Listing Thumbnail

    Vanta

     Info
    Sold by: Vanta 
    Deployed on AWS
    Vendor Insights
    Vanta helps thousands of fast-growing companies simplify and centralize compliance and security workflows so they can build trust.
    4.6

    Overview

    Play video

    Whether you're just starting out or scaling a mature security program, demonstrating strong security practices and building trust with buyers has never been more critical.

    Vanta's Trust Management Platform helps over 6,000 AWS customers, including Atlassian, Modern Health, and Mistral AI, automate compliance, improve visibility, and reduce manual work. Security, GRC, and IT teams use Vanta to:

    • Automate evidence collection across 35+ frameworks, including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    • Public Sector ready - Compliance automation for CMMC, CJIS, NIST 800-53/171, and FedRAMP across government, non-profit, and healthcare
    • Centralize GRC workflows like risk and vendor management
    • Complete security reviews up to 5x faster

    Now, with the Vanta AI Agent, teams can unlock a new level of efficiency. Acting like an intelligent teammate, the AI Agent helps manage tasks, recommend next steps, and generate audit-ready documentation, enabling teams to work faster, stay organized, and be more proactive in maintaining trust.

    Vanta customers report a 526% ROI over three years, with most seeing payback in just three months. On average, Vanta boosts compliance team productivity by 129%, helping teams do more with less.

    For more complex environments, Vanta supports custom automated tests, built directly in-platform or via the Vanta API, ideal for self-hosted and custom-built systems.

    As the only multi-product vendor in the Trust Management space, Vanta offers not only core compliance automation but also AI-powered solutions across Third Party Risk Management, Trust Center, and now, the Vanta AI Agent, which brings intelligent guidance and automation to every layer of your security.

    Pricing is tiered based on company size and program complexity. Preview pricing for 1-20 employees and more at: vanta.com/pricing. Interested in a private offer via AWS Marketplace? Email awsmarketplace@vanta.com 

    Highlights

    • Built for AWS - not just compatible: As an AWS Security Competency Partner with deep integrations across 40+ AWS services, Vanta gives you full visibility into your cloud security and compliance, and is purpose-built for AWS-native environments.
    • Automated and scalable compliance: Continuously monitor your AWS environment to meet frameworks like SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR. Vanta automates evidence collection and policy management to reduce manual effort and audit prep time.
    • Security posture, strengthened by AI: Leverage the Vanta AI Agent for intelligent task management, smart recommendations, and real-time responses to audit needs. Combined with features like real-time audit trails, centralized access reviews, and AI-powered Vendor Risk Management, Vanta helps you stay secure and audit-ready all year round.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (10)

     Info
    Dimension
    Description
    Cost/12 months
    AWS FTR
    AWS FTR Module
    $7,500.00
    Essentials Package
    Starting cost for 1-20 employees
    $14,000.00
    Professional Package
    Starting cost for 1-20 employees
    $23,000.00
    Plus Package
    Starting cost for 1-20 employees
    $21,500.00
    Trust Center
    Trust Center module for 1-20 employees
    $6,000.00
    Third Party Risk Management (TPRM)
    Up to 50 vendors managed per year
    $13,600.00
    Questionnaire Automation Advanced
    Questionnaire Automation module with 288 questionnaires a year
    $16,000.00
    Customer Trust Management
    Includes Trust Center Advanced and Questionnaire Automation Advanced
    $22,250.00
    Questionnaire Automation
    Questionnaire Automation module with 144 questionnaires a year
    $10,000.00
    Trust Center Advanced
    Trust Center Advanced module for 1-20 employees
    $10,000.00

    Vendor refund policy

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Centralized Risk Management, Compliance and Auditing, Security
    Top
    10
    In Centralized Risk Management, Compliance and Auditing, Security
    Top
    25
    In IT Business Management, Monitoring

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Compliance Framework Automation
    Automates evidence collection and monitoring across 35+ compliance frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CMMC, CJIS, NIST 800-53/171, and FedRAMP
    Cloud Service Integration
    Provides deep integrations across 40+ AWS services with real-time visibility into cloud security and compliance posture in AWS-native environments
    AI-Powered Task Management
    Includes AI Agent functionality for intelligent task management, smart recommendations, audit-ready documentation generation, and real-time responses to audit requirements
    Centralized GRC Workflows
    Centralizes governance, risk, and compliance workflows including risk management, vendor management, centralized access reviews, and real-time audit trails
    Custom Automated Testing
    Supports custom automated tests built directly in-platform or via API for self-hosted and custom-built systems
    Multi-Framework Compliance Support
    Streamlines over 20 compliance frameworks, standards, and regulations including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    Continuous Automated Monitoring
    Continuously monitors security controls across integrated applications and systems with automated alerts when controls are not operating effectively
    AWS Service Integration
    Integrates with 45+ AWS services and utilizes an AI engine built on AWS Bedrock
    Automated Evidence Collection
    Automatically collects evidence required for audit processes to streamline audit preparation
    Real-Time Compliance Posture Visibility
    Provides real-time compliance posture tracking and reporting capabilities for risk management and remediation
    Automated Evidence Collection
    More than 100+ integrations with core services such as AWS, Asana, Azure, G Suite, Google Cloud, Github, Gusto, JAMF, Okta and Slack automatically and continuously collect audit evidence and monitor cloud infrastructure for nonconformities.
    Machine Learning-Powered Questionnaire Completion
    Machine learning-powered RFP and security questionnaire completion with knowledge base management that pulls best answers from approved past responses.
    Continuous Monitoring and Automated Testing
    Continuous monitoring and automated tests across cloud infrastructure to identify and track compliance violations and security issues.
    Prebuilt Customizable Security Policies
    Standard policy templates that can be customized to meet organizational requirements while maintaining alignment with auditor and regulatory framework standards.
    Multi-Framework Compliance Support
    Support for multiple compliance frameworks including SOC 2, ISO 27001, ISO 27701, HIPAA, GDPR, CCPA, NIST 800-53, NIST 800-171, NIST CSF, NIST Privacy Framework, CMMC, PCI DSS SAQ-A, PCI DSS SAQ-D, Microsoft SSPA, and MVSP.

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.6
    2361 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    77%
    21%
    2%
    0%
    0%
    9 AWS reviews
    |
    2352 external reviews
    External reviews are from G2  and PeerSpot .
    Bhavya J.

    Review Vanta

    Reviewed on Apr 10, 2026
    Review provided by G2
    What do you like best about the product?
    They should roll out new changes more frequently by better understanding customer needs and aligning updates with what users are asking for.
    What do you dislike about the product?
    Sudden new test give hard time to implement
    What problems is the product solving and how is that benefiting you?
    Meeting compliance continuously is tough, and Vanta makes it easier.
    Consulting

    Best-in-Class UI/UX, Comprehensive Controls, and Top-Tier Integrations

    Reviewed on Apr 10, 2026
    Review provided by G2
    What do you like best about the product?
    Vanta has the best UI/UX in the industry, along with one of the most comprehensive sets of controls (or “tests”) that are mapped correctly to the relevant frameworks. In my experience (we’re a service provider), other GRC tools often add too many unnecessary controls that don’t actually map cleanly to SOC 2, ISO 27001, HIPAA, GDPR, etc. That ends up wasting time for the company using the tool, especially when they’re trying to get compliant with the specific framework they’re targeting.

    Vanta also has the best integrations in the industry. They’re custom-built, as opposed to most of the other major GRC tools that decided to use Leen (a great company, but a very different experience). Their pricing is on par with the value they deliver.
    What do you dislike about the product?
    The company removed partners’ ability to get accurate quotes directly from the site and now requires us to go through a person to figure out what to quote customers. This has added significant time (usually waiting time) to our proposal process. Other than that, there isn’t anything else I dislike.
    What problems is the product solving and how is that benefiting you?
    Vanta has a solid multi-tenant view that lets us manage multiple companies at once, and it’s been pretty seamless. In our experience, out of all the GRC tools we’ve worked with (over 10), Vanta has consistently been far above the competition when it comes to supporting our customers’ compliance needs. It also provides a better day-to-day experience for our team handling the actual work: evidence collection, policy writing, auditor back-and-forth, and control remediation.
    Emiel Q.

    Streamlines Compliance with Minimal Hassle, But Integration Challenges Remain

    Reviewed on Apr 07, 2026
    Review provided by G2
    What do you like best about the product?
    I think Vanta provides a comprehensive UI and UX experience that clearly shows how well we comply with different frameworks. It integrates the auditing framework in a way that feels streamlined and easy to follow. Vanta also guides us through setting up regulatory controls by offering remedies and instructions on how to meet the requirements. Overall, these features make it much more accessible to manage compliance frameworks.
    What do you dislike about the product?
    I think the integration experience could be improved. The integrations do work, but I’ve had trouble getting them up and running. Even though the product shows you what you should be doing, once you hit an error you can feel a bit stuck. Customer support will work with you and they’re quite comprehensive, so you’re not truly left to your own devices, but it’s still easy to get hung up on certain integrations.

    Also, I feel like ISO 9001 is more of an afterthought and not really a focus compared with more IT-regulated frameworks like SOC 2 or ISO 27001. The initial setup was fairly easy, but it still isn’t finished on our side. If you’re a company with an array of SaaS tools and you need to integrate each and every one of them, no one is really going to sit with you for a full day to run through all those integrations. In my experience, the onboarding isn’t necessarily very structured, and that’s where things can slow down.
    What problems is the product solving and how is that benefiting you?
    I use Vanta to automate compliance with ISO frameworks, reducing manual checks and integrating our tech stack. It streamlines policy creation, making compliance less dependent on individuals.
    Rogerio G.

    Easy-to-Use Audits in One Place with Solid Integrations

    Reviewed on Apr 03, 2026
    Review provided by G2
    What do you like best about the product?
    Vanta is really easy to use and integrates well with the tools we already have. The best part is that we don't need to go back and forth with auditors using giant spreadsheets anymore. Everything is in one place. Uploading evidence is simple and saves us a lot of time during audits.

    Performance has been solid for us. Our workload isn't huge so we haven't really pushed it to the limits, but we have no complaints there. Support and onboarding were great too, the app is pretty intuitive so we didn't need much hand-holding to get started.

    On pricing, it's a bit on the higher side, especially if you're a startup going through your first audit. That said, the ROI is definitely there once you see how much time and effort it saves you.
    What do you dislike about the product?
    Some user flows are hidden deep inside specific pages and not easy to find from the main menu. I get that they want to keep the menu clean, but it takes too many clicks to go from a failing test all the way to, say, removing a computer from an employee that left the company. And if you go directly to the computers page, it's not obvious that there's an unassigned computer sitting there. A bit more visibility on those things would help a lot.
    What problems is the product solving and how is that benefiting you?
    We're a small company without a dedicated security team, and we needed to get SOC 2 compliant. That's where Vanta really helps. Normal engineers and operations people who don't have deep expertise in security controls can use Vanta and trust it to guide them through the whole audit process. It makes something that feels overwhelming actually manageable for a small team like ours.
    Prateek S.

    Helpful mitigation guidance, but GCP integration flags removed assets

    Reviewed on Mar 31, 2026
    Review provided by G2
    What do you like best about the product?
    The section that explains how you can mitigate the issue is helpful, especially because it shows multiple approaches to do it, such as using Terraform, the Console, or the CLI.
    What do you dislike about the product?
    There are issues with the GCP integration. We removed the asset completely, but Vanta was still flagging it.The AI support bot is not very useful .
    What problems is the product solving and how is that benefiting you?
    We cant to be SOC and PCI compliant .
    View all reviews