Sold by
Drata Security & Compliance Automation Platform (D)
An AWS Security Competency Partner, Drata is a GRC automation solution that allows companies to continuously monitor security and compliance controls, automatically collect evidence needed for an audit, and manage and remediate risk. Drata streamlines common compliance frameworks like SOC 2, ISO 27001, GDPR, and more and allows you to share your real-time compliance posture with prospects and customers to build trust and accelerate growth.
Reviews (1349)
Emre Utku S.
Great framework for information security audits and overall compliance
Reviewed on Aug 07, 2026
Review provided by G2
What do you like best about the product?
I like the thoughtfully designed UI, the AI chatbot, and the relatively fast human support (special thanks to Terrious for exceptionally quick and accurate support). The integrations with other tools still have room for improvement, but overall, it’s been a better experience than some competitors. I also appreciate Drata Autopilot and how easy it is to quickly test integrations to confirm their capabilities and performance.
What do you dislike about the product?
There are some limitations in how the integrations are designed. With certain tools, the integrations leave you with very little control, and the available capabilities remain fairly high-level. In most cases, though, they make up for that with support.
That said, I think the scope of onboarding and the accelerator program is also too high-level. They help you collect some standard documents and fill in general fields in your Drata setup, but those aren’t the real pain points. They also provide generic policy templates. If you have zero policies in your business, you could try to implement what’s in those templates as your policies. However, if you already have policies in place, there’s little value in the provided templates.
If they took the time to understand your business and your current state, and then helped you align your existing policies with the requirements, that would make for a much better accelerator program experience. Overall, Drata is a great tool if you already know or understand what you need to do to achieve compliance, and it works well for us.
That said, I think the scope of onboarding and the accelerator program is also too high-level. They help you collect some standard documents and fill in general fields in your Drata setup, but those aren’t the real pain points. They also provide generic policy templates. If you have zero policies in your business, you could try to implement what’s in those templates as your policies. However, if you already have policies in place, there’s little value in the provided templates.
If they took the time to understand your business and your current state, and then helped you align your existing policies with the requirements, that would make for a much better accelerator program experience. Overall, Drata is a great tool if you already know or understand what you need to do to achieve compliance, and it works well for us.
What problems is the product solving and how is that benefiting you?
We’re working to comply with information security standards and obtain ISO 27001 certification, and Drata is giving us a solid framework for that journey. It’s been a great starting point and template for managing the entire process. It helped us save weeks of planning for our compliance project, and it will likely save us hundreds of hours over the long run, since most of the things can be managed through the platform—policies, vendor reviews, and other documents that are created once and then kept up to date, automated integrations with our tools (MDM, Infrastructure, HRIS, Identity, Version Control, etc.), annual trainings, and more.
That said, it's not a magic wand that reduces the time required to prepare for a certificate to 100 hours. It depends heavily on your company's compliance posture, and if you're a beginner, it'll likely take months to write your policies, review your vendors, set up your integrations, and remediate failing configurations by redefining your procedures and updating your policies, etc.
That said, it's not a magic wand that reduces the time required to prepare for a certificate to 100 hours. It depends heavily on your company's compliance posture, and if you're a beginner, it'll likely take months to write your policies, review your vendors, set up your integrations, and remediate failing configurations by redefining your procedures and updating your policies, etc.
Marc M.
Compliance with Drata
Reviewed on Jul 28, 2026
Review provided by G2
What do you like best about the product?
I feel like it's well organized. Also includes corporate documentation. That is a big help.
What do you dislike about the product?
There is a lot in there. Sometimes it's hard to find things.
What problems is the product solving and how is that benefiting you?
We're using it for SOCII and HIPAA compliance.
Information Technology and Services
Seamless Setup You Can Set and Forget
Reviewed on Jul 22, 2026
Review provided by G2
What do you like best about the product?
It’s seamless: you install it, set it up, and then forget about it. It only bothers you when you actually have an action item.
What do you dislike about the product?
I haven't experienced anything worth mentioning
What problems is the product solving and how is that benefiting you?
It is helping us enforcing security policies needed for soc2
Mohd Z.
practical solution for security and compliance.
Reviewed on Jul 20, 2026
Review provided by G2
What do you like best about the product?
Drata provides a clean and easy to use interface that makes compliance management less overwhelming. I like that it continuously monitors and send alerts when someone needs attention.
What do you dislike about the product?
One thing I don't like about Drata is that some integration requires additional setup, and troubleshooting them can take longer than expected
What problems is the product solving and how is that benefiting you?
Drata has helped us reduce the manual effort involved in compliance and security monitoring. instead of tracking controls and collecting evidence manually.
Information Technology and Services
Drata Makes SOC 2 Type II Requirements Clear with Knowledgeable Support
Reviewed on Jun 23, 2026
Review provided by G2
What do you like best about the product?
I’m a couple of years into my SOC 2 Type II journey, and I’ve really liked Drata for how they turn cryptic requests and requirements into clear, actionable to-dos. Their support team is extremely knowledgeable. I also appreciate the AI integrated into their documentation, which makes it really easy to find answers to common questions.
What do you dislike about the product?
The UI can sometimes be confusing. I've gotten lost trying to find data about former employees inside the Drata system. The filtering for controls is sometime unintuitive -- filtering and sorting should remembered in the browser URL. Sorting by control number should be the default.
What problems is the product solving and how is that benefiting you?
Drata is helping me with SOC 2 Type 2 audit. Helps me have an organized single pane of glass for both myself and auditors
Sports
Very User-Friendly Platform with Great Support and Sales Staff
Reviewed on Jun 19, 2026
Review provided by G2
What do you like best about the product?
Very user-friendly platform with a great support and sales staff.
What do you dislike about the product?
Nothing to dislike thus far. Im new to the product and its been great.
What problems is the product solving and how is that benefiting you?
The biggest problem solver ive witnessed is leveraging their AIQA to assist with questionaires.
Computer Software
Very bad dont recomend at all
Reviewed on Jun 10, 2026
Review provided by G2
What do you like best about the product?
didnt like anything about the company specially the onboarding process we spent so much time on it
What do you dislike about the product?
sale process was a big lie they sell a very short process of onboarding but in fact it was a very long we spent so much resources on it
What problems is the product solving and how is that benefiting you?
sapuse to solve speed up maintenance and control of regulation in practice its make more work
Anonymous
Effortless Compliance with Stellar Support
Reviewed on Jun 09, 2026
Review provided by G2
What do you like best about the product?
I like that Drata helps me with getting ISO 27001 by working as a checklist. The interface and integrations work really well, which I find valuable. It's easy to use and offers clear progress tracking, which allows us to scope tasks efficiently. The customer support is great, as demonstrated when Terrious helped me with the Orca integration issue.
What do you dislike about the product?
The Orca integration was not working but Terrious managed to help me. Support was great
What problems is the product solving and how is that benefiting you?
I use Drata to help me get ISO 27001. It works as a checklist, is easy to use, provides clear progress tracking, and allows us to scope tasks effectively. The interface and integrations work really well.
Computer & Network Security
Simple, Straightforward Design with Engaging Gamification
Reviewed on Jun 08, 2026
Review provided by G2
What do you like best about the product?
Simple & straight forward design. Easy to understand what I need to do. And what's my responsibility. Easy to sign and consume info. I like the gamification as well.
What do you dislike about the product?
Sometimes it's difficult to understand just how much signatures one need to go through, it's duteous and tiring to go over paper works- especailly important ones. So I'd have loved to have a AI summary or maybe highlighting of certain areas that I would need to focus on.
What problems is the product solving and how is that benefiting you?
Solving managing the security tasks - set by our CISO and making sure everyone signed all the relevant paperwork. Team accountablility
Anonymous
Effortless Compliance with Room for Improvement in Collaboration
Reviewed on Jun 08, 2026
Review provided by G2
What do you like best about the product?
I use Drata for security and compliance, especially for policy creation and ensuring SOC, HIPPA, and GDPR compliance. Drata is crucial in policy creation and control monitoring, making the process of policy creation easy and allowing us to account for all the controls needed for audits. The platform is very easy to use, with a user-friendly web UI and layout that makes navigation simple. I appreciate how well-organized everything is in the Drata UI, allowing me to see, acknowledge, and collaborate on policies effortlessly. It's intuitive and doesn't feel cumbersome like other platforms. Setting up Drata was also easy, and our representatives made the process smooth. This was my first experience with a compliance tool like Drata, but it was easy to learn, and I would definitely recommend it.
What do you dislike about the product?
The collaboration when drafting policy could be better. I've run into issues where multiple people working on the same policy end up conflicting with each other's edits. We tried using Word for live collaboration, but that was clumsy. A live editor would be a game changer! Also, versioning could be improved and more detailed. I think a feature to 'check out' a policy so it isn't editable by others could help avoid conflicts.
What problems is the product solving and how is that benefiting you?
I use Drata for easy policy creation and compliance with SOC, HIPPA, and GDPR. It simplifies policy creation, making it intuitive and organized for monitoring controls during audits.