Compare this with other toolsSave it to your board and evaluate your options side by side.
Save to board

Drata Reviews & Product Details

Value at a Glance

Averages based on real user reviews.

Time to Implement

2 months

Drata Media

Drata Demo - Drata's Automated Security Control Monitoring
Automated monitoring of your controls mapped to your framework
Drata Demo - Drata's SOC 2 Framework
Get audit ready with Drata's SOC 2 product. Drata gives you a single view of your security and compliance with 75+ deep integrations, automated monitoring and evidence collection, dashboards with real-time audit readiness, policy templates, compliance monitoring of your personnel, streamlined ven...
Drata Demo - Drata's Automated Security and Compliance Dashboard
With Drata's Dratameter and central dashboard, you will always know your overall control and requirement readiness.
Drata Demo - Drata's Open API
Drata’s Open API allows you to build and configure your security posture with flexible workflows, any integrations, and data exchanges. There is little to no code and the ability to connect to any solution—like security training solutions, background check providers, MDM systems, and more—to brin...
Drata Demo - Trust Center by Drata
Trust Center provides real-time transparency into your organization’s security posture. It seamlessly integrates with your website and allows you to publicly display security reports like vulnerability assessments and penetration test summaries, certifications and attestations like SOC 2, ISO 270...
Drata Demo - Risk Management
Drata's Risk Management is an integrated solution that helps you manage risk and compliance in one place.
Play Drata Video
Play Drata Video
Play Drata Video
Play Drata Video
Play Drata Video
Product Avatar Image

Have you used Drata before?

Answer a few questions to help the Drata community

Drata Reviews (1,157)

Reviews

Drata Reviews (1,157)

4.7
1,157 reviews

Review Summary

Generated using AI from real user reviews
Users consistently praise Drata for its ease of use and exceptional customer support, which simplifies the compliance process and enhances user experience. The platform's automation features significantly reduce manual effort, making it easier to maintain compliance and stay audit-ready. However, some users note that the user interface can be confusing at times, particularly for new users.

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Dylan E.
DE
Information Security Officer
Mid-Market (51-1000 emp.)
"Huge Time-Saver: Smart Control Mapping, Helpful Onboarding, and an Intuitive UI"
What do you like best about Drata?

The best feature Drata has is the mapping of recurring requirements of different frameworks/standards to generic Drata Controls. What this means is that if multiple of your frameworks require pretty much the same thing, you only have one Drata control you need to comply with to satisfy all the requirements of your frameworks. This also means only one place to store evidence, add policies, do tasks, etc. This is tremendous time-saver compared to other GRC tools.

Another great feature is the onboarding service they offer. Every subscription has a number of hours attached that you can use to call in GRC-specialists to help you set up something, or just ask questions. You don't have to struggle to get Drata up and running, but can lean on their expertise.

The AI policy builder they have works quite well. It starts you off with a template for whatever policy you selected, but it can also analyse something you made yourself to see if it adheres with the requirements of the Drata controls. It also makes suggestions for what is missing. It isn't always foolproof, so you do need to review the suggestions yourself, but it is a good tool to pinpoint where you are lacking.

Connections are important to get your compliance evidence in Drata in an automated way, and it is adequate. There are many out-of-the-box intergrations, but frankly some of them are missing automated evidence collection. As an example, we integrated our password manager using the built-in Drata connection, and it was easy to set up and gather our list of users. However, it didn't get data to show that our security-related settings were configured properly. We ended up having to use a custom integration.

Lastly some praise for the UI. It is clean, easy to navigate and most importantly, is intuitive. If I want to see my Risk Register, you just navigate to "Risks". Review collected by and hosted on G2.com.

What do you dislike about Drata?

As a premium offering, the only real barrier to entry is the price. It isn't the most expensive GRC tool I have seen, but it is up there. This can be compounded if you need alot of extras (more frameworks, etc.).

Our experiences with customer support have also been mixed. Some responded very quickly and accurately, while other times the response was too vague to actually answer our question. Review collected by and hosted on G2.com.

Response from Lizzie Higgins of Drata

Hi Dylan! Thank you so much for the feedback and for highlighting the time-savings you've experienced as a result of using Drata as a single source of truth for your program. We love hearing that you found the platform intuitive and easy to onboard, that controls mapped to multiple frameworks has helped, and that you found so much value in the AI-powered control suggestions for policies. We know the importance of efficiency and accuracy as you continually build and maintain trust, and we're so pleased that Drata has reduced the manual work for you and your team.

Nate S.
NS
Senior Director, Infrastructure and Security
Mid-Market (51-1000 emp.)
"Drata is the gold-standard for compliance management with steadily improving AI functionality"
What do you like best about Drata?

Their monitoring dashboard is fantastic for identifying monitoring and compliance gaps, and their policy creation module is a game-changer for getting company policies created or updated. Review collected by and hosted on G2.com.

What do you dislike about Drata?

The way test failures are presented in the pure JSON test output can sometimes make it take an unnecessarily long time to figure out which resource is causing a compliance error. The AI-generated output for these failures has improved, but they could still benefit from better JSON parsing so that, even when the raw output is shown, the user only sees the failures. Review collected by and hosted on G2.com.

Response from Lizzie Higgins of Drata

Hi Nate, thanks so much for the feedback! We're thrilled to hear that you found our continuous monitoring and policy creation functions to be game-changing, and of course are delighted that Drata was able to save you months of time (& money too!). We also appreciate your feedback on the JSON test output and have surfaced to the team. Thank you for recommending Drata to others considering our platform, especially with such thoughtful advice about onboarding. We appreciate you!

Emily B.
EB
Chief of Staff
Small-Business (50 or fewer emp.)
"Decent SOC 2 Tracking, but would prefer more advanced capabilities for the price"
What do you like best about Drata?

It’s a decent tool for tracking SOC 2 compliance rules and controls. It also integrates with our HRIS, which helps keep things connected and easier to manage. Review collected by and hosted on G2.com.

What do you dislike about Drata?

The “tests” for various controls aren’t very intuitive, and at times they feel more arbitrary than helpful. Pricing also seems high relative to the platform’s actual capabilities. During onboarding, the reliability of the tool was oversold, which made it harder to gauge how deep we needed to go with our controls and any supplemental tracking tools. I would have preferred clearer, more practical guidance throughout. Review collected by and hosted on G2.com.

Verified User in Marketing and Advertising
UM
Mid-Market (51-1000 emp.)
"Drata Keeps Us Continuously Audit-Ready with Hands-Off Evidence Collection"
What do you like best about Drata?

What I like about Drata is how it transforms compliance from a manual, point-in-time effort into a continuous, automated process. Its integrations with tools like cloud providers and identity systems make evidence collection largely hands-off. The dashboard is clear and accessible, giving both technical and non-technical stakeholders quick insight into compliance status. Overall, Drata makes it much easier to stay audit-ready without the usual operational burden, and it scales well as organizations grow. Review collected by and hosted on G2.com.

What do you dislike about Drata?

What I dislike about Drata is that the initial setup and configuration can be time-consuming and sometimes confusing, especially when mapping controls across multiple frameworks.The platform can also generate a high volume of alerts or tasks, which may create noise if not carefully tuned. Review collected by and hosted on G2.com.

Response from Lizzie Higgins of Drata

Thank you for sharing your positive experience with Drata! We're glad to hear that our automated tests and integrations have made evidence collection easier and saved you time, without sacrificing accuracy. Also, we love to hear that information about your compliance posture is clear and accessible for your technical and non-technical teams. Trust is everyone's job, and we're happy to be enabling your whole team to maintain that trust.

Zeyd Taha C.
ZC
Co-Founder
Small-Business (50 or fewer emp.)
"Great Compliance Tool with Room for Performance Improvement"
What do you like best about Drata?

I really like the ease of use and the support that Drata provides, especially for a small team like ours. It's helpful to have a tool that works for us in terms of compliance. Drata gives us an overview of all necessary renewals for evidence, and the use of templates is really handy. It's nice that Drata offers many easy setup configurations. Review collected by and hosted on G2.com.

What do you dislike about Drata?

The platform is sometimes a little bit slow and minor bugs. Sometimes I have to wait for tech support to answer for bugs which slows me down, or wait for page loads longer than usual. Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
AH
Mid-Market (51-1000 emp.)
"Expect things to break all the time silently"
What do you like best about Drata?

Comes with a Drata Trust Center that's relatively easy to manage. That's pretty much the only thing that hasn't broken on me this past year. Review collected by and hosted on G2.com.

What do you dislike about Drata?

Drata seems to have major breakage on what seems to be a monthly basis.

- MDM integration is currently broken

- Audit hub messages from auditors are currently broken

- Using a custom framework, only your auditors can create the controls (and control mappings in the audit hub vs what's in your view of the custom framework are not kept in sync)

I've reached the point where I'm running audits outside of Drata because Drata is so broken.

Customer Service seems to have taken a major step back in quality. I've been advised at least twice to make dangerous changes that each time broke my Drata instance (Google, HRIS). Review collected by and hosted on G2.com.

Response from Ashley Hyman of Drata

Thank you so much for taking the time to provide your feedback. While difficult to hear, your feedback is important to us, and we’d like the opportunity to address directly with you.

It sounds like you’ve dealt with repeated problems across important parts of the product, and that’s clearly eroded your trust in us. While this is not representative of the experience most Drata customers have, I want to apologize on behalf of the entire Drata team - this is not the way we strive to support the customers who place their trust in us.

I have already shared this feedback with our internal teams, but would love to connect with you so we can gather additional details and dig into this further. Our goal is to support you to resolution. Please reach out to me directly at ashley@drata.com to set up time to connect, and I’ll ensure we pull in our top experts to address your concerns.

Sincerely,

Ashley Hyman

VP of Customer Experience

Verified User in Computer Software
EC
Small-Business (50 or fewer emp.)
"Comprehensive Alerts and Excellent Support—Key to Passing Our SOC 2 Audit"
What do you like best about Drata?

Comprehensive alerts on tasks and status pf controls. Could not have passed SOC2 audit without Drata. Initial onboarding was difficult as the platform is not intuitive, especially for folks new to the CRG arena. Good documention but not easy to formulate searches as a newbie. Review collected by and hosted on G2.com.

What do you dislike about Drata?

Usage is not intuitive, UI is OK

Support is excellent Review collected by and hosted on G2.com.

Response from Lizzie Higgins of Drata

Thank you so much for sharing your experience with Drata. We're pleased to hear that our comprehensive alerts and excellent support were instrumental as you completed your SOC 2 audit process. We'd love to hear more details about the challenges you had with the UI and onboarding process, so we can ensure the particulars make it to the right team for review. Feel free to email me at lizziehiggins@drata.com with any specific feedback, or to set up time to chat! Thanks again!

Sheldon J.
SJ
Director, Information Technology
Mid-Market (51-1000 emp.)
"SOC2 Compliance with a little help from our friends."
What do you like best about Drata?

What I like best is the Integration with MS365, CERTN, Defender, Meraki ect. the automation makes it easier to manage several endpoints and users. Review collected by and hosted on G2.com.

What do you dislike about Drata?

Clearly defined policy renewal steps should be given prior to renewal, simply renewing a policy without updates changes the version of the document eg: 1.1, 1.2 and the tables inside don't reflect the changes. there's no point in doing the renew without updates as the table below has not reflected the version change. Review collected by and hosted on G2.com.

Response from Lizzie Higgins of Drata

Thank you so much for the insightful feedback! We're happy to hear that Drata's wide variety of integrations have enabled automation that makes things easier to manage for you and your team. We're so glad to be partnering with you and helping you to run an effective and efficient compliance program which enables your business to grow!

Eric L.
EL
Security Engnieer
Electrical/Electronic Manufacturing
Mid-Market (51-1000 emp.)
"Drata: Simplifying Your Compliance Journey"
What do you like best about Drata?

Drata supports the most common compliance frameworks. It effectively translates compliance requirements into readable control items. Each control item consists of a set of tests that are defined with clear specifications. For example, if an organization wants to adhere to the compliance NIST CSF, personnel responsible for achieving compliance simply focus on the control items of target compliance that Drata organized. Some tests can be shared across multiple compliance frameworks! It is easier for them to implement other compliances more efficiently in the future. Secondly, the most impressive design is the capability of automated evidence collection. With easy configuration on integrations to popular platforms, it can save effort when collecting the evidence of control items. To manage the overall readiness of compliance continuously, Drata provides efficient monitoring of controls, the status of tests, and the integrity of essential evidence. It provides users with real-time status and benchmarks in the dashboard. That helps internal or external auditors to track progress, identify gaps, and demonstrate compliance to key stakeholders. Finally, when I was new to Drata in the beginning, the Drata support team consistently delivered effective solutions to customer issues. The experience of customer support really touched my heart. Review collected by and hosted on G2.com.

What do you dislike about Drata?

The automated evidence-collection feature is a very productive design. However, it has both pros and cons. The limitations on integrations may become a burden if the target platform is not on the support list. Another thing that needs to be improved is the instructions for fixing the failed/error tests. Sometimes, I can not directly understand the root cause of the failed test. I hope the error information or solution instructions become more transparent or readable. Review collected by and hosted on G2.com.

Verified User in Translation and Localization
AT
Mid-Market (51-1000 emp.)
"Simplifies Auditing with Minimal Effort"
What do you like best about Drata?

I like the graphical interface of Drata. It's fairly easy to use, and after using it for a while, it becomes very easy. You can quickly look at various areas, from monitoring to pass and fail metrics, and risk assessment and assets. It's just easy to move around and understand where you're at and what you're doing. It breaks everything down simply in front of me, so I can see what's been done and what needs to be done without getting overwhelmed. The initial setup was fairly easy, with the majority of everything going smoothly, and I needed minimal assistance to get set up and running. I'm very happy and impressed with the product overall. Review collected by and hosted on G2.com.

What do you dislike about Drata?

Sometimes scrolling is a bit of an issue for me if I have a smaller monitor. There can be up to three slide bars on the right-hand side, and I have to move the page to go through a longer list. Review collected by and hosted on G2.com.

Questions about Drata? Ask real users or explore answers from the community

Get practical answers, real workflows, and honest pros and cons from the G2 community or share your insights.

Adenrele A.
AA
Adenrele Amosu
Last activity almost 4 years ago

Hard Disk Encryption

GU
Guest User
Last activity 3 months ago

How are others coping with slower support, chatbot inconsistencies, and login / chat issues?

Pricing Insights

Averages based on real user reviews.

Time to Implement

2 months

Return on Investment

11 months

Average Discount

13%

Perceived Cost

$$$$$

How much does Drata cost?

Data powered by BetterCloud.

Drata Comparisons
Drata Features
Compliance Monitoring
Anomoly Detection
Cloud Gap Analytics
Governance
Data Governance
Sensitive Data Compliance
Policy Enforcement
Auditing
Workflow Management
Questionnaire Templates
User Access Control