Listing Thumbnail

    Drata Security & Compliance Automation Platform

     Info
    Sold by: Drata 
    Deployed on AWS
    An AWS Security Competency Partner, Drata is a GRC solution that enables companies to continuously monitor security and compliance controls, automatically collect evidence needed for an audit, and manage and remediate risk. Drata also allows you to share your real-time compliance posture with prospects and customers to build trust and accelerate growth.
    4.8

    Overview

    Play video

    Drata's compliance automation platform integrates with hundreds of applications and systems to continuously monitor security controls and streamline over 20 compliance frameworks, standards, and regulations, such as SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and more. Drata integrates with 45+ AWS services and is a proud AWS Security Competency partner with an AI engine built on AWS Bedrock.

    Whether you're looking to get compliant quickly for the first time or want to streamline your complex GRC program, Drata scales with you. Get and stay compliant efficiently, build risk management into your GRC practice, and share your real-time compliance posture with prospects and customers to build trust and sell into new markets.

    Continuous automated monitoring alerts Drata customers when security controls aren't operating effectively to remediate, stay secure, and keep from falling out of compliance. Plus, automatic evidence collection makes the audit process as seamless as possible.

    For custom pricing, EULA, or a private contract, please contact AWS-Marketplace@drata.com , for a private offer.

    Highlights

    • Drata for Startups: Drata helps startups create a scalable foundation and systematic approach to compliance to unlock market opportunities and scale safely. Startups can speed up audit prep time with Drata's best-in-class automation and support from our compliance experts to achieve SOC 2 and ISO 27001 compliance quickly.
    • Drata for Commercial and Mid Market: Drata helps companies with audit experience establish a scalable GRC program and structured process for risk management. Streamline compliance tasks and substantially reduce manual workloads while leveraging compliance to increase revenue and build trust.
    • Drata for Enterprise: Customers can optimize and customize their mature GRC programs and depend on reliable compliance outcomes. Organizations can manage and remediate risk and leverage Drata workspaces and workflows to keep pace with the complexity of advanced compliance programs.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Drata Security & Compliance Automation Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    Foundation Package for 1-50 FTE Companies
    List price for 1-50 FTE Company
    $15,000.00

    Vendor refund policy

    All Orders are non-cancellable and all fees and other amounts you pay under this Agreement are non-refundable.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    Included in your contract, Drata provides onboarding, live chat (in product), and continuous enablement. Onboarding includes integration setup, assistance configuring compliance policy and controls in the platform, and guidance on utilizing our network of auditors and technology/service partners to serve you in your compliance journey. support@drata.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Centralized Risk Management, Compliance and Auditing, Security
    Top
    10
    In Centralized Risk Management, Compliance and Auditing, Security
    Top
    10
    In Legal & Compliance, Compliance and Auditing

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Multi-Framework Compliance Support
    Streamlines over 20 compliance frameworks, standards, and regulations including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    Continuous Automated Monitoring
    Continuously monitors security controls across integrated applications and systems with automated alerts when controls are not operating effectively
    AWS Service Integration
    Integrates with 45+ AWS services and utilizes an AI engine built on AWS Bedrock
    Automated Evidence Collection
    Automatically collects evidence required for audit processes to streamline audit preparation
    Real-Time Compliance Posture Visibility
    Provides real-time compliance posture tracking and reporting capabilities for risk management and remediation
    Compliance Framework Automation
    Automates evidence collection and monitoring across 35+ compliance frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CMMC, CJIS, NIST 800-53/171, and FedRAMP
    Cloud Service Integration
    Provides deep integrations across 40+ AWS services with real-time visibility into cloud security and compliance posture in AWS-native environments
    AI-Powered Task Management
    Includes AI Agent functionality for intelligent task management, smart recommendations, audit-ready documentation generation, and real-time responses to audit requirements
    Centralized GRC Workflows
    Centralizes governance, risk, and compliance workflows including risk management, vendor management, centralized access reviews, and real-time audit trails
    Custom Automated Testing
    Supports custom automated tests built directly in-platform or via API for self-hosted and custom-built systems
    Compliance Framework Support
    Supports 30+ compliance frameworks including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, PCI DSS, and POPIA
    Automated Evidence Collection
    Automated evidence collection with continuous control monitoring and auditor-approved policy templates
    Vendor Risk Management
    Vendor risk management and automated user access reviews capabilities
    Cloud Integration
    Seamless integration with 30+ AWS services including Security Hub, Config, and CloudTrail, plus over 100 cloud integrations
    Continuous Monitoring
    24/7 continuous monitoring for real-time compliance posture visibility

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    No security profile
    -
    -
    -
    -
    -
    -
    -
    -
    -

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.8
    1148 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    87%
    12%
    0%
    0%
    0%
    7 AWS reviews
    |
    1141 external reviews
    External reviews are from G2  and PeerSpot .
    Jacqueline Segooa

    Centralized audits and policies have transformed how our team manages compliance workflows

    Reviewed on Feb 28, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I am an end user of Drata . Most of the time I work with Drata  for control mapping, uploading evidence, and sometimes risk management and the Policy Center, such as uploading policies. Those are mainly the features that I work with most of the time.

    I primarily do internal audit support with Drata. Drata has been really helpful in terms of centralizing audit evidence. During the traditional audit method, you would have to send evidence via emails. With Drata, everything is centralized, and once external auditors have access to the system, they are able to review everything within a centralized tool. They are also able to download the evidence in a package form and review it. Having to upload policies in one centralized system has been feasible and most effective. Drata has the feature of Policy Center where you are able to upload all the policies within the company and they can be published from there. They can also be acknowledged by employees and approved by policy owners.

    What is most valuable?

    I think the tool having the ability to centralize most of the things is one of the most good things about Drata because when you do things that are scattered, managing policies from another tool and managing evidence collection during audits from another tool becomes difficult. Drata has Audit Hub where you can actually do the audit and when a control has been audited and prepared, you can mark it as complete within the system. With Drata having those capabilities as a GRC  tool, I think it has most of the capabilities that are needed within GRC . We do not need to be purchasing other third-party tools. Though they might be needed, it is most useful that most of the work can be performed within the tool without having multiple third parties.

    Currently, we have a dashboard in Drata. The dashboards go with admin access and relevant access that you need. With the views that I have, I am able to see all the frameworks that we are compliant with. I am able to see if there are certain controls that are not yet fulfilled. It will show that out of 60 controls, 23 is fulfilled and the rest is not fulfilled. That feature is helpful so that you are able to see that when it is 100%, it means you are compliant.

    Overall, Drata as a tool has brought a lot of improvements within the GRC team. Having to centralize everything in one system, mapping the controls within one system, performing audits within one system, monitoring policies within one system, and doing risk management within one system is something that in GRC, speaking from a GRC perspective in cybersecurity, has been very impactful and effective within the team.

    What needs improvement?

    At the moment, integrating Drata with other AIs would be beneficial. I am not too sure if it is something that can be done or if it is possible, but I am not aware. Integrating it with AI where maybe with regards to evidence collection, I would not have to be collecting the evidence manually would be helpful. When you are managing a lot of frameworks, it is a lot of work to actually individually and manually upload all the evidence in Drata. If maybe there is an AI which can be able to automate that kind of a workflow, and obviously as human beings, we will have to do a human error check, I think it would be amazing. I am not too sure if maybe at the moment it is something that is in place and I am not aware of, but I think it would be great.

    Integrations within my team are managed by someone, but I do have an idea about Drata's automated control monitoring. For example, with tests, there are certain systems such as AWS  that has been integrated with Drata, and it tests those systems and puts them as part of evidence. For example, data encryption at rest. We can put it a test and integrate it with AWS , and then it will automatically test the encryption in data at rest. If the test has failed, you will see it. When I log in to check all the controls that have failed, it will show on Drata that the test has failed. Then I will be able to coordinate with the relevant stakeholders and tell them that it needs to be fixed.

    I would like Drata to make the user interface more intuitive.

    For how long have I used the solution?

    I joined SUSE in October 2024, and we started using Drata from May of last year.

    What do I think about the stability of the solution?

    Drata has been an 8 in terms of stability and reliability for me so far.

    There was one instance where our auditors could not access the Audit Hub in Drata, and it was not really something that was wrong from our company side. It was something wrong with Drata. Technical issues do occur. Speaking with them, it took a bit longer than we expected, and we were during the audit process and auditors had to audit, so we had to switch and do it the traditional way without using the tool. However, it was not really that too long.

    What do I think about the scalability of the solution?

    Drata is a 9 in terms of scalability.

    How are customer service and support?

    I do not communicate with the technical support of Drata. I am copied in the emails during the conversations, but I am not the one who is handling the overall support. As part of the GRC team, I am just there for visibility to see what the status of the issues is, but I am not the one who is handling the overall issues.

    How would you rate customer service and support?

    How was the initial setup?

    I was there to do reviews regarding Drata. The setup and the integration of the systems itself was not really done by me, but I was there to review the features and when we do the control mappings and uploading things, I was there to actually see if it was a user-friendly app and if it was understandable.

    Which other solutions did I evaluate?

    I know there is SafetyCulture. It is also for compliance and project management, but it is not really the same as Drata. I would say Drata outperforms it.

    What other advice do I have?

    From my experience with Drata, if maybe for someone who is entry-level or who is not really too technical, they would not really understand some of the things. For someone who is not really technical, some of the terms they would not understand. However, overall, it is understandable and clear and comprehensive.

    Drata has official documentation, guides, and manuals. I think it is going to depend on who is doing the integration. If Drata has that feature, it means it is something that is possible. From my experience, there have been some integrations that have been made and they were a success. Sometimes they do fail because of maybe the problem, it might be with Drata or it might be with the third-party tool that it has been integrated with. However, overall, with my experience having gone through some of the controls, the integrations have been a success.

    At the moment, the ones that I know that Drata has been integrated with are AWS and Qualys. I do not use any tools from Drata's 75 plus integrations overall.

    I would give this review a rating of 10.

    Financial Services

    Drata Streamlined Our Policy and Vendor Management for Audit Readiness

    Reviewed on Feb 19, 2026
    Review provided by G2
    What do you like best about the product?
    We’ve had an incredibly positive experience with Drata. Implementing their platform has been a game-changer for our organization, especially when it comes to getting our policies, procedures, and vendor management processes structured and audit-ready.

    Before Drata, many of our compliance-related documents lived in different places, and maintaining consistency across policies was time-consuming. Drata gave us a centralized, intuitive system to build, organize, and maintain our policies and procedures. The pre-built templates and automated reminders helped ensure nothing fell through the cracks, and version control made updates seamless. What used to take weeks of coordination is now streamlined into a clear, trackable workflow.

    Vendor management has also improved dramatically. Drata’s vendor tracking and risk management features give us a single source of truth for all third-party relationships. We can easily monitor due diligence documentation, review timelines, and risk classifications without relying on scattered spreadsheets. This has not only strengthened our compliance posture but also given leadership better visibility into vendor risk.
    What do you dislike about the product?
    Overall, our experience with Drata has been very positive, particularly around vendor management, and policy management. However, one area where we’ve felt some limitations is client management.
    What problems is the product solving and how is that benefiting you?
    On the policy and procedure side, Drata provides a centralized, structured system that makes it easy to create, organize, update, and track documentation. The built-in templates and automated workflows ensure that policies are not only well-documented but also consistently reviewed and acknowledged by the appropriate team members. Instead of chasing approvals or wondering whether a policy is current, we now have clear visibility into ownership, version control, and review cycles.

    When it comes to vendor management, Drata gives us a single source of truth for all third-party relationships. We can track due diligence documentation, risk assessments, contract renewals, and ongoing monitoring requirements in one place. Automated reminders and continuous monitoring help ensure that no vendor falls through the cracks, significantly reducing risk and manual administrative effort.
    Jeremy M.

    Drata Made SOC 2 Type 2 Simple with Easy Setup and Strong Integrations

    Reviewed on Feb 19, 2026
    Review provided by G2
    What do you like best about the product?
    Drata simplified the process of attaining the SOC 2 Type 2 and works well with integrations. Easy to use, easy implementation, Good Support, its used every day, and has good features.
    What do you dislike about the product?
    I wish it had more integrations as we have many
    What problems is the product solving and how is that benefiting you?
    Drata helped us manage and attaining our SOC 2 Type 2
    Information Technology and Services

    Drata Makes Continuous Audit Readiness Easy with Real-Time Compliance Visibility

    Reviewed on Feb 19, 2026
    Review provided by G2
    What do you like best about the product?
    I like how Drata automates compliance and provides real-time visibility, making audit readiness continuous instead of manual and stressful.
    What do you dislike about the product?
    Sometimes the UI can feel overwhelming, and certain integrations or customizations require more manual effort than expected.
    What problems is the product solving and how is that benefiting you?
    Drata helps automate and streamline the SOC 2 compliance process by continuously collecting evidence, monitoring controls, and keeping us audit-ready, which saves time, reduces manual effort, and lowers compliance risk.
    Sheldon J.

    SOC2 Compliance with a little help from our friends.

    Reviewed on Feb 19, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best is the Integration with MS365, CERTN, Defender, Meraki ect. the automation makes it easier to manage several endpoints and users.
    What do you dislike about the product?
    Clearly defined policy renewal steps should be given prior to renewal, simply renewing a policy without updates changes the version of the document eg: 1.1, 1.2 and the tables inside don't reflect the changes. there's no point in doing the renew without updates as the table below has not reflected the version change.
    What problems is the product solving and how is that benefiting you?
    We required SOC2TII to continue doing business with our banking partners. It was critical that we chose a partner who can best help us acheive this in a timely and effective manner. Drata has been a great partner to help us do that.
    View all reviews