Listing Thumbnail

    Drata Security & Compliance Automation Platform (D)

     Info
    Sold by: Drata 
    Deployed on AWS
    Vendor Insights
    An AWS Security Competency Partner, Drata is a GRC automation solution that allows companies to continuously monitor security and compliance controls, automatically collect evidence needed for an audit, and manage and remediate risk. Drata streamlines common compliance frameworks like SOC 2, ISO 27001, GDPR, and more and allows you to share your real-time compliance posture with prospects and customers to build trust and accelerate growth.

    Overview

    Play video

    Drata's compliance automation platform integrates with over 200 applications and systems to continuously monitor security controls and streamline over 20 compliance frameworks, standards, and regulations, such as SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and more. Drata integrates with 45+ AWS services and is a proud AWS Security Competency partner with an AI engine built on AWS Bedrock.

    Whether you're looking to get compliant quickly for the first time or want to streamline your complex GRC program, Drata scales with you. Get and stay compliant efficiently, build risk management into your GRC practice, and share your real-time compliance posture with prospects and customers to build trust and sell into new markets.

    Continuous automated monitoring alerts Drata customers when security controls aren't operating effectively to remediate, stay secure, and keep from falling out of compliance. Plus, automatic evidence collection makes the audit process as seamless as possible.

    Highlights

    • Drata for Startups: Drata helps startups create a scalable foundation and systematic approach to compliance to unlock market opportunities and scale safely. Startups can speed up audit prep time with Drata's best-in-class automation and support from our compliance experts to achieve SOC 2 and ISO 27001 compliance quickly.
    • Drata for Commercial and Mid Market: Drata helps companies with audit experience establish a scalable GRC program and structured process for risk management. Streamline compliance tasks and substantially reduce manual workloads while leveraging compliance to increase revenue and build trust.
    • Drata for Enterprise: Customers can optimize and customize their mature GRC programs and depend on reliable compliance outcomes. Organizations can manage and remediate risk and leverage Drata workspaces and workflows to keep pace with the complexity of advanced compliance programs.

    Details

    Sold by

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Pricing

    Drata Security & Compliance Automation Platform (D)

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (16)

     Info
    Dimension
    Description
    Cost/12 months
    Drata Platform Fee
    Access to the Drata SaaS platform with capacity for a 100 FTE org
    $25,000.00
    SOC 2 Framework
    SOC 2 2017 control set
    $7,500.00
    GDPR Framework
    GDPR control set
    $7,500.00
    ISO 27001 Framework
    ISO 27001 v2022 control set
    $7,500.00
    HIPAA Framework
    HIPAA control set
    $7,500.00
    PCI DSS Framework
    PCI DSS control set
    $7,500.00
    CCPA Framework
    CCPA control set
    $7,500.00
    CMMC Framework
    CMMC control set
    $7,500.00
    Microsoft SSPA Framework
    Microsoft SSPA control set
    $7,500.00
    NIST CSF Framework
    NIST CSF control set
    $7,500.00

    Vendor refund policy

    All Orders are non-cancellable and all fees and other amounts you pay under this Agreement are non-refundable.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    Included in your contract, Drata provides onboarding, live chat (in product), and continuous enablement. Onboarding includes integration setup, assistance configuring compliance policy and controls in the platform, and guidance on utilizing our network of auditors and technology/service partners to serve you in your compliance journey. support@drata.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Monitoring, Centralized Risk Management, Security
    Top
    10
    In Centralized Risk Management, Compliance and Auditing, Security
    Top
    10
    In Legal & Compliance, Compliance and Auditing

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Compliance Framework Support
    Supports continuous monitoring and automation for over 20 compliance standards including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    Application Integration
    Integrates with over 200 applications and systems for comprehensive security control monitoring
    Cloud Service Compatibility
    Native integration with 45+ AWS services and built on AWS Bedrock AI engine
    Automated Evidence Collection
    Automatically collects compliance evidence and provides continuous security control monitoring
    Risk Management Automation
    Provides continuous automated monitoring with real-time alerts for security control effectiveness and potential compliance deviations
    Compliance Automation
    Automates evidence collection across 35+ security and compliance frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    Cloud Service Integration
    Deep integrations with 40+ AWS services providing comprehensive cloud security and compliance visibility
    AI-Powered Security Management
    AI Agent provides intelligent task management, smart recommendations, and real-time audit documentation generation
    Custom Test Support
    Supports custom automated tests built directly in-platform or via API for self-hosted and custom-built systems
    Multi-Product Security Platform
    Offers comprehensive trust management solutions including compliance automation, third-party risk management, and trust center capabilities
    Compliance Framework Support
    Supports multiple compliance frameworks including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, PCI DSS, and POPIA
    Automated Evidence Collection
    Enables automated evidence collection and continuous control monitoring across security workflows
    Cloud Integration Capabilities
    Seamless integration with 30+ AWS services and over 100 cloud platform integrations
    Continuous Monitoring
    Provides 24/7 continuous monitoring with capability to reduce time to compliance by up to 90%
    Security Control Management
    Offers automated user access reviews, vendor risk management, and centralized security and compliance workflow management

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    -
    -
    -
    -
    -
    -
    -
    -
    -

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    3.3
    11 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    27%
    36%
    0%
    0%
    36%
    11 AWS reviews
    |
    1100 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Kim W.

    Outstanding Support and Partnership Make Compliance a Breeze

    Reviewed on Nov 05, 2025
    Review provided by G2
    What do you like best about the product?
    The partnership and support we've received from our Drata team have been exceptional. Sierra Alvarez, our Customer Success Manager, and Christina from support have both consistently gone above and beyond to help me organize our SOC 2 controls and prepare for the audit. Their prompt responses and expertise made what could have been a complicated process much more manageable, and Sierra's collaborative approach has truly helped me stay on track and sane throughout.
    What do you dislike about the product?
    The SOC 2 control mapping and evidence alignment process seems tedious and time consuming, the platform is powerful, but it could benefit from more streamlned control mapping and control reassignments.
    What problems is the product solving and how is that benefiting you?
    Drata is streamlining and automating many aspects of our SOC 2 framework, which helps minimize the risk of human error and provides QuikQ with greater confidence that our controls stay compliant and ready for audits. This will also save us a significant amount of time.
    Hospital & Health Care

    Simple to set up and use - greatly sped up accreditation timelines

    Reviewed on Oct 31, 2025
    Review provided by G2
    What do you like best about the product?
    Simple to use and get set up with the different connections to automate some of the controls. Good policy templates that passed our audit. Drata agent was simple to install across our devices and helped with the automation as well.

    Advice on each control evidence was extremely useful to speed up evidence gathering.

    Good recommendation for audit partner in the UK who specialised in earlier stage companies.

    Support seems very good, even at the lower price tiers.
    What do you dislike about the product?
    There were a couple of additional policies that I would have liked some guidance on or basic examples of. The balance of integration audit partners is heavily to the US (to be expected) but would like some more options for UK / EU based providers in the future.
    What problems is the product solving and how is that benefiting you?
    Limited resources as an early stage company needing to demonstrate compliance quickly
    Amanda S.

    Robust Compliance Tool with a Steep Learning Curve

    Reviewed on Oct 31, 2025
    Review provided by G2
    What do you like best about the product?
    I find Drata extremely useful for complete document organization, alerts, compliance, and security across the board. The alert system stands out for its ability to integrate with tools like Slack and Linear, which enhances my workflow seamlessly. I also appreciate the templates for policies and recommendations that Drata makes; they provide valuable guidance and save me time in setting up our compliance processes. What truly sets Drata apart is the extraordinarily helpful support from Alex Hamilton and Tina, who are patient and knowledgeable, assisting me in learning how to optimize and best use Drata. As I become more familiar with the system, I'm increasingly able to leverage its full potential, which is a significant factor in my decision to continue using and considering repurchasing Drata. The combination of these features and the excellent customer support makes Drata an invaluable tool for me and my organization.
    What do you dislike about the product?
    {"I find the initial setup of Drata very difficult, and I felt a lack of sufficient onboarding support.","I'm also frustrated by the extensive knowledge required to effectively use Drata. I wish there were more accessible and responsive chat support, similar to the experience I have with Gusto, to quickly answer questions.","I believe Drata would benefit from having chat support available 24/7 to address issues and learning curves more efficiently."}
    What problems is the product solving and how is that benefiting you?
    Drata organizes documents, provides alerts, aids compliance and security. It integrates well with our tools and offers policy templates and recommendations, enhancing our compliance efficiency.
    Hospital & Health Care

    good support

    Reviewed on Oct 30, 2025
    Review provided by G2
    What do you like best about the product?
    Excellent support and a good feature set.
    What do you dislike about the product?
    missing some integrations that would helpful such as elmo and phished.
    What problems is the product solving and how is that benefiting you?
    ISO Certification and management client questionnaire automation
    Information Technology and Services

    Excellent Customer Support

    Reviewed on Oct 16, 2025
    Review provided by G2
    What do you like best about the product?
    Drata's customer support & how it can help customers have a better picture of their compliance
    What do you dislike about the product?
    At the moment, nothing. Their customer support is top notch.
    What problems is the product solving and how is that benefiting you?
    It is allowing me to manage my customer's Drata instances and help them achieve compliance.
    View all reviews