I use it as a way to shift from using spreadsheets for SOC2 compliance to something where I can operationalize it into a platform and manage my documents and schedules when needed and where attention needs to be given to the auditor's review of the tools.
External reviews
External reviews are not included in the AWS star rating for the product.
Easy to use product and great customer experience
Great product and team = great overall experience
Best Product Development I Have Experienced
Best Aspects of Drata:
1. Product development quality and speed
2. Ease of mapping frameworks to policies to controls to risks for end to end management
3. Balance of configuration versus customization, Drata is still easy to setup and manage while allowing you to meet your current process in the middle
4. Focus on automation whether its automated control tests or smart use of AI for repetitive tasks
2. Implementing the principle of "assess once, report many".
3. Ensuring that our framework is grounded by what is happening in security operations and engineering through integrations and process/framework alignment.
Manages documents and schedules with integrations and organizational efficiency
What is our primary use case?
What is most valuable?
Once the tool is set up, Drata offers several valuable features. One key aspect is its integrations, which connect seamlessly with your ecosystem, including cloud services, HR systems, and various security tools. It checks configurations to determine compliance, significantly reducing the overhead of creating evidence from screenshots and configuration changes. This proactive approach allows users to address issues as they arise.
Another important feature relates to organizational efficiency during audits. Typically, you would need to review folder structures where specific controls are located and manually set up calendar events to remind you when to upload documents or screenshots as proof of compliance. Drata streamlines this process by providing a platform that automates control management. You can check your policies and procedures, conduct reviews, and automatically generate evidence for tracking compliance.
What needs improvement?
I consider my team and myself to be advanced users of Drata, continually pushing the boundaries of use cases and feature requests. We were actively involved in enhancements related to metrics from the risk register and compliance areas, focusing on visualizing trends in risk closure over time and assessing tolerance levels across different categories.
We engaged with customer success on improvements for the Trust Center, seeking metrics like the most downloaded documents, visitor analytics, and insights into which verticals access our site most frequently. This information is crucial for identifying hotspots and areas for improvement across sectors such as K-12, higher education, corporate, and government.
The readiness state of compliance frameworks can sometimes be misleading. For instance, despite having been in SOC 2 Type II compliance for a few years and being 36 months into using Drata, our readiness metric may still show around 60%. This often doesn't reflect our readiness, which is closer to 90-100%. The score can be impacted by recent policy revisions, such as updates made in Q3 or Q4, which may not yet be reflected in the system. These nuances often require additional explanation regarding the reported readiness status.
For how long have I used the solution?
I have been using Drata for a year and a half.
What do I think about the stability of the solution?
Some minor bugs occasionally appeared in the web UI, and when reported, they were quickly fixed. There was also a minor outage on the Trust Center caused by an issue with CloudFlare that was outside their control. They provide a status page where users can check for such incidents and their resolutions.
What do I think about the scalability of the solution?
We have about fifteen people with access to Drata, each in different roles. As a global company, these users are spread across various locations around the world.
How are customer service and support?
Our experience with customer success at Drata has been quite positive, largely due to the quality of the personnel assigned to us and the frequency of our meetings, which occurred every two to three weeks for about a year and a half. Having a game plan for these meetings and treating them like office hour sessions has been valuable, as it allows for timely answers to our questions, either on the spot or as follow-ups. This level of involvement from Drata's team stands in stark contrast to some other vendors, where you might not even know who your representative is, and they typically only reach out during quarterly business reviews or renewal discussions.
How would you rate customer service and support?
Positive
How was the initial setup?
I strongly advocate for evaluations that prioritize objectivity by removing emotions from the decision-making process. During my assessment of various tools, I utilized a scorecard and test plan that included clear requirements and priorities. I compared options such as Fanta, OneTrust, and Drata, which was emerging as a strong contender.
Throughout the evaluation, we encountered several bugs within Drata's platform, but their team quickly addressed these issues in production. Additionally, having visibility into their roadmap was a crucial factor that indicated Drata would be a reliable vendor and partner for us.
It supports my privacy and legal team with features like auto consent and AI capabilities, which meet our needs. We chose this tool because of its agility; we felt confident it would grow alongside us and allow us to influence its roadmap.
The platform includes a helpful wizard for setting up integrations, organizing our policies and procedures, and addressing unready controls through a punch list. Additionally, we have assigned a customer success manager who will collaborate with us to tackle these items. We aim to ensure all controls are ready, connected, and scheduled, enabling us to transition to an operational state.
Five people are required for the deployment.
What was our ROI?
Before implementing Drata, I managed compliance tasks using spreadsheets, which required significant discipline and involvement. With Drata, I could transition most responsibilities to a more junior team member in security, allowing them to take on the bulk of the work, except for certain nuances like writing policies or phrasing things correctly to support sales. The value of Drata is quite high in terms of trust enablement, which can nearly pay for itself from an organizational standpoint.
What's my experience with pricing, setup cost, and licensing?
There’s a dependence on licensing with Drata, as it varies based on the frameworks you purchase and whether you opt for advanced capabilities like the Trust Center and risk module. Pricing is influenced by the number of frameworks you buy. The price ranges from about $18,000 to $30,000, with a sweet spot for small and medium-sized businesses around $20,000. The pricing is reasonable, and it’s worth noting that software can often be heavily discounted if you know how to negotiate.
What other advice do I have?
Our Drata package has a risk register capability that allows you to track all organizational risks while providing insights and metrics to support that tracking. The proactive integration checks compliance against the controls set for different compliance frameworks. The Trust Center is significant for the company, as it showcases all the controls you test against, whether automated or manual—in a public-facing format. This transparency allows customers and prospects to see how we monitor our infrastructure and integrations. If a control fails, it will appear amber on the public Trust Center, demonstrating our commitment to oversight.
The package streamlines the NDA process, reducing the time required for technical reviews by minimizing reliance on the legal team for manual NDA sign-offs. This functionality decreases the manual work involved for each prospect and has proven a competitive advantage, significantly supporting sales efforts and expediting the review process.
It becomes much easier to use once you familiarize yourself with the web UI and its documentation. Jira has a solid knowledge base, and we also create internal documentation to address specific nuances. After getting past the initial learning curve, the UI is relatively straightforward. I had someone new to security successfully take over most of the operational tasks.
Some nuances are involved in getting your onboarding with Drata set up, particularly in understanding how the AuditHub and its capabilities function. The process can be straightforward as long as everyone is on the same page.
Overall, I rate the solution a nine out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Compliance Guidance Made Easy
Excellence: Your Comprehensive Partner in SOC 2 Compliance
Truly, I cannot say enough of the appreciation I have for the Drata team that has been supporting me and the company in working toward our Soc2.
Rachael is focused and dedicated to our company's success and guides me with every step and follows up with documentation for me to review.
I have stated this before but believe it is well worth pointing out again, Drata is a well thought out platform and easy to use. The integrations with other platforms have been well documented making the setup flawless.
Anytime I've reached out to Drata's support team, without fail, they quickly assist and get me exactly what my company needs to keep us progressing forward.
I use the platform on a daily basis and highly recommend using this platform.
Drata for ISO 27001:2022
Risk management, Vendor management, Asset management and Tust center services that allow us to share our public facing compliance documents with current and potential customers, are all integrated into Drata.
Our Mac fleet is monitored for compliance continuously. Configuration and patching tests run daily. Policy attestations are requested directly to the users when channges are made. Users know about the changes when they are completed and can read and attest directly from the service.
We love Drata!
Helps eliminate evidence gathering and makes assigning different activities easier, simplifying compliance and audit processes
What is our primary use case?
I work with Drata on compliance and audit processes.
What is most valuable?
Drata helps eliminate evidence gathering and makes assigning different activities to different team members easier, simplifying compliance and audit processes. In Pennsylvania, we're putting in thousands of hours. Drata improves our security posture by reducing extra work, allowing us to focus on other security directives. I like the control editing and task management features the most. It's easy to use, but it's also easy for people to think they don't need security experts if they have it.
What needs improvement?
In terms of improvements, I'd suggest better marketing since the industry tends to market these tools as security experts, which isn't true.
For how long have I used the solution?
I have been using Drata for the past eight months.
What do I think about the stability of the solution?
I've had no issues with stability.
What do I think about the scalability of the solution?
Drata is very scalable and suitable for larger organizations due to the ability to assign tasks to different business lines. We have around twenty users across various companies, and I still use other tools.
How are customer service and support?
The technical support team is good, though I haven't used them much.
How was the initial setup?
The initial setup is pretty straightforward.
What's my experience with pricing, setup cost, and licensing?
It's one of the more expensive options, but I think it's worth the money if you can afford it.
What other advice do I have?
I'd rate Drata an eight out of ten because there's always room for improvement. We've seen value and impact from this tool, and I would recommend it to others. My advice would be to have a set project plan for implementation and to get help from a security expert if you don't have one in-house.
Achieves both SOC 2 and ISO 27001 compliance with improved security posture
What is our primary use case?
We use the solution to achieve both SOC 2 and ISO 27001 compliance.
How has it helped my organization?
Drata improved our security posture by ensuring that all our laptops were encrypted and all our production environments were validated with MFA access. We tracked all our Jira tickets to ensure timely remediation. Going through SOC 2 compliance, we still had to perform other tasks like external pen testing, which we achieved, and document it. We also developed tabletop exercises, which were conducted annually, and performed disaster recovery testing on the database. All this was tracked in Drata in real-time, allowing us to quickly identify and address issues, such as TLS encryption problems.
Drata helped us publish our ISO and SOC reports, which was essential for the acquisition. The challenge now is whether Drata can scale up to meet the needs of a larger company. Drata is excellent for startups and small—to medium-sized companies but may face challenges in larger organizations with multiple environments.
What needs improvement?
One of the challenges with Drata is that if you're paying for a subscription to ISO 27001, you must undergo a risk assessment. You should have access to all necessary modules on the platform to achieve your compliance posture and certification.
It provides real-time reporting regarding SOC 2 or ISO compliance. The auditors issue the reports. Therefore, if the auditors make a recommendation, such as configuring our alert system internally based on their advice, we implement it. Drata must also address its bugs to improve things for the auditors.
For how long have I used the solution?
I have been using Drata for one and a half years.
What do I think about the stability of the solution?
After the acquisition, we're still integrating Drata into our environment. The challenges of this integration with the new regime are more significant than anticipated. One issue is stability; when Drata releases updates, we notice some bugs, especially those affecting Mac users. While Drata seems well-suited for smaller startups and mid-sized companies, larger enterprises may encounter more hurdles. Such platforms must remain robust despite occasional integration issues, as updates are necessary for continuous improvement.
I rate the solution's stability a nine out of ten.
What do I think about the scalability of the solution?
These platforms provide real-time reporting. For example, if a control fails, such as requiring all users to log in with unique passwords, I receive an alert. If a user hasn't logged in, the system flags it. Drata helps streamline this process. When a new employee starts, I meet with them to configure their laptop with Drata and show them where the training is. Drata's real-time monitoring is beneficial.
Drata is particularly effective for smaller companies, where communication is easier, and departments are not siloed like in larger organizations. This makes Drata a good platform for startups to complete their audit reporting and demonstrate their legitimacy. Companies can use this to attract private equity, go IPO, or secure more funding from investors.
Ultimately, companies reach a certain level of corporate maturity where they recognize the value of these investments. Real-time reporting and monitoring with Drata pay off by highlighting smaller issues early on, which benefits the company's overall operation and growth.
How are customer service and support?
Drata also made certain promises regarding specific features but did not deliver.
How would you rate customer service and support?
Neutral
Which other solutions did I evaluate?
I've had other demos and due diligence meetings with various vendors, some at the same level as Drata. The challenge becomes whether the bigger company wants to spend the higher cost. It becomes a negotiation between price and service.
What other advice do I have?
Drata has excellent integrations and allows for real-time monitoring. Some tasks require manual uploads for screenshot evidence. It can have company policies within the module. This prevents data islands in Dropbox, Google Drive, or other locations. You can tell critical stakeholders, "Alright, we're having a meeting. Here's the draft; let's edit it." Once edited, the owner can press the green button to publish it, automatically sending alerts to the entire company or specific groups.
For example, if the access control policy is updated, everyone must acknowledge the change. You can create groups, like the dev team, to agree to policies like SDLC, change management, or vulnerability management. Any changes are automatically pushed to designated personnel, who must review and approve them. You can track when they've done this in real-time, which is essential for auditors. Everything within the module shows whether personnel have agreed to specific policies.
There are other competitors out there. If you don't prefer Drata, find a similar platform. Many different companies exist because Drata enables you to monitor things in real time, which is crucial for both short-term and long-term goals. Short-term goals include daily or weekly reviews for compliance, while long-term goals aim to achieve SOC 2 and ISO goals.
Overall, I rate the solution an eight out of ten.