Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Loading...
    Listing Thumbnail

    Drata Security & Compliance Automation Platform

     Info
    Sold by: Drata 
    Vendor Insights
    An AWS Security Competency Partner, Drata is a GRC automation solution that allows companies to continuously monitor security and compliance controls, automatically collect evidence needed for an audit, and manage and remediate risk. Drata streamlines common compliance frameworks like SOC 2, ISO 27001, GDPR, and more and allows you to share your real-time compliance posture with prospects and customers to build trust and accelerate growth.
    Listing Thumbnail

    Drata Security & Compliance Automation Platform

     Info
    Sold by: Drata 

    Overview

    Play video

    Drata's compliance automation platform integrates with over 200 applications and systems to continuously monitor security controls and streamline over 20 compliance frameworks, standards, and regulations, such as SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and more. Drata integrates with 45+ AWS services and is a proud AWS Security Competency partner with an AI engine built on AWS Bedrock.

    Whether you're looking to get compliant quickly for the first time or want to streamline your complex GRC program, Drata scales with you. Get and stay compliant efficiently, build risk management into your GRC practice, and share your real-time compliance posture with prospects and customers to build trust and sell into new markets.

    Continuous automated monitoring alerts Drata customers when security controls aren't operating effectively to remediate, stay secure, and keep from falling out of compliance. Plus, automatic evidence collection makes the audit process as seamless as possible.

    Highlights

    • Drata for Startups: Drata helps startups create a scalable foundation and systematic approach to compliance to unlock market opportunities and scale safely. Startups can speed up audit prep time with Drata's best-in-class automation and support from our compliance experts to achieve SOC 2 and ISO 27001 compliance quickly.
    • Drata for Commercial and Mid Market: Drata helps companies with audit experience establish a scalable GRC program and structured process for risk management. Streamline compliance tasks and substantially reduce manual workloads while leveraging compliance to increase revenue and build trust.
    • Drata for Enterprise: Customers can optimize and customize their mature GRC programs and depend on reliable compliance outcomes. Organizations can manage and remediate risk and leverage Drata workspaces and workflows to keep pace with the complexity of advanced compliance programs.

    Details

    Sold by

    Delivery method

    Features and programs

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Drata Security & Compliance Automation Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.

    12-month contract (16)

     Info
    Dimension
    Description
    Cost/12 months
    Drata Platform Fee
    Access to the Drata SaaS platform with capacity for a 100 FTE org
    $25,000.00
    SOC 2 Framework
    SOC 2 2017 control set
    $7,500.00
    GDPR Framework
    GDPR control set
    $7,500.00
    ISO 27001 Framework
    ISO 27001 v2022 control set
    $7,500.00
    HIPAA Framework
    HIPAA control set
    $7,500.00
    PCI DSS Framework
    PCI DSS control set
    $7,500.00
    CCPA Framework
    CCPA control set
    $7,500.00
    CMMC Framework
    CMMC control set
    $7,500.00
    Microsoft SSPA Framework
    Microsoft SSPA control set
    $7,500.00
    NIST CSF Framework
    NIST CSF control set
    $7,500.00

    Vendor refund policy

    All Orders are non-cancellable and all fees and other amounts you pay under this Agreement are non-refundable.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    Included in your contract, Drata provides onboarding, live chat (in product), and continuous enablement. Onboarding includes integration setup, assistance configuring compliance policy and controls in the platform, and guidance on utilizing our network of auditors and technology/service partners to serve you in your compliance journey. support@drata.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Centralized Risk Management
    Top
    25
    In IT Business Management
    Top
    10
    In Compliance and Auditing, Monitoring

    Customer reviews

     Info
    AI generated sentiment from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Compliance Framework Support
    Supports continuous monitoring and automation for over 20 compliance standards including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    Application Integration
    Integrates with over 200 applications and systems for comprehensive security control monitoring
    Cloud Service Compatibility
    Native integration with 45+ AWS services and built on AWS Bedrock AI engine
    Automated Evidence Collection
    Automatically collects compliance evidence and provides continuous security control monitoring
    Risk Management Automation
    Provides continuous automated monitoring with real-time alerts for security control effectiveness and potential compliance deviations
    Compliance Framework Support
    Supports multiple global security and privacy compliance standards including SOC 2, ISO 27001, HIPAA, GDPR, CCPA, NIST frameworks, CMMC, and PCI DSS
    Cloud Service Integrations
    Provides over 100 automated integrations with cloud services like AWS, Azure, Google Cloud, G Suite, GitHub, Okta, and Slack for continuous evidence collection and infrastructure monitoring
    Machine Learning Questionnaire Processing
    Utilizes machine learning to automate RFP and security questionnaire completion by generating responses based on approved past answers
    Continuous Security Monitoring
    Performs automated tests, continuous infrastructure monitoring, and nonconformity detection across cloud environments
    Risk and Compliance Management
    Offers comprehensive risk management capabilities including personnel and asset inventory, vendor risk management, risk register, and enterprise policy management
    Compliance Framework Support
    Supports multiple compliance frameworks including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, PCI DSS, and POPIA
    Automated Evidence Collection
    Enables automated evidence collection and continuous control monitoring across security workflows
    Cloud Integration Capabilities
    Seamless integration with 30+ AWS services and over 100 cloud platform integrations
    Continuous Monitoring
    Provides 24/7 continuous monitoring with capability to reduce time to compliance by up to 90%
    Security Control Management
    Offers automated user access reviews, vendor risk management, and centralized security and compliance workflow management

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    No security profile
    -
    -
    -
    -

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    3
    4 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    50%
    0%
    0%
    0%
    50%
    4 AWS reviews
    |
    1005 external reviews
    External reviews are sourced from G2  and are not included in the star rating for this product.
    Afiq A.

    Streamlined Compliance Made Easy

    Reviewed on Apr 07, 2025
    Review provided by G2
    What do you like best about the product?
    Drata makes compliance tracking incredibly simple and efficient. The automated workflows and integrations with tools like Google Workspace, AWS, and Slack save a lot of manual effort. The dashboard is clean and easy to navigate, making it easy to stay on top of tasks and audits.
    What do you dislike about the product?
    Some of the integrations require a bit of fine-tuning during the initial setup, and occasional sync delays can happen. A mobile app would also be a great addition for on-the-go access.
    What problems is the product solving and how is that benefiting you?
    Drata helps streamline and automate our security compliance processes, reducing the need for manual tracking and documentation. It ensures that we're continuously meeting requirements for frameworks like SOC 2 by integrating with our existing tools and providing real-time monitoring. This saves time, minimizes human error, and keeps us audit-ready at all times.
    Computer Software

    Great product and best support

    Reviewed on Apr 04, 2025
    Review provided by G2
    What do you like best about the product?
    Drata has provided a great platform to begin our ISO-27001 journey. There are so many aspects of this certification and Drata has simplified it in many ways. We had so many questions regarding the policies, etc. and Drata has helped us enormously.
    What do you dislike about the product?
    The tool has some limitations- and one of the most annoying is the inability to store my list/filter settings in the controls, personnel, etc. We have so many people that for it to show only 20 items at a time is a waste of my time. Also, when I go to the controls, I sort by policy number, not alphabetical and I have to reset that *every* time I use the app.
    What problems is the product solving and how is that benefiting you?
    It's a one-stop for us to write the policies, have personnel acknowledge those, has security awareness training, and maps tasks/evidence to the policies via controls. This makes is so much easier to work through the requirements for ISO-27001. On top of it, it's very easy to see where we are missing something.
    Chris L.

    Drata makes compliance possible in the chaos of running a business...

    Reviewed on Apr 04, 2025
    Review provided by G2
    What do you like best about the product?
    As someone who used to do compliance manually, I love how Drata uses our vendors and systems to automate much of the data collection and organization of evidence. The support is always available for questions, and the dashboard and onboarding steps simplify implementation. They walk you through the steps with questions, and once you select your auditor, they know Drata as well and can help tie up any loose ends before starting an audit.
    What do you dislike about the product?
    There is no downside. They have integrations with all of our cloud, development and IDP systems.
    What problems is the product solving and how is that benefiting you?
    Drata collects the majotity of evidence needed for our SOC 2 and HIPAA and for the manual evidence, has reminders and places to store the manual evidence when it is collected.
    Consumer Services

    had a quick question and was helped immediately with great service

    Reviewed on Mar 28, 2025
    Review provided by G2
    What do you like best about the product?
    Easy to use - great support - very helpful and knowledgeable
    What do you dislike about the product?
    I sometimes get too into the details and miss how easy it is to actually use and track my needs
    What problems is the product solving and how is that benefiting you?
    I need to maintain a SOC2 certification and Drata makes it easy
    Dan L.

    Clarity and support that has helped us grow

    Reviewed on Mar 27, 2025
    Review provided by G2
    What do you like best about the product?
    Take what you will from that fact that I've enjoyed learning about and implementing these data privacy and security frameworks, but I attribute a lot of that enjoyment to the value we've gotten from working with Drata. They've been an essential partner in our startup’s growth, streamlining our GRC and compliance efforts with clarity, transparency, and exceptional support. Their platform makes it easy to navigate complex requirements, the Compliance Accelerator program has been a major asset in helping us quickly align with industry standards, and the integration with SafeBase’s Trust Center has elevated how we can communicate our security posture—clean, modern, and confidence-inspiring for both prospective partners and customers. Their documentation is extensive and accessible, the onboarding and implementation process was quick and clear, and their support team has always been responsive and genuinely helpful.
    What do you dislike about the product?
    I don't think there's anything I actively dislike. The help guides could probably be structured more clearly with subheadings/highlights, some of the large tables could be better formatted for either dynamic resizing or pop-out windows, and the help docs overall could use a bit more branded visual flair or character, but that's pretty minor all things considered.
    What problems is the product solving and how is that benefiting you?
    Demonstrating our security posture, helping us meet modern GRC requirements quickly, and supporting our ability to grow our business and customer base.
    View all reviews