External reviews
1,136 reviews
from
and
External reviews are not included in the AWS star rating for the product.
Drata Made SOC 2 Type 2 Simple with Easy Setup and Strong Integrations
What do you like best about the product?
Drata simplified the process of attaining the SOC 2 Type 2 and works well with integrations. Easy to use, easy implementation, Good Support, its used every day, and has good features.
What do you dislike about the product?
I wish it had more integrations as we have many
What problems is the product solving and how is that benefiting you?
Drata helped us manage and attaining our SOC 2 Type 2
SOC2 Compliance with a little help from our friends.
What do you like best about the product?
What I like best is the Integration with MS365, CERTN, Defender, Meraki ect. the automation makes it easier to manage several endpoints and users.
What do you dislike about the product?
Clearly defined policy renewal steps should be given prior to renewal, simply renewing a policy without updates changes the version of the document eg: 1.1, 1.2 and the tables inside don't reflect the changes. there's no point in doing the renew without updates as the table below has not reflected the version change.
What problems is the product solving and how is that benefiting you?
We required SOC2TII to continue doing business with our banking partners. It was critical that we chose a partner who can best help us acheive this in a timely and effective manner. Drata has been a great partner to help us do that.
Intuitive Compliance Platform with Excellent Support
What do you like best about the product?
I like that Drata is intuitive and serves as a central repository for connecting platforms and collecting audit-ready information. The platform is easy to set up, which is really helpful for someone like me who doesn't know what I’m doing. Also, the team is good and helpful, which I find really useful. I also have many tools integrated into Drata.
What do you dislike about the product?
An audit is a heavy lift, maybe a little more hands-on offerings?
What problems is the product solving and how is that benefiting you?
I use Drata as a central repository for connecting platforms and collecting audit-ready information. The intuitive platform helps me when I'm unsure, and the supportive team is really useful.
Streamlined Compliance with Exceptional Support
What do you like best about the product?
I find Drata's UI easy to use, and their support team is sharp and quick to reply. They have incredible integration capabilities, and as a small, lean startup team, Drata has been an excellent investment to achieve compliance. I also appreciate that we don't need prior knowledge to onboard thanks to their great guides that help us focus on what matters most. The initial setup of Drata was very easy, offering a great onboarding experience.
What do you dislike about the product?
The policy review process is lengthy in terms of steps. We manage our policies outside in Notion to allow for collaboration. It would be great if they could have a 'change request' that's comment-driven, reducing the back and forth across different tools to support collaboration.
What problems is the product solving and how is that benefiting you?
I use Drata for compliance management, handling everything from framework selection to monitoring and integrating with various tools. Its UI is user-friendly, and the integration and support are excellent. It manages policies, audit logs, and ensures a solid paper trail for SOC 2.
Be aware of their sales people,- Platform, Resources, and Documentation Are OK
What do you like best about the product?
The platform, resources, and documentation are ok.
What do you dislike about the product?
Be aware of their salespeople who overpromise and underdeliver (they promised us a letter signed by their CSM director that we could show to our prospects, saying that we have started the process of getting a certification). Their sales handover to the CSM was horrible. A lot of confusion, multiple contacts, and very little clarity.
They are not "holding your hand" through the process as they sell it out to be. They are also not for startups as they brand themselves to be.
They are not "holding your hand" through the process as they sell it out to be. They are also not for startups as they brand themselves to be.
What problems is the product solving and how is that benefiting you?
Is 27001 preparation
Drata Simplifies Certification Effortlessly
What do you like best about the product?
As someone who's been doing certification before without Drata, it's simplify the process so much.
What do you dislike about the product?
To be honest, not much that I dislike, I think the system is very nice
What problems is the product solving and how is that benefiting you?
Drata really helps me be on track with my evidence collections and controls
Good Control Mapping Across Different Frameworks
What do you like best about the product?
Good control mapping across different frameworks. Drata is easy to use and makes it simpler to manage certifications.
What do you dislike about the product?
Drata doesn’t support a Quality Management System. As a result, organizations with an ISO 9001 certificate can’t use the Drata Policy Management System as a single, central point for managing their policies.
What problems is the product solving and how is that benefiting you?
It helps us stay SOC 2, ISO 27001, and HIPAA certified with minimal effort.
Streamlined Compliance with Automated Evidence Collection
What do you like best about the product?
I use Drata for my GRC program including ISO27001, SOC2, GDPR, and Cyberessentials. I appreciate having better visibility of my controls and risks all in a single console. I like the ability to integrate with my tech stack with automated evidence collection. I don't have to log into AWS and Google Workspace to check compliance as everything is visible from Drata connections. The automation of evidence collection for SOC2 is what made us switch from Rubiq.
What do you dislike about the product?
The asset management module could be improved to generate a consolidated report. It currently doesn’t display device serial numbers and make, which are useful identifiers for an asset list. The serial numbers can only be seen when downloading a report for an individual, not for the entire company. I’d prefer Drata to have out-of-the-box modules like incident management to avoid purchasing a separate solution. Having an incident management report and a business continuity flow would greatly enhance Drata. Also, the integrations with Zoho Desk have been buggy since last year, and the issue remains unresolved despite logging a ticket about it.
What problems is the product solving and how is that benefiting you?
With Drata, I have better visibility of my controls and risks on a single console. I also like the integration with my tech stack and automated evidence collection, which means I don't have to log in to AWS and Google Workspace to check compliance.
Effortless Compliance Management and Auditing
What do you like best about the product?
I think one of Drata's key strengths is its ability to perform framework mapping across compliance frameworks, which greatly reduces redundant work and duplicate work. I also appreciate its monitoring capabilities. Drata provides timely system updates on governance risk and compliance processes, making them more efficient and significantly less burdensome.
What do you dislike about the product?
I would like to be able to manipulate their dashboards a little better, just so I could cater it specifically to what our company needs to see, especially for generating reports to leadership.
What problems is the product solving and how is that benefiting you?
Drata automates our compliance status for risk management and auditing, gives us a clear view of our security posture, identifies real-time risks, and excels in framework mapping across compliance frameworks, reducing redundant work.
Streamlined SOC2 Compliance, Intuitive and Effective
What do you like best about the product?
I appreciate how Drata keeps everything organized, from evidence and compliance to risk management, making it the key to everything. The interface is always improving, becoming smarter and easier to use, which is great since I am in it every day working on compliance. What I really like is how the interface actively guides me through compliance work by linking controls, policies, and integrations together. It lets me see what's wrong, what's missing, why it matters, and how to fix it. The setup process is very intuitive as well, allowing me to add and remove vendors, policies, and connections easily. Drata was essential in obtaining our first SOC2 certification and continues to be invaluable in maintaining it. I can't imagine how challenging it would be to organize everything without Drata.
What do you dislike about the product?
I always seem to struggle when it comes to the hardware. I feel that workstations could be reported on a little better. Same for people. When looking at people, and seeing their compliance tasks overdue, like policies, it feels a bit convoluted.
What problems is the product solving and how is that benefiting you?
I use Drata for maintaining our SOC2 compliance. It organizes our evidence, policies, and more in one place. The interface guides compliance work actively, linking controls and policies. I can't imagine organizing SOC2 without it.
showing 1 - 10