Listing Thumbnail

    Drata Security & Compliance Automation Platform

     Info
    Sold by: Drata 
    Deployed on AWS
    An AWS Security Competency Partner, Drata is a GRC solution that enables companies to continuously monitor security and compliance controls, automatically collect evidence needed for an audit, and manage and remediate risk. Drata also allows you to share your real-time compliance posture with prospects and customers to build trust and accelerate growth.
    4.8

    Overview

    Play video

    Drata's compliance automation platform integrates with hundreds of applications and systems to continuously monitor security controls and streamline over 20 compliance frameworks, standards, and regulations, such as SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and more. Drata integrates with 45+ AWS services and is a proud AWS Security Competency partner with an AI engine built on AWS Bedrock.

    Whether you're looking to get compliant quickly for the first time or want to streamline your complex GRC program, Drata scales with you. Get and stay compliant efficiently, build risk management into your GRC practice, and share your real-time compliance posture with prospects and customers to build trust and sell into new markets.

    Continuous automated monitoring alerts Drata customers when security controls aren't operating effectively to remediate, stay secure, and keep from falling out of compliance. Plus, automatic evidence collection makes the audit process as seamless as possible.

    For custom pricing, EULA, or a private contract, please contact AWS-Marketplace@drata.com , for a private offer.

    Highlights

    • Drata for Startups: Drata helps startups create a scalable foundation and systematic approach to compliance to unlock market opportunities and scale safely. Startups can speed up audit prep time with Drata's best-in-class automation and support from our compliance experts to achieve SOC 2 and ISO 27001 compliance quickly.
    • Drata for Commercial and Mid Market: Drata helps companies with audit experience establish a scalable GRC program and structured process for risk management. Streamline compliance tasks and substantially reduce manual workloads while leveraging compliance to increase revenue and build trust.
    • Drata for Enterprise: Customers can optimize and customize their mature GRC programs and depend on reliable compliance outcomes. Organizations can manage and remediate risk and leverage Drata workspaces and workflows to keep pace with the complexity of advanced compliance programs.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Drata Security & Compliance Automation Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    Foundation Package for 1-50 FTE Companies
    List price for 1-50 FTE Company
    $15,000.00

    Vendor refund policy

    All Orders are non-cancellable and all fees and other amounts you pay under this Agreement are non-refundable.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    Included in your contract, Drata provides onboarding, live chat (in product), and continuous enablement. Onboarding includes integration setup, assistance configuring compliance policy and controls in the platform, and guidance on utilizing our network of auditors and technology/service partners to serve you in your compliance journey. support@drata.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Centralized Risk Management, Compliance and Auditing, Security
    Top
    10
    In Centralized Risk Management, Compliance and Auditing, Security
    Top
    10
    In Legal & Compliance, Compliance and Auditing

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Multi-Framework Compliance Support
    Streamlines over 20 compliance frameworks, standards, and regulations including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    Continuous Automated Monitoring
    Continuously monitors security controls across integrated applications and systems with automated alerts when controls are not operating effectively
    AWS Service Integration
    Integrates with 45+ AWS services and utilizes an AI engine built on AWS Bedrock
    Automated Evidence Collection
    Automatically collects evidence required for audit processes to streamline audit preparation
    Real-Time Compliance Posture Visibility
    Provides real-time compliance posture tracking and reporting capabilities for risk management and remediation
    Compliance Framework Automation
    Automates evidence collection and monitoring across 35+ compliance frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CMMC, CJIS, NIST 800-53/171, and FedRAMP
    Cloud Service Integration
    Provides deep integrations across 40+ AWS services with real-time visibility into cloud security and compliance posture in AWS-native environments
    AI-Powered Task Management
    Includes AI Agent functionality for intelligent task management, smart recommendations, audit-ready documentation generation, and real-time responses to audit requirements
    Centralized GRC Workflows
    Centralizes governance, risk, and compliance workflows including risk management, vendor management, centralized access reviews, and real-time audit trails
    Custom Automated Testing
    Supports custom automated tests built directly in-platform or via API for self-hosted and custom-built systems
    Compliance Framework Support
    Supports 30+ compliance frameworks including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, PCI DSS, and POPIA
    Automated Evidence Collection
    Automated evidence collection with continuous control monitoring and auditor-approved policy templates
    Vendor Risk Management
    Vendor risk management and automated user access reviews capabilities
    Cloud Integration
    Seamless integration with 30+ AWS services including Security Hub, Config, and CloudTrail, plus over 100 cloud integrations
    Continuous Monitoring
    24/7 continuous monitoring for real-time compliance posture visibility

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    No security profile
    -
    -
    -
    -
    -
    -
    -
    -
    -

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.8
    1138 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    87%
    12%
    0%
    0%
    0%
    6 AWS reviews
    |
    1132 external reviews
    External reviews are from G2  and PeerSpot .
    Information Services

    Good Control Mapping Across Different Frameworks

    Reviewed on Feb 02, 2026
    Review provided by G2
    What do you like best about the product?
    Good control mapping across different frameworks. Drata is easy to use and makes it simpler to manage certifications.
    What do you dislike about the product?
    Drata doesn’t support a Quality Management System. As a result, organizations with an ISO 9001 certificate can’t use the Drata Policy Management System as a single, central point for managing their policies.
    What problems is the product solving and how is that benefiting you?
    It helps us stay SOC 2, ISO 27001, and HIPAA certified with minimal effort.
    Arther M.

    Streamlined Compliance with Automated Evidence Collection

    Reviewed on Jan 29, 2026
    Review provided by G2
    What do you like best about the product?
    I use Drata for my GRC program including ISO27001, SOC2, GDPR, and Cyberessentials. I appreciate having better visibility of my controls and risks all in a single console. I like the ability to integrate with my tech stack with automated evidence collection. I don't have to log into AWS and Google Workspace to check compliance as everything is visible from Drata connections. The automation of evidence collection for SOC2 is what made us switch from Rubiq.
    What do you dislike about the product?
    The asset management module could be improved to generate a consolidated report. It currently doesn’t display device serial numbers and make, which are useful identifiers for an asset list. The serial numbers can only be seen when downloading a report for an individual, not for the entire company. I’d prefer Drata to have out-of-the-box modules like incident management to avoid purchasing a separate solution. Having an incident management report and a business continuity flow would greatly enhance Drata. Also, the integrations with Zoho Desk have been buggy since last year, and the issue remains unresolved despite logging a ticket about it.
    What problems is the product solving and how is that benefiting you?
    With Drata, I have better visibility of my controls and risks on a single console. I also like the integration with my tech stack and automated evidence collection, which means I don't have to log in to AWS and Google Workspace to check compliance.
    Kevin J.

    Effortless Compliance Management and Auditing

    Reviewed on Jan 16, 2026
    Review provided by G2
    What do you like best about the product?
    I think one of Drata's key strengths is its ability to perform framework mapping across compliance frameworks, which greatly reduces redundant work and duplicate work. I also appreciate its monitoring capabilities. Drata provides timely system updates on governance risk and compliance processes, making them more efficient and significantly less burdensome.
    What do you dislike about the product?
    I would like to be able to manipulate their dashboards a little better, just so I could cater it specifically to what our company needs to see, especially for generating reports to leadership.
    What problems is the product solving and how is that benefiting you?
    Drata automates our compliance status for risk management and auditing, gives us a clear view of our security posture, identifies real-time risks, and excels in framework mapping across compliance frameworks, reducing redundant work.
    Zeyd Taha C.

    User-Friendly Compliance Platform with Helpful Templates and Resources

    Reviewed on Jan 16, 2026
    Review provided by G2
    What do you like best about the product?
    Drata is very user-friendly and offers a great platform that provides all the necessary information and templates to get started with anything related to compliance, even for startups.
    What do you dislike about the product?
    At the beginning, it can feel a bit overwhelming, but they offer so many resources and onboarding calls that it quickly feels manageable again.
    What problems is the product solving and how is that benefiting you?
    Drata helps us keep everything related to compliance in one place, and it automatically reminds us to renew policies when needed.
    Dave R.

    Streamlined SOC2 Compliance, Intuitive and Effective

    Reviewed on Jan 15, 2026
    Review provided by G2
    What do you like best about the product?
    I appreciate how Drata keeps everything organized, from evidence and compliance to risk management, making it the key to everything. The interface is always improving, becoming smarter and easier to use, which is great since I am in it every day working on compliance. What I really like is how the interface actively guides me through compliance work by linking controls, policies, and integrations together. It lets me see what's wrong, what's missing, why it matters, and how to fix it. The setup process is very intuitive as well, allowing me to add and remove vendors, policies, and connections easily. Drata was essential in obtaining our first SOC2 certification and continues to be invaluable in maintaining it. I can't imagine how challenging it would be to organize everything without Drata.
    What do you dislike about the product?
    I always seem to struggle when it comes to the hardware. I feel that workstations could be reported on a little better. Same for people. When looking at people, and seeing their compliance tasks overdue, like policies, it feels a bit convoluted.
    What problems is the product solving and how is that benefiting you?
    I use Drata for maintaining our SOC2 compliance. It organizes our evidence, policies, and more in one place. The interface guides compliance work actively, linking controls and policies. I can't imagine organizing SOC2 without it.
    View all reviews