Introducing G2.ai, the future of software buying.Try now
Share your insights with Drata

Thousands of people like you come to G2 to find out whether solutions like Drata are the right fit for them. Share your real experiences with Drata and the G2 community and help someone make the right decision about their software.

Drata Pros and Cons: Top Advantages and Disadvantages

Quick AI Summary Based on G2 Reviews

Generated from real user reviews

Users value Drata's exceptional customer support, including live chat and personalized assistance that enhances compliance management. (182 mentions)
Users find Drata's platform to be exceptionally easy to use, facilitating compliance management efficiently and effectively. (159 mentions)
Users find Drata's efficiency in maintaining compliance essential for streamlining audits and enhancing HR/IT processes. (142 mentions)
Users value the ease of collaboration and dedicated support from the Drata Team, enhancing their GRC management experience. (115 mentions)
Users value Drata for its time-saving compliance monitoring, allowing them to focus on other priorities while staying secure. (109 mentions)
Users value Drata's seamless integration capabilities, simplifying compliance management and enhancing operational efficiency. (102 mentions)
Users find limited integrations with systems like JIRA hinder the overall functionality and flexibility of Drata. (47 mentions)
Users face integration issues with Drata, impacting the smooth transition and functionality across various platforms. (44 mentions)
Users find that improvements are needed in the audit hub's navigation and resolution guidance for compliance tests. (40 mentions)
Users find the lack of clarity in controls and connections in Drata to be confusing and disconnected. (26 mentions)
Users find the missing features like ISO 27001 documentation and additional integrations limiting for their needs. (24 mentions)
Users find Drata’s services to be expensive, especially for startups looking for cost-effective compliance solutions. (23 mentions)

Top Pros or Advantages of Drata

1. Customer Support
Users value Drata's exceptional customer support, including live chat and personalized assistance that enhances compliance management.
See 182 mentions

See Related User Reviews

IT

Ian T.

Small-Business (50 or fewer emp.)

4.5/5

"Helpful platform for building out our CMS"

What do you like about Drata?

The ability to incoprorate goals, such as SOC-2 compliance, and maintaining dashboards that can quickly showcase our status to compliance with each.

Verified User
A

Verified User

Mid-Market (51-1000 emp.)

5.0/5

"Game Changing"

What do you like about Drata?

Drata has truly been a game-changer for our organization’s compliance and security processes. Drata’s user-friendly interface is intuitive, and th

2. Ease of Use
Users find Drata's platform to be exceptionally easy to use, facilitating compliance management efficiently and effectively.
See 159 mentions

See Related User Reviews

Art B.
AB

Art B.

Small-Business (50 or fewer emp.)

5.0/5

"Drata has provided us an excellent compliance experience."

What do you like about Drata?

The Drata platform is organized logically and pragmatically to guide the compliance experience. We were able to work through and complete our SOC 2 Ty

Isaac A.
IA

Isaac A.

Small-Business (50 or fewer emp.)

5.0/5

"Streamlined Compliance, Thanks to Drata’s Automation"

What do you like about Drata?

Drata’s automated compliance platform. From implementation to ongoing monitoring, easy to use.

3. Compliance
Users find Drata's efficiency in maintaining compliance essential for streamlining audits and enhancing HR/IT processes.
See 142 mentions

See Related User Reviews

Seren T.
ST

Seren T.

5.0/5

"Smooth Setup, Essential for Compliance"

What do you like about Drata?

I appreciate Drata’s setup process, which was quick and clear, with any issues resolved swiftly. I find the integration features particularly benefici

Verified User
A

Verified User

Mid-Market (51-1000 emp.)

5.0/5

"Great product, and even greater customer support"

What do you like about Drata?

Drata has helped streamline audits, keep us compliant through out the year by monitoring key controls, which saves me time from performing a number of

4. Helpful
Users value the ease of collaboration and dedicated support from the Drata Team, enhancing their GRC management experience.
See 115 mentions

See Related User Reviews

Verified User
U

Verified User

Small-Business (50 or fewer emp.)

5.0/5

"Simple to set up and use - greatly sped up accreditation timelines"

What do you like about Drata?

Simple to use and get set up with the different connections to automate some of the controls. Good policy templates that passed our audit. Drata agent

Verified User
A

Verified User

Mid-Market (51-1000 emp.)

3.5/5

"Worth considering for sure"

What do you like about Drata?

Seems like once it's fully set up, it' s a good way to manage GRC - auditors seem to like it too.

5. Time-saving
Users value Drata for its time-saving compliance monitoring, allowing them to focus on other priorities while staying secure.
See 109 mentions

See Related User Reviews

Verified User
A

Verified User

Enterprise (> 1000 emp.)

4.0/5

"Drata Trust Center a smart way to share your company security posture"

What do you like about Drata?

Apart from the main use of the Drata solution focused on compliance monitoring, the platform also provides an easy way to share with customers your co

Verified User
A

Verified User

Mid-Market (51-1000 emp.)

5.0/5

"Game Changing"

What do you like about Drata?

Drata has truly been a game-changer for our organization’s compliance and security processes. Drata’s user-friendly interface is intuitive, and th

6. Integrations
Users value Drata's seamless integration capabilities, simplifying compliance management and enhancing operational efficiency.
See 102 mentions

See Related User Reviews

Verified User
A

Verified User

Enterprise (> 1000 emp.)

4.0/5

"Drata Trust Center a smart way to share your company security posture"

What do you like about Drata?

Apart from the main use of the Drata solution focused on compliance monitoring, the platform also provides an easy way to share with customers your co

Verified User
C

Verified User

Small-Business (50 or fewer emp.)

5.0/5

"100% Drata support satisfaction"

What do you like about Drata?

Ease of use, Ease of implementation, Customer Support, Ease of Integration

Top Cons or Disadvantages of Drata

1. Limited Integrations
Users find limited integrations with systems like JIRA hinder the overall functionality and flexibility of Drata.
See 47 mentions

See Related User Reviews

CB

Chris B.

Mid-Market (51-1000 emp.)

5.0/5

"Great compliance automation tool, great UX, easy to navigate."

What do you dislike about Drata?

Dislike is a strong word. Given the relative youngness of the company, there are a few rough edges spread around none of which stop getting the value

Shannon  K.
SK

Shannon K.

Mid-Market (51-1000 emp.)

5.0/5

"Streamlined SOC 2 Audit and Great Customer Support"

What do you dislike about Drata?

There is no HITRUST framework yet. But I hear it's coming next quarter. Some of the automated integrations have been problematic (e.g., github, backg

2. Integration Issues
Users face integration issues with Drata, impacting the smooth transition and functionality across various platforms.
See 44 mentions

See Related User Reviews

Verified User
A

Verified User

Mid-Market (51-1000 emp.)

5.0/5

"Great CSM and platform experience"

What do you dislike about Drata?

Some things can only be configured by contacting the CSM. Switching from another compliance platform to Drata is far less seamless than the market

CB

Chris B.

Mid-Market (51-1000 emp.)

5.0/5

"Great compliance automation tool, great UX, easy to navigate."

What do you dislike about Drata?

Dislike is a strong word. Given the relative youngness of the company, there are a few rough edges spread around none of which stop getting the value

3. Improvements Needed
Users find that improvements are needed in the audit hub's navigation and resolution guidance for compliance tests.
See 40 mentions

See Related User Reviews

NB

Noam B.

Mid-Market (51-1000 emp.)

5.0/5

"Drata fits big organization as well as small, putting GRC and automation at the center with ease"

What do you dislike about Drata?

Custom tailoring per client, feature requests(roadmap)can sometimes be too generic or basic. Vendor assessment work can be tedious.

SD

Steven D.

Mid-Market (51-1000 emp.)

5.0/5

"A system that greatly simplified the complicated SOC2 and PCI process."

What do you dislike about Drata?

The downside is very minimal. When a compliance test fails, the instructions for resolution could be better.

4. Lack of Clarity
Users find the lack of clarity in controls and connections in Drata to be confusing and disconnected.
See 26 mentions

See Related User Reviews

Alexander P.
AP

Alexander P.

Mid-Market (51-1000 emp.)

5.0/5

"Great tool with a great team behind"

What do you dislike about Drata?

When following a particular framework, ISO 27001:2022 in our case, it makes it difficult to get a clear overview of controls required within the frame

Verified User
A

Verified User

Mid-Market (51-1000 emp.)

5.0/5

"Excellent support"

What do you dislike about Drata?

so far the controls and connections are not obvious what they do or what they are for

5. Missing Features
Users find the missing features like ISO 27001 documentation and additional integrations limiting for their needs.
See 24 mentions

See Related User Reviews

Verified User
A

Verified User

Small-Business (50 or fewer emp.)

4.0/5

"Streamlines compliance"

What do you dislike about Drata?

Add-ons and segmented features which would be really useful as part of core package e.g user access control

Verified User
A

Verified User

Small-Business (50 or fewer emp.)

4.5/5

"Solid product, helpful support"

What do you dislike about Drata?

- While SOC 2 is well documented in the help center, ISO 27001 is not always mentioned as well. - More integrations that could be helpful

6. Expensive
Users find Drata’s services to be expensive, especially for startups looking for cost-effective compliance solutions.
See 23 mentions

See Related User Reviews

Albert C.
AC

Albert C.

Small-Business (50 or fewer emp.)

4.5/5

"Compliance automation made easy."

What do you dislike about Drata?

Quite a bit of the products newer useful features don't support our versioning control i.e. 'compliance as code' and gitlab. A lot of newer features

NM

Nikolai M.

Small-Business (50 or fewer emp.)

4.5/5

"Made our ISO certification much easier"

What do you dislike about Drata?

- No open info about prices - Additional features are quite expensive

Drata Reviews (1,104)

Reviews

Drata Reviews (1,104)

4.8
1,104 reviews
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Artem T.
AT
Chief Information Security Officer
Mid-Market (51-1000 emp.)
"From Manual Work to Automation: Why We Love Drata"
What do you like best about Drata?

The most valuable feature for us is the continuous monitoring and real-time alerts, which provide reassurance that our controls are consistently effective. Drata also simplifies evidence collection and audit preparation, helping us save time and reduce the risk of errors. As a result, we are able to maintain compliance proactively and dedicate more attention to strategic security improvements instead of getting bogged down by administrative work.

In terms of usability, the platform is highly intuitive and user-friendly, making it easy for even new team members to navigate and complete tasks. The implementation process was smooth and quick, thanks to clear instructions and minimal disruption to our existing workflows. Drata’s integration with our current tools and systems is seamless, which cuts down on manual work and keeps our data consistent across platforms. The customer support team is always responsive, knowledgeable, and eager to help, which greatly enhances our overall experience. We rely on Drata daily for monitoring and compliance activities, and it has become an essential part of our security operations. Review collected by and hosted on G2.com.

What do you dislike about Drata?

It would be great to have more available integrations, for example with popular observability tools such as Grafana. Review collected by and hosted on G2.com.

Keith B.
KB
Interim IT and Security Lead
Mid-Market (51-1000 emp.)
"A seamless and reliable compliance automation platform, supported with an incredible CSM."
What do you like best about Drata?

As a relatively small organisation, Drata has truly been a game-changer for us. Without a large compliance team, we have still been able to make steady progress toward our compliance goals, thanks to the platform. Working alongside a responsive auditing partner, we found the initial implementation straightforward and easy to get started with. The automation features for evidence collection and continuous monitoring have saved us countless hours of manual effort. We rely on Drata daily to ensure that any issues are promptly reported to the appropriate team and resolved quickly. We also value how smoothly it integrates with our core tools, such as AWS, Microsoft 365, and Intune, and how it offers clear dashboards and guided workflows that make preparing for audits much less stressful. Review collected by and hosted on G2.com.

What do you dislike about Drata?

The only real negative we’ve experienced is that support can sometimes be slower than we would like to respond. However, this has been more than mitigated by our highly responsive Customer Success Manager, who has consistently gone above and beyond to keep us moving forward. Overall, this balance has meant issues never become blockers. I wouldn't hesitate to recommend Drata to any organization. Review collected by and hosted on G2.com.

Ben  B.
BB
Compliance and Information Security Manager
Mid-Market (51-1000 emp.)
"An amazing ISMS solution that meets our needs"
What do you like best about Drata?

Drata provides a clear dashboard view of the frameworks we work towards, clear connections to controls, the capabilities of ownership and maintenance of our ISMS and risk management.

The supplier management section is also super helpful!

Implementation was easy and using the connections and integrations we were set up and running within two weeks.

The ability to be part of the roadmap and feedback to Drata using customer support really makes you feel part of a family.

When I log on to our system, Drata is one of the first applications I open and it stays with me all day. Review collected by and hosted on G2.com.

What do you dislike about Drata?

The downside of Drata for me personally, is that it is that efficient, the moment any part of ISMS falls out of review I see the percentage score drop and this messes with my OCD! Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
AC
Mid-Market (51-1000 emp.)
"Audit-Ready Dashboard and Automation Save Us Time"
What do you like best about Drata?

It's always audit-ready: I can literally look at the dashboard and see our real-time compliance status for SOC 2 or ISO 27001. If a control fails, I get an alert immediately, not six months later during a review.

Massive time savings: It has seriously automated 90% of the manual evidence collection. I no longer spend days or weeks before an audit compiling screenshots and documentation.

The Audit Hub is a game-changer: When the auditor shows up, everything they need is centralized in one place. Communication and evidence requests are streamlined, which makes the entire audit process so much smoother and faster. Review collected by and hosted on G2.com.

What do you dislike about Drata?

Limited Niche Integrations: We use a few niche tools, and Drata either doesn't have an integration for them or the pre-built connection is very limited in the evidence it can pull. This forces us back to the manual process for those specific controls, which defeats the whole purpose of the automation.

Lack of Flexibility in Control Mapping: For standard frameworks (like SOC 2), it's great. But if your organization has unique workflows, internal policies, or needs a less common framework, customizing or mapping your controls to fit those needs can be rigid and challenging. It can feel like it's a "my way or the highway" platform. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
II
Small-Business (50 or fewer emp.)
"Effortless Compliance Automation with Seamless Integrations"
What do you like best about Drata?

Drata has taken what used to be a complex, manual process and turned it into a seamless, automated workflow. The integrations with HR systems, cloud providers, and security tools (like Google Workspace, AWS, and Jira) make evidence collection nearly effortless. I particularly love the continuous monitoring feature — it gives real-time visibility into control status and alerts when something falls out of compliance.

The user interface is clean and intuitive, making it easy for both technical and non-technical stakeholders to navigate. The risk assessment and policy management modules are also well-structured, helping us align with auditors’ expectations without juggling multiple spreadsheets. Review collected by and hosted on G2.com.

What do you dislike about Drata?

While the platform covers most use cases perfectly, some integrations (like HR background checks and certain people-data syncs) occasionally require reauthentication or manual validation. Their support team, however, is responsive and proactive in resolving such issues. Review collected by and hosted on G2.com.

KW
Compliance Analyst
Mid-Market (51-1000 emp.)
"Outstanding Support and Partnership Make Compliance a Breeze"
What do you like best about Drata?

The partnership and support we've received from our Drata team have been exceptional. Sierra Alvarez, our Customer Success Manager, and Christina from support have both consistently gone above and beyond to help me organize our SOC 2 controls and prepare for the audit. Their prompt responses and expertise made what could have been a complicated process much more manageable, and Sierra's collaborative approach has truly helped me stay on track and sane throughout. Review collected by and hosted on G2.com.

What do you dislike about Drata?

The SOC 2 control mapping and evidence alignment process seems tedious and time consuming, the platform is powerful, but it could benefit from more streamlned control mapping and control reassignments. Review collected by and hosted on G2.com.

Amanda S.
AS
"Robust Compliance Tool with a Steep Learning Curve"
What do you like best about Drata?

I find Drata extremely useful for complete document organization, alerts, compliance, and security across the board. The alert system stands out for its ability to integrate with tools like Slack and Linear, which enhances my workflow seamlessly. I also appreciate the templates for policies and recommendations that Drata makes; they provide valuable guidance and save me time in setting up our compliance processes. What truly sets Drata apart is the extraordinarily helpful support from Alex Hamilton and Tina, who are patient and knowledgeable, assisting me in learning how to optimize and best use Drata. As I become more familiar with the system, I'm increasingly able to leverage its full potential, which is a significant factor in my decision to continue using and considering repurchasing Drata. The combination of these features and the excellent customer support makes Drata an invaluable tool for me and my organization. Review collected by and hosted on G2.com.

What do you dislike about Drata?

{"I find the initial setup of Drata very difficult, and I felt a lack of sufficient onboarding support.","I'm also frustrated by the extensive knowledge required to effectively use Drata. I wish there were more accessible and responsive chat support, similar to the experience I have with Gusto, to quickly answer questions.","I believe Drata would benefit from having chat support available 24/7 to address issues and learning curves more efficiently."} Review collected by and hosted on G2.com.

Dan V.
DV
Head of Security and Business Systems
Small-Business (50 or fewer emp.)
"The Document and Security solution for companies that just want it done and done right."
What do you like best about Drata?

Drata makes creating policies and following frameworks easy and straight forward. Security is necessary at all companies now and so many companies are trying to re-invent the wheel. Why? Drata gives you what you need to pass your audits and do it right, without trying to re-invent what security is. Its a one stop shop for security professionals to keep their companies in the green in all senses of the word. We will continue to use Drata and it will enable us to grow without worrying about if we are doing it right. We know we are because we use Drata. Review collected by and hosted on G2.com.

What do you dislike about Drata?

I wish there were even easier way to fill out the templates for the policies. Allow more boxes to fill in the "stuff" that matters to your company. Review collected by and hosted on G2.com.

"Convenient Training and Compliance Management"
What do you like best about Drata?

I primarily use Drata for training, which is extremely convenient for me. I really appreciate how it helps me stay on top of compliance, especially given how busy we are. The setup process was straightforward and easy when I initially installed it, which was a pleasant surprise. Additionally, Drata appears to effectively manage important functions like antivirus and hard drive encryption, which adds to its value. Overall, it operates better than I had initially expected, and I'm quite satisfied with its performance, as reflected in my high likelihood of recommending it to others. Review collected by and hosted on G2.com.

What do you dislike about Drata?

Nothing comes to mind right now. I've only been using it for about a year. Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
UH
Small-Business (50 or fewer emp.)
"Simple to set up and use - greatly sped up accreditation timelines"
What do you like best about Drata?

Simple to use and get set up with the different connections to automate some of the controls. Good policy templates that passed our audit. Drata agent was simple to install across our devices and helped with the automation as well.

Advice on each control evidence was extremely useful to speed up evidence gathering.

Good recommendation for audit partner in the UK who specialised in earlier stage companies.

Support seems very good, even at the lower price tiers. Review collected by and hosted on G2.com.

What do you dislike about Drata?

There were a couple of additional policies that I would have liked some guidance on or basic examples of. The balance of integration audit partners is heavily to the US (to be expected) but would like some more options for UK / EU based providers in the future. Review collected by and hosted on G2.com.