External reviews
1,140 reviews
from
and
External reviews are not included in the AWS star rating for the product.
Drata Streamlined Our Policy and Vendor Management for Audit Readiness
What do you like best about the product?
We’ve had an incredibly positive experience with Drata. Implementing their platform has been a game-changer for our organization, especially when it comes to getting our policies, procedures, and vendor management processes structured and audit-ready.
Before Drata, many of our compliance-related documents lived in different places, and maintaining consistency across policies was time-consuming. Drata gave us a centralized, intuitive system to build, organize, and maintain our policies and procedures. The pre-built templates and automated reminders helped ensure nothing fell through the cracks, and version control made updates seamless. What used to take weeks of coordination is now streamlined into a clear, trackable workflow.
Vendor management has also improved dramatically. Drata’s vendor tracking and risk management features give us a single source of truth for all third-party relationships. We can easily monitor due diligence documentation, review timelines, and risk classifications without relying on scattered spreadsheets. This has not only strengthened our compliance posture but also given leadership better visibility into vendor risk.
Before Drata, many of our compliance-related documents lived in different places, and maintaining consistency across policies was time-consuming. Drata gave us a centralized, intuitive system to build, organize, and maintain our policies and procedures. The pre-built templates and automated reminders helped ensure nothing fell through the cracks, and version control made updates seamless. What used to take weeks of coordination is now streamlined into a clear, trackable workflow.
Vendor management has also improved dramatically. Drata’s vendor tracking and risk management features give us a single source of truth for all third-party relationships. We can easily monitor due diligence documentation, review timelines, and risk classifications without relying on scattered spreadsheets. This has not only strengthened our compliance posture but also given leadership better visibility into vendor risk.
What do you dislike about the product?
Overall, our experience with Drata has been very positive, particularly around vendor management, and policy management. However, one area where we’ve felt some limitations is client management.
What problems is the product solving and how is that benefiting you?
On the policy and procedure side, Drata provides a centralized, structured system that makes it easy to create, organize, update, and track documentation. The built-in templates and automated workflows ensure that policies are not only well-documented but also consistently reviewed and acknowledged by the appropriate team members. Instead of chasing approvals or wondering whether a policy is current, we now have clear visibility into ownership, version control, and review cycles.
When it comes to vendor management, Drata gives us a single source of truth for all third-party relationships. We can track due diligence documentation, risk assessments, contract renewals, and ongoing monitoring requirements in one place. Automated reminders and continuous monitoring help ensure that no vendor falls through the cracks, significantly reducing risk and manual administrative effort.
When it comes to vendor management, Drata gives us a single source of truth for all third-party relationships. We can track due diligence documentation, risk assessments, contract renewals, and ongoing monitoring requirements in one place. Automated reminders and continuous monitoring help ensure that no vendor falls through the cracks, significantly reducing risk and manual administrative effort.
Drata Made SOC 2 Type 2 Simple with Easy Setup and Strong Integrations
What do you like best about the product?
Drata simplified the process of attaining the SOC 2 Type 2 and works well with integrations. Easy to use, easy implementation, Good Support, its used every day, and has good features.
What do you dislike about the product?
I wish it had more integrations as we have many
What problems is the product solving and how is that benefiting you?
Drata helped us manage and attaining our SOC 2 Type 2
Drata Makes Continuous Audit Readiness Easy with Real-Time Compliance Visibility
What do you like best about the product?
I like how Drata automates compliance and provides real-time visibility, making audit readiness continuous instead of manual and stressful.
What do you dislike about the product?
Sometimes the UI can feel overwhelming, and certain integrations or customizations require more manual effort than expected.
What problems is the product solving and how is that benefiting you?
Drata helps automate and streamline the SOC 2 compliance process by continuously collecting evidence, monitoring controls, and keeping us audit-ready, which saves time, reduces manual effort, and lowers compliance risk.
SOC2 Compliance with a little help from our friends.
What do you like best about the product?
What I like best is the Integration with MS365, CERTN, Defender, Meraki ect. the automation makes it easier to manage several endpoints and users.
What do you dislike about the product?
Clearly defined policy renewal steps should be given prior to renewal, simply renewing a policy without updates changes the version of the document eg: 1.1, 1.2 and the tables inside don't reflect the changes. there's no point in doing the renew without updates as the table below has not reflected the version change.
What problems is the product solving and how is that benefiting you?
We required SOC2TII to continue doing business with our banking partners. It was critical that we chose a partner who can best help us acheive this in a timely and effective manner. Drata has been a great partner to help us do that.
Efficient Security Management with Robust Automation
What do you like best about the product?
I really like the automation and integrations that Drata provides. They help me manage information security and privacy much more easily, especially since we have limited resources. Drata significantly reduces manual effort and provides easy, actionable insights into areas that need fixing. The initial setup was pretty straightforward, and I also appreciate its seamless integration with tools like GitHub, Heroku, and Google Workspace.
What do you dislike about the product?
There's a few bits of clunky user flow - e.g. when a control is marked as 'not ready' it's not always clear why it's not ready. It would be better if there was a clear button that showed a step-by-step guide on how to fix something.
What problems is the product solving and how is that benefiting you?
Drata makes security management easier with limited resources by simplifying evidence collection for audits and compliance. Its automation and integrations reduce manual effort significantly and provide actionable insights into areas needing fixes.
Intuitive Compliance Platform with Excellent Support
What do you like best about the product?
I like that Drata is intuitive and serves as a central repository for connecting platforms and collecting audit-ready information. The platform is easy to set up, which is really helpful for someone like me who doesn't know what I’m doing. Also, the team is good and helpful, which I find really useful. I also have many tools integrated into Drata.
What do you dislike about the product?
An audit is a heavy lift, maybe a little more hands-on offerings?
What problems is the product solving and how is that benefiting you?
I use Drata as a central repository for connecting platforms and collecting audit-ready information. The intuitive platform helps me when I'm unsure, and the supportive team is really useful.
Streamlined Compliance with Exceptional Support
What do you like best about the product?
I find Drata's UI easy to use, and their support team is sharp and quick to reply. They have incredible integration capabilities, and as a small, lean startup team, Drata has been an excellent investment to achieve compliance. I also appreciate that we don't need prior knowledge to onboard thanks to their great guides that help us focus on what matters most. The initial setup of Drata was very easy, offering a great onboarding experience.
What do you dislike about the product?
The policy review process is lengthy in terms of steps. We manage our policies outside in Notion to allow for collaboration. It would be great if they could have a 'change request' that's comment-driven, reducing the back and forth across different tools to support collaboration.
What problems is the product solving and how is that benefiting you?
I use Drata for compliance management, handling everything from framework selection to monitoring and integrating with various tools. Its UI is user-friendly, and the integration and support are excellent. It manages policies, audit logs, and ensures a solid paper trail for SOC 2.
Be aware of their sales people,- Platform, Resources, and Documentation Are OK
What do you like best about the product?
The platform, resources, and documentation are ok.
What do you dislike about the product?
Be aware of their salespeople who overpromise and underdeliver (they promised us a letter signed by their CSM director that we could show to our prospects, saying that we have started the process of getting a certification). Their sales handover to the CSM was horrible. A lot of confusion, multiple contacts, and very little clarity.
They are not "holding your hand" through the process as they sell it out to be. They are also not for startups as they brand themselves to be.
They are not "holding your hand" through the process as they sell it out to be. They are also not for startups as they brand themselves to be.
What problems is the product solving and how is that benefiting you?
Is 27001 preparation
Drata Simplifies Certification Effortlessly
What do you like best about the product?
As someone who's been doing certification before without Drata, it's simplify the process so much.
What do you dislike about the product?
To be honest, not much that I dislike, I think the system is very nice
What problems is the product solving and how is that benefiting you?
Drata really helps me be on track with my evidence collections and controls
Good Control Mapping Across Different Frameworks
What do you like best about the product?
Good control mapping across different frameworks. Drata is easy to use and makes it simpler to manage certifications.
What do you dislike about the product?
Drata doesn’t support a Quality Management System. As a result, organizations with an ISO 9001 certificate can’t use the Drata Policy Management System as a single, central point for managing their policies.
What problems is the product solving and how is that benefiting you?
It helps us stay SOC 2, ISO 27001, and HIPAA certified with minimal effort.
showing 1 - 10