Listing Thumbnail

    Vanta

     Info
    Sold by: Vanta 
    Deployed on AWS
    Vendor Insights
    Vanta helps thousands of fast-growing companies simplify and centralize compliance and security workflows so they can build trust.
    4.6

    Overview

    Play video

    Whether you're just starting out or scaling a mature security program, demonstrating strong security practices and building trust with buyers has never been more critical.

    Vanta's Trust Management Platform helps over 6,000 AWS customers, including Atlassian, Modern Health, and Mistral AI, automate compliance, improve visibility, and reduce manual work. Security, GRC, and IT teams use Vanta to:

    • Automate evidence collection across 35+ frameworks, including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    • Public Sector ready - Compliance automation for CMMC, CJIS, NIST 800-53/171, and FedRAMP across government, non-profit, and healthcare
    • Centralize GRC workflows like risk and vendor management
    • Complete security reviews up to 5x faster

    Now, with the Vanta AI Agent, teams can unlock a new level of efficiency. Acting like an intelligent teammate, the AI Agent helps manage tasks, recommend next steps, and generate audit-ready documentation, enabling teams to work faster, stay organized, and be more proactive in maintaining trust.

    Vanta customers report a 526% ROI over three years, with most seeing payback in just three months. On average, Vanta boosts compliance team productivity by 129%, helping teams do more with less.

    For more complex environments, Vanta supports custom automated tests, built directly in-platform or via the Vanta API, ideal for self-hosted and custom-built systems.

    As the only multi-product vendor in the Trust Management space, Vanta offers not only core compliance automation but also AI-powered solutions across Third Party Risk Management, Trust Center, and now, the Vanta AI Agent, which brings intelligent guidance and automation to every layer of your security.

    Pricing is tiered based on company size and program complexity. Preview pricing for 1-20 employees and more at: vanta.com/pricing. Interested in a private offer via AWS Marketplace? Email awsmarketplace@vanta.com 

    Highlights

    • Built for AWS - not just compatible: As an AWS Security Competency Partner with deep integrations across 40+ AWS services, Vanta gives you full visibility into your cloud security and compliance, and is purpose-built for AWS-native environments.
    • Automated and scalable compliance: Continuously monitor your AWS environment to meet frameworks like SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR. Vanta automates evidence collection and policy management to reduce manual effort and audit prep time.
    • Security posture, strengthened by AI: Leverage the Vanta AI Agent for intelligent task management, smart recommendations, and real-time responses to audit needs. Combined with features like real-time audit trails, centralized access reviews, and AI-powered Vendor Risk Management, Vanta helps you stay secure and audit-ready all year round.

    Get personalized pricing in minutes - New

    If qualified, an express private offer gets you custom pricing and terms. Finalize your purchase in the AWS Marketplace console.

    Details

    Sold by

    Delivery method

    Deployed on AWS

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Pricing

    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (10)

     Info
    Dimension
    Description
    Cost/12 months
    AWS FTR
    AWS FTR Module
    $7,500.00
    Essentials Package
    Starting cost for 1-20 employees
    $14,000.00
    Professional Package
    Starting cost for 1-20 employees
    $23,000.00
    Plus Package
    Starting cost for 1-20 employees
    $21,500.00
    Trust Center
    Trust Center module for 1-20 employees
    $6,000.00
    Third Party Risk Management (TPRM)
    Up to 50 vendors managed per year
    $13,600.00
    Questionnaire Automation Advanced
    Questionnaire Automation module with 288 questionnaires a year
    $16,000.00
    Customer Trust Management
    Includes Trust Center Advanced and Questionnaire Automation Advanced
    $22,250.00
    Questionnaire Automation
    Questionnaire Automation module with 144 questionnaires a year
    $10,000.00
    Trust Center Advanced
    Trust Center Advanced module for 1-20 employees
    $10,000.00

    Vendor refund policy

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Centralized Risk Management, Compliance and Auditing, Security
    Top
    10
    In Centralized Risk Management, Compliance and Auditing, Security
    Top
    25
    In IT Business Management, Monitoring

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Compliance Framework Automation
    Automates evidence collection and monitoring across 35+ compliance frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CMMC, CJIS, NIST 800-53/171, and FedRAMP
    Cloud Service Integration
    Provides deep integrations across 40+ AWS services with real-time visibility into cloud security and compliance posture in AWS-native environments
    AI-Powered Task Management
    Includes AI Agent functionality for intelligent task management, smart recommendations, audit-ready documentation generation, and real-time responses to audit requirements
    Centralized GRC Workflows
    Centralizes governance, risk, and compliance workflows including risk management, vendor management, centralized access reviews, and real-time audit trails
    Custom Automated Testing
    Supports custom automated tests built directly in-platform or via API for self-hosted and custom-built systems
    Multi-Framework Compliance Support
    Streamlines over 20 compliance frameworks, standards, and regulations including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    Continuous Automated Monitoring
    Continuously monitors security controls across integrated applications and systems with automated alerts when controls are not operating effectively
    AWS Service Integration
    Integrates with 45+ AWS services and utilizes an AI engine built on AWS Bedrock
    Automated Evidence Collection
    Automatically collects evidence required for audit processes to streamline audit preparation
    Real-Time Compliance Posture Visibility
    Provides real-time compliance posture tracking and reporting capabilities for risk management and remediation
    Automated Evidence Collection
    More than 100+ integrations with core services such as AWS, Asana, Azure, G Suite, Google Cloud, Github, Gusto, JAMF, Okta and Slack automatically and continuously collect audit evidence and monitor cloud infrastructure for nonconformities.
    Machine Learning-Powered Questionnaire Completion
    Machine learning-powered RFP and security questionnaire completion with knowledge base management that pulls best answers from approved past responses.
    Continuous Monitoring and Automated Testing
    Continuous monitoring and automated tests across cloud infrastructure to identify and track compliance violations and security issues.
    Prebuilt Customizable Security Policies
    Standard policy templates that can be customized to meet organizational requirements while maintaining alignment with auditor and regulatory framework standards.
    Multi-Framework Compliance Support
    Support for multiple compliance frameworks including SOC 2, ISO 27001, ISO 27701, HIPAA, GDPR, CCPA, NIST 800-53, NIST 800-171, NIST CSF, NIST Privacy Framework, CMMC, PCI DSS SAQ-A, PCI DSS SAQ-D, Microsoft SSPA, and MVSP.

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.6
    2466 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    76%
    21%
    1%
    1%
    1%
    9 AWS reviews
    |
    2457 external reviews
    External reviews are from G2  and PeerSpot .
    Financial Services

    Vanta Saves time - Making Compliance Management More Efficient

    Reviewed on Jun 30, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about Vanta is how much time it saves... It takess lot of the manual work out of compliance by automating evidence collection and monitoring, which makes staying audit-ready much easier. I also like that it gives us a clear and professional way to showcase Fenergo's security and compliance posture through the Trust Center, helping build trust with customers and prospects..
    What do you dislike about the product?
    Vanta has been really useful overall, but I think some areas could be more flexible. There are times when workflows don't quite match how we operate, and it can take a bit of digging to understand why a test has failed or what action is needed. More customization and clearer guidance would help.
    What problems is the product solving and how is that benefiting you?
    Vanta is helping solve a lot of the administrative burden that comes with managing compliance. Instead of spending time chasing evidence, tracking control ownership, or preparing for audits manually, much of that information is collected and monitored automatically.

    For me, that means less time on repetitive tasks and more & moree time focusing on actual compliance and security improvements. It also gives better visibility into our overall compliance posture and makes it easier to demonstrate trust and assurance to customers and auditors when needed...
    Anubhav T.

    Automated Compliance That Cut Our Audit Time in Half

    Reviewed on Jun 30, 2026
    Review provided by G2
    What do you like best about the product?
    I use Vanta for automating security compliance and to monitor our cloud structure. It easily integrates with systems like AWS, Google Workspace, GitHub, and endpoint management tools to collect audit evidence, monitor security controls, and identify compliance gaps wherever necessary, and it simplifies audit preparation for frameworks such as SOC 2 and ISO 27001. The feature I like the most is the automation it provides. Instead of manually collecting evidence and checking security controls, Vanta continuously performs these tasks in the background, which significantly reduces audit preparation time. It gives me a centralized, real-time view of compliance status, failed security checks, and remediation tasks across all integrated systems. During a SOC 2 audit, Vanta automatically collected evidence from AWS and other similar platforms throughout the year, so instead of spending several weeks gathering screenshots and access logs manually, everything was already organized in one dashboard. We completed auditor requests within days and reduced audit preparation time by nearly half while improving accuracy and transparency. It automatically checks controls such as MFA enforcement, device encryption, employee onboarding, user access reviews, and cloud security configuration through integrated systems. Failed checks generate alerts and remediation tasks for the appropriate teams, and this continuous automation keeps compliance up to date and ensures we are always audit ready throughout the year. I like the continuous evidence collection, which ensures evidence is always current, significantly reduces repetitive administrative work, and minimizes human error. IT security has benefited the most, since it reduces their manual workload now that it's automated and reduces human errors. There is a 60-70% reduction in audit time, we reduced compliance-related manual tasks, responded to auditors faster, and identified security gaps much earlier through continuous monitoring. It collaborates well between teams, hands off the work smoothly, and the remediation of tasks is well organized with easy transitions. The initial setup was moderately easy for us.
    What do you dislike about the product?
    Even though it's highly effective, I find the customization and reporting capabilities somewhat limited for organizations with unique compliance requirements. Some integrations require additional manual configuration. And for complex environments, I need extra tools to get complete visibility and meet specialized security or regulatory needs.
    What problems is the product solving and how is that benefiting you?
    Before Vanta I had to manage security compliance manually. Now it automates evidence collection, continuously monitors security controls, and identifies gaps for audits like SOC 2 and ISO 27001. It cuts our audit time by 60-70%, reduces manual work and human errors, and helps maintain customer trust.
    Consulting

    Vanta Centralizes Compliance: Clean Dashboard, Automated Integrations & Continuous Monitoring

    Reviewed on Jun 29, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about Vanta is how it brings security compliance into one organized, easy-to-manage platform. The dashboard is clean and intuitive, making it simple to see which security controls are complete and which ones still require attention. Instead of tracking evidence manually, the automated integrations collect information from many of the tools our team already uses, which saves a significant amount of time and reduces repetitive work.

    I also appreciate the continuous monitoring features because they help identify potential issues early instead of waiting until an audit. That gives our team more confidence that we're staying compliant throughout the year rather than scrambling before review time. The onboarding experience was straightforward, and the documentation made it easy to understand what each control required.

    One benefit I didn't expect was how much easier collaboration became. Since evidence, tasks, and compliance progress are all centralized, everyone has visibility into what needs to be done without relying on long email threads or spreadsheets. Overall, Vanta has made the compliance process more efficient, transparent, and much less stressful.
    What do you dislike about the product?
    One area where Vanta could improve is making some of the compliance requirements more beginner-friendly. While the platform automates a lot of evidence collection, there are still controls that require manual interpretation, and it isn't always immediately clear what specific documentation is expected. More in-app examples or guided recommendations would help newer users complete these tasks with greater confidence.

    As our organization connected more integrations, the amount of information in the dashboard increased significantly. Although it's comprehensive, it can sometimes feel overwhelming when trying to prioritize what needs immediate attention. Additional filtering, customizable views, or AI-powered prioritization could make the experience even more efficient.

    Overall, these are usability improvements rather than major issues. The platform performs well and is reliable, but adding more contextual guidance and making navigation easier for first-time users would make an already strong product even better.
    What problems is the product solving and how is that benefiting you?
    Before using Vanta, keeping track of compliance requirements and collecting audit evidence was much more manual and time-consuming. Information was spread across different systems, making it difficult to know what was complete and what still needed attention. Vanta centralized those tasks by automatically collecting evidence through integrations, continuously monitoring security controls, and organizing compliance work in a single dashboard.

    This has made it much easier to stay on top of ongoing compliance instead of scrambling before an audit. The automated reminders and real-time visibility into outstanding tasks have improved collaboration across the team because everyone can see progress in one place. Overall, Vanta has reduced administrative work, helped us identify potential issues earlier, and made the compliance process more organized and predictable, allowing us to spend more time on higher-value security initiatives instead of repetitive manual tracking.
    Computer Software

    Nothing is perfect, but Vanta is the closest I have found so far.

    Reviewed on Jun 29, 2026
    Review provided by G2
    What do you like best about the product?
    One stop shop, minimal configuration. Most of the time "it just works". Having worked in this space in the past, I know what a nightmare it can be to keep integrations working and data flowing. While there are still friction points, Vanta is a huge improvement over tooling I have used in the past.
    What do you dislike about the product?
    I have had issues with integrations in the past. Generally human support is very helpful and able to get things sorted, but when I get routed to AI it is very unhelpful and just tells me to do things I have already tried.
    What problems is the product solving and how is that benefiting you?
    SOC2 compliance, user account housekeeping
    Hospital & Health Care

    Feels Safer After a Hack, but Privacy Monitoring Still Worries Me

    Reviewed on Jun 29, 2026
    Review provided by G2
    What do you like best about the product?
    I feel safe using it because I was hacked before, and now I’m afraid it could happen again and that I might lose the company’s data.
    What do you dislike about the product?
    Honestly, there isn’t much to say, but I’m still worried about my privacy since it monitors my I/O.
    What problems is the product solving and how is that benefiting you?
    Vanta automates our compliance processes, making it easier to collect evidence, monitor security controls, and prepare for audits while saving our team time.
    View all reviews