Prompt Support, Effortless Access
What do you like best about the product?
I like how quickly Drata responded and how polite they were. It was also easy to contact customer support since the button was right at the top, and they responded immediately. Additionally, the initial setup of Drata was very easy for me.
What do you dislike about the product?
Nothing I can think of
What problems is the product solving and how is that benefiting you?
Drata solved my email authorization issue and allowed me to access my account easily. The customer service was quick, helpful, and polite, making it easy to contact support when needed.
Centralized audits and policies have transformed how our team manages compliance workflows
What is our primary use case?
I am an end user of
Drata. Most of the time I work with
Drata for control mapping, uploading evidence, and sometimes risk management and the Policy Center, such as uploading policies. Those are mainly the features that I work with most of the time.
I primarily do internal audit support with Drata. Drata has been really helpful in terms of centralizing audit evidence. During the traditional audit method, you would have to send evidence via emails. With Drata, everything is centralized, and once external auditors have access to the system, they are able to review everything within a centralized tool. They are also able to download the evidence in a package form and review it. Having to upload policies in one centralized system has been feasible and most effective. Drata has the feature of Policy Center where you are able to upload all the policies within the company and they can be published from there. They can also be acknowledged by employees and approved by policy owners.
What is most valuable?
I think the tool having the ability to centralize most of the things is one of the most good things about Drata because when you do things that are scattered, managing policies from another tool and managing evidence collection during audits from another tool becomes difficult. Drata has Audit Hub where you can actually do the audit and when a control has been audited and prepared, you can mark it as complete within the system. With Drata having those capabilities as a
GRC tool, I think it has most of the capabilities that are needed within
GRC. We do not need to be purchasing other third-party tools. Though they might be needed, it is most useful that most of the work can be performed within the tool without having multiple third parties.
Currently, we have a dashboard in Drata. The dashboards go with admin access and relevant access that you need. With the views that I have, I am able to see all the frameworks that we are compliant with. I am able to see if there are certain controls that are not yet fulfilled. It will show that out of 60 controls, 23 is fulfilled and the rest is not fulfilled. That feature is helpful so that you are able to see that when it is 100%, it means you are compliant.
Overall, Drata as a tool has brought a lot of improvements within the GRC team. Having to centralize everything in one system, mapping the controls within one system, performing audits within one system, monitoring policies within one system, and doing risk management within one system is something that in GRC, speaking from a GRC perspective in cybersecurity, has been very impactful and effective within the team.
What needs improvement?
At the moment, integrating Drata with other AIs would be beneficial. I am not too sure if it is something that can be done or if it is possible, but I am not aware. Integrating it with AI where maybe with regards to evidence collection, I would not have to be collecting the evidence manually would be helpful. When you are managing a lot of frameworks, it is a lot of work to actually individually and manually upload all the evidence in Drata. If maybe there is an AI which can be able to automate that kind of a workflow, and obviously as human beings, we will have to do a human error check, I think it would be amazing. I am not too sure if maybe at the moment it is something that is in place and I am not aware of, but I think it would be great.
Integrations within my team are managed by someone, but I do have an idea about Drata's automated control monitoring. For example, with tests, there are certain systems such as AWS that has been integrated with Drata, and it tests those systems and puts them as part of evidence. For example, data encryption at rest. We can put it a test and integrate it with AWS, and then it will automatically test the encryption in data at rest. If the test has failed, you will see it. When I log in to check all the controls that have failed, it will show on Drata that the test has failed. Then I will be able to coordinate with the relevant stakeholders and tell them that it needs to be fixed.
I would like Drata to make the user interface more intuitive.
For how long have I used the solution?
I joined SUSE in October 2024, and we started using Drata from May of last year.
What do I think about the stability of the solution?
Drata has been an 8 in terms of stability and reliability for me so far.
There was one instance where our auditors could not access the Audit Hub in Drata, and it was not really something that was wrong from our company side. It was something wrong with Drata. Technical issues do occur. Speaking with them, it took a bit longer than we expected, and we were during the audit process and auditors had to audit, so we had to switch and do it the traditional way without using the tool. However, it was not really that too long.
What do I think about the scalability of the solution?
Drata is a 9 in terms of scalability.
How are customer service and support?
I do not communicate with the technical support of Drata. I am copied in the emails during the conversations, but I am not the one who is handling the overall support. As part of the GRC team, I am just there for visibility to see what the status of the issues is, but I am not the one who is handling the overall issues.
How would you rate customer service and support?
How was the initial setup?
I was there to do reviews regarding Drata. The setup and the integration of the systems itself was not really done by me, but I was there to review the features and when we do the control mappings and uploading things, I was there to actually see if it was a user-friendly app and if it was understandable.
Which other solutions did I evaluate?
I know there is SafetyCulture. It is also for compliance and project management, but it is not really the same as Drata. I would say Drata outperforms it.
What other advice do I have?
From my experience with Drata, if maybe for someone who is entry-level or who is not really too technical, they would not really understand some of the things. For someone who is not really technical, some of the terms they would not understand. However, overall, it is understandable and clear and comprehensive.
Drata has official documentation, guides, and manuals. I think it is going to depend on who is doing the integration. If Drata has that feature, it means it is something that is possible. From my experience, there have been some integrations that have been made and they were a success. Sometimes they do fail because of maybe the problem, it might be with Drata or it might be with the third-party tool that it has been integrated with. However, overall, with my experience having gone through some of the controls, the integrations have been a success.
At the moment, the ones that I know that Drata has been integrated with are AWS and Qualys. I do not use any tools from Drata's 75 plus integrations overall.
I would give this review a rating of 10.
Drata Made SOC 2 Type 2 Simple with Easy Setup and Strong Integrations
What do you like best about the product?
Drata simplified the process of attaining the SOC 2 Type 2 and works well with integrations. Easy to use, easy implementation, Good Support, its used every day, and has good features.
What do you dislike about the product?
I wish it had more integrations as we have many
What problems is the product solving and how is that benefiting you?
Drata helped us manage and attaining our SOC 2 Type 2
Drata Makes Continuous Audit Readiness Easy with Real-Time Compliance Visibility
What do you like best about the product?
I like how Drata automates compliance and provides real-time visibility, making audit readiness continuous instead of manual and stressful.
What do you dislike about the product?
Sometimes the UI can feel overwhelming, and certain integrations or customizations require more manual effort than expected.
What problems is the product solving and how is that benefiting you?
Drata helps automate and streamline the SOC 2 compliance process by continuously collecting evidence, monitoring controls, and keeping us audit-ready, which saves time, reduces manual effort, and lowers compliance risk.
SOC2 Compliance with a little help from our friends.
What do you like best about the product?
What I like best is the Integration with MS365, CERTN, Defender, Meraki ect. the automation makes it easier to manage several endpoints and users.
What do you dislike about the product?
Clearly defined policy renewal steps should be given prior to renewal, simply renewing a policy without updates changes the version of the document eg: 1.1, 1.2 and the tables inside don't reflect the changes. there's no point in doing the renew without updates as the table below has not reflected the version change.
What problems is the product solving and how is that benefiting you?
We required SOC2TII to continue doing business with our banking partners. It was critical that we chose a partner who can best help us acheive this in a timely and effective manner. Drata has been a great partner to help us do that.
Intuitive Compliance Platform with Excellent Support
What do you like best about the product?
I like that Drata is intuitive and serves as a central repository for connecting platforms and collecting audit-ready information. The platform is easy to set up, which is really helpful for someone like me who doesn't know what I’m doing. Also, the team is good and helpful, which I find really useful. I also have many tools integrated into Drata.
What do you dislike about the product?
An audit is a heavy lift, maybe a little more hands-on offerings?
What problems is the product solving and how is that benefiting you?
I use Drata as a central repository for connecting platforms and collecting audit-ready information. The intuitive platform helps me when I'm unsure, and the supportive team is really useful.
Streamlined Compliance with Exceptional Support
What do you like best about the product?
I find Drata's UI easy to use, and their support team is sharp and quick to reply. They have incredible integration capabilities, and as a small, lean startup team, Drata has been an excellent investment to achieve compliance. I also appreciate that we don't need prior knowledge to onboard thanks to their great guides that help us focus on what matters most. The initial setup of Drata was very easy, offering a great onboarding experience.
What do you dislike about the product?
The policy review process is lengthy in terms of steps. We manage our policies outside in Notion to allow for collaboration. It would be great if they could have a 'change request' that's comment-driven, reducing the back and forth across different tools to support collaboration.
What problems is the product solving and how is that benefiting you?
I use Drata for compliance management, handling everything from framework selection to monitoring and integrating with various tools. Its UI is user-friendly, and the integration and support are excellent. It manages policies, audit logs, and ensures a solid paper trail for SOC 2.
Drata Simplifies Certification Effortlessly
What do you like best about the product?
As someone who's been doing certification before without Drata, it's simplify the process so much.
What do you dislike about the product?
To be honest, not much that I dislike, I think the system is very nice
What problems is the product solving and how is that benefiting you?
Drata really helps me be on track with my evidence collections and controls
Effortless Compliance Management and Auditing
What do you like best about the product?
I think one of Drata's key strengths is its ability to perform framework mapping across compliance frameworks, which greatly reduces redundant work and duplicate work. I also appreciate its monitoring capabilities. Drata provides timely system updates on governance risk and compliance processes, making them more efficient and significantly less burdensome.
What do you dislike about the product?
I would like to be able to manipulate their dashboards a little better, just so I could cater it specifically to what our company needs to see, especially for generating reports to leadership.
What problems is the product solving and how is that benefiting you?
Drata automates our compliance status for risk management and auditing, gives us a clear view of our security posture, identifies real-time risks, and excels in framework mapping across compliance frameworks, reducing redundant work.
Streamlined SOC2 Compliance, Intuitive and Effective
What do you like best about the product?
I appreciate how Drata keeps everything organized, from evidence and compliance to risk management, making it the key to everything. The interface is always improving, becoming smarter and easier to use, which is great since I am in it every day working on compliance. What I really like is how the interface actively guides me through compliance work by linking controls, policies, and integrations together. It lets me see what's wrong, what's missing, why it matters, and how to fix it. The setup process is very intuitive as well, allowing me to add and remove vendors, policies, and connections easily. Drata was essential in obtaining our first SOC2 certification and continues to be invaluable in maintaining it. I can't imagine how challenging it would be to organize everything without Drata.
What do you dislike about the product?
I always seem to struggle when it comes to the hardware. I feel that workstations could be reported on a little better. Same for people. When looking at people, and seeing their compliance tasks overdue, like policies, it feels a bit convoluted.
What problems is the product solving and how is that benefiting you?
I use Drata for maintaining our SOC2 compliance. It organizes our evidence, policies, and more in one place. The interface guides compliance work actively, linking controls and policies. I can't imagine organizing SOC2 without it.