Listing Thumbnail

    Drata Security & Compliance Automation Platform (D)

     Info
    Sold by: Drata 
    Deployed on AWS
    Vendor Insights
    An AWS Security Competency Partner, Drata is a GRC automation solution that allows companies to continuously monitor security and compliance controls, automatically collect evidence needed for an audit, and manage and remediate risk. Drata streamlines common compliance frameworks like SOC 2, ISO 27001, GDPR, and more and allows you to share your real-time compliance posture with prospects and customers to build trust and accelerate growth.
    4.7

    Overview

    Play video

    Drata's compliance automation platform integrates with over 200 applications and systems to continuously monitor security controls and streamline over 20 compliance frameworks, standards, and regulations, such as SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and more. Drata integrates with 45+ AWS services and is a proud AWS Security Competency partner with an AI engine built on AWS Bedrock.

    Whether you're looking to get compliant quickly for the first time or want to streamline your complex GRC program, Drata scales with you. Get and stay compliant efficiently, build risk management into your GRC practice, and share your real-time compliance posture with prospects and customers to build trust and sell into new markets.

    Continuous automated monitoring alerts Drata customers when security controls aren't operating effectively to remediate, stay secure, and keep from falling out of compliance. Plus, automatic evidence collection makes the audit process as seamless as possible.

    Highlights

    • Drata for Startups: Drata helps startups create a scalable foundation and systematic approach to compliance to unlock market opportunities and scale safely. Startups can speed up audit prep time with Drata's best-in-class automation and support from our compliance experts to achieve SOC 2 and ISO 27001 compliance quickly.
    • Drata for Commercial and Mid Market: Drata helps companies with audit experience establish a scalable GRC program and structured process for risk management. Streamline compliance tasks and substantially reduce manual workloads while leveraging compliance to increase revenue and build trust.
    • Drata for Enterprise: Customers can optimize and customize their mature GRC programs and depend on reliable compliance outcomes. Organizations can manage and remediate risk and leverage Drata workspaces and workflows to keep pace with the complexity of advanced compliance programs.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (1)

    Pricing

    Drata Security & Compliance Automation Platform (D)

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (16)

     Info
    Dimension
    Description
    Cost/12 months
    Drata Platform Fee
    Access to the Drata SaaS platform with capacity for a 100 FTE org
    $25,000.00
    SOC 2 Framework
    SOC 2 2017 control set
    $7,500.00
    GDPR Framework
    GDPR control set
    $7,500.00
    ISO 27001 Framework
    ISO 27001 v2022 control set
    $7,500.00
    HIPAA Framework
    HIPAA control set
    $7,500.00
    PCI DSS Framework
    PCI DSS control set
    $7,500.00
    CCPA Framework
    CCPA control set
    $7,500.00
    CMMC Framework
    CMMC control set
    $7,500.00
    Microsoft SSPA Framework
    Microsoft SSPA control set
    $7,500.00
    NIST CSF Framework
    NIST CSF control set
    $7,500.00

    Vendor refund policy

    All Orders are non-cancellable and all fees and other amounts you pay under this Agreement are non-refundable.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    Included in your contract, Drata provides onboarding, live chat (in product), and continuous enablement. Onboarding includes integration setup, assistance configuring compliance policy and controls in the platform, and guidance on utilizing our network of auditors and technology/service partners to serve you in your compliance journey. support@drata.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Monitoring, Centralized Risk Management, Security
    Top
    10
    In Centralized Risk Management, Compliance and Auditing, Security
    Top
    10
    In Legal & Compliance, Compliance and Auditing

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Multi-Framework Compliance Support
    Streamlines over 20 compliance frameworks, standards, and regulations including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    Continuous Automated Monitoring
    Continuously monitors security controls across integrated systems and alerts when controls are not operating effectively to enable rapid remediation
    Broad Application Integration
    Integrates with over 200 applications and systems, including 45+ AWS services, to collect and monitor compliance data
    Automated Evidence Collection
    Automatically collects evidence required for audits to streamline the audit process and reduce manual documentation efforts
    AI-Powered Risk Management
    Utilizes an AI engine built on AWS Bedrock to support risk management and compliance automation capabilities
    Compliance Framework Automation
    Automates evidence collection and monitoring across 35+ compliance frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CMMC, CJIS, NIST 800-53/171, and FedRAMP
    Cloud Service Integration
    Provides deep integrations across 40+ AWS services with real-time visibility into cloud security and compliance posture in AWS-native environments
    AI-Powered Task Management
    Includes AI Agent functionality for intelligent task management, smart recommendations, audit-ready documentation generation, and real-time responses to audit requirements
    Centralized GRC Workflows
    Centralizes governance, risk, and compliance workflows including risk management, vendor management, centralized access reviews, and real-time audit trails
    Custom Automated Testing
    Supports custom automated tests built directly in-platform or via API for self-hosted and custom-built systems
    Compliance Framework Support
    Supports 30+ compliance frameworks including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, PCI DSS, and POPIA
    Automated Evidence Collection
    Automated evidence collection with continuous control monitoring and auditor-approved policy templates
    Vendor Risk Management
    Vendor risk management and automated user access reviews capabilities
    Cloud Integration
    Seamless integration with 30+ AWS services including Security Hub, Config, and CloudTrail, plus over 100 cloud integrations
    Continuous Monitoring
    24/7 continuous monitoring for real-time compliance posture visibility

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    -
    -
    -
    -
    -
    -
    -
    -
    -
    -

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.7
    1341 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    85%
    13%
    1%
    0%
    1%
    12 AWS reviews
    |
    1329 external reviews
    External reviews are from G2  and PeerSpot .
    Computer & Network Security

    Simple, Straightforward Design with Engaging Gamification

    Reviewed on Jun 08, 2026
    Review provided by G2
    What do you like best about the product?
    Simple & straight forward design. Easy to understand what I need to do. And what's my responsibility. Easy to sign and consume info. I like the gamification as well.
    What do you dislike about the product?
    Sometimes it's difficult to understand just how much signatures one need to go through, it's duteous and tiring to go over paper works- especailly important ones. So I'd have loved to have a AI summary or maybe highlighting of certain areas that I would need to focus on.
    What problems is the product solving and how is that benefiting you?
    Solving managing the security tasks - set by our CISO and making sure everyone signed all the relevant paperwork. Team accountablility
    Information Services

    The most horrible experience in my prof. life.

    Reviewed on Jun 05, 2026
    Review provided by G2
    What do you like best about the product?
    Pricing. I do not like nothing else in this SW
    What do you dislike about the product?
    The role-based model is horrible. You need this software for compliance, but you can’t properly manage your users within it. It feels like they only give you two options: either you do everything yourself, or you have to grant overly broad permissions to others, which then breaks compliance. You cannot manage different companies simuntenioustly because other they cannot spleat access between entities. And DRATA has no trust center, in their case Trust center it is other company and you will need to have addtitional discuttions with them about pricing and functionality.
    Limit list of integrations.
    Integration which exist is often are not working.

    The company deleted support and replace it with AI agent.
    What problems is the product solving and how is that benefiting you?
    ISO27001 documentation storage
    Alex R.

    Effortless Compliance Management, Pricy Add-Ons

    Reviewed on Jun 05, 2026
    Review provided by G2
    What do you like best about the product?
    I love that Drata makes the compliance process so much easier for our ISO27001, SOC2, and HIPAA certifications by doing all the heavy lifting for us. I also appreciate the ease of use; it was so easy to get started, and the UI just makes sense. The way it breaks things down into sections like compliance and risk is really helpful. Setting up Drata was incredibly easy, I was set up in a day.
    What do you dislike about the product?
    Buying a new framework is incredibly expensive! One additional framework I've been quoted 1/3 of my subscription price!
    What problems is the product solving and how is that benefiting you?
    Drata simplifies compliance governance for ISO27001, SOC2, and HIPAA. It eases the process by automating heavy lifting and eliminating manual spreadsheet management.
    Financial Services

    Clear Tickets and Fast AWS Integration Make Issue Tracking Effortless

    Reviewed on Jun 04, 2026
    Review provided by G2
    What do you like best about the product?
    The tickets include detailed and clear instructions, which makes most of them quick to fix, re-test, and resolve. It feels like steady progress rather than one large chunk of work and pressure.

    I also really like the historical results bar chart, as it provides clarity on when an issue was reintroduced.

    The web platform and the AWS account integration are consistently accessible, fast, and technical-user friendly.
    What do you dislike about the product?
    Well, I dislike 2 things:
    1. There are no filters on AWS account id or Git project, which would be really nice to have and apply. We have multiple connections to 1 Drata account, so figuring out what account affected via findings is time consuming. Or maybe custom filters sit somewhere, but I haven't found them yet.
    2. There was one case of Drata tightening rules on Infra ticket, that caused a lot of confusion. On Jan 28th 2026 NACL rules with ALLOW TCP 0–65535 from 0.0.0.0/0 and ALLOW UDP 0–65535 from 0.0.0.0/0 satisfied Drata test case 227, but on Jan 29th the test 227 started failing. I couldn't find any details on the test rules change, at least it was my understanding that something had been changed in the test settings. Maybe adding "last updated at" + short info would have given some clarity.
    What problems is the product solving and how is that benefiting you?
    The biggest benefit is from Infra/Compliance monitoring. I'm a software/cloud engineer who is looking at failed tickets and resolving them.
    Alain F.

    Super helpful for SOC-2, but some Integrations and the Tasks module could be improved

    Reviewed on Jun 03, 2026
    Review provided by G2
    What do you like best about the product?
    It's complete: when well configured, it covers efficiently all the controls necessary to reach SOC-2 compliance (and presumably other standards, that I haven't checked yet). It even goes further with list of vendors, risk assessments, and a partnership with SafeBase to host your Trust Center. Great!
    The product was pretty responsive and easy to navigate, administrate and use (I haven't worked much with the new UI/UX, tho), and integration with our tech stack (IDP, code-base, etc.) is simple.
    Their AI-chatbot is most of the time helpful for basic support, although the corresponding doc is not always up-to-date (so the chatbot may be out-of-date too; but there's always a human to take over).
    What do you dislike about the product?
    Integration with Linear was supported, but the main point is to submit Linear ticket as evidence… which is not possible (and frustrating).
    The "Tasks" module of Drata could be a powerful tool to manage/plan/track/remind all the tasks to do, recurring or punctual, but it is not as complete and smooth as a good old Google or Outlook Calendar (to invite several people, to link to a document, etc.), so we have quickly stopped using it.
    Also, like all other GRC tools, it's always hard to justify the price to our management when everything goes well and no threat was directly addressed via Drata.
    What problems is the product solving and how is that benefiting you?
    We wanted a tool that our auditors could access to answer most of their questions for a SOC-2 audit. Apart from the on-boarding and some permissions issues, Drata did all the work I would have had to do to satisfay the auditors.
    View all reviews