and streamline our internal processes.

Above that our CSM, Benjamin Chau, is phenominal. His professionlism, his can-do attitude, and availability makes him stand out against other CS personnel I've worked with in the past. There was more than one occasion Benjamin dropped what he was doing and joined one of our calls without hesitation to ensure our success, making us feel truly valued both as a customer and a partner. Review collected by and hosted on G2.com.

What do you dislike about Drata?

A small gripe I have is there were some technical nuances that were not clearly mentioned within the help articles when attempting to self-service the SFDC and Docusign connection. This created small hiccups in the integration process, but Benjamin was a strategic partner helping iron our the nuances. Review collected by and hosted on G2.com.

What problems is Drata solving and how is that benefiting you?

Speeding up prospective sales cycle by bypassing NDA requirements Review collected by and hosted on G2.com.