![Zachary O.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Zachary O.")
ZO

Zachary O.

GRC Manager

Manufacturing

Mid-Market (51-1000 emp.)

8/19/2026

"Good for SaaS posture and SOC 2 evidence, with room to grow on frameworks"

4.5/5

What do you like best about DoControl?

The misconfiguration module maps checks to CIS controls and shows impact by app and domain, so my team fixes the worst things first instead of reading a 200-item list. Auditors like the evidence trail. Every remediation is logged with a timestamp and an actor, which ended the annual screenshot scavenger hunt. Guided remediation steps are specific enough that a junior analyst can follow them without Slack-ing an engineer. Review collected by and hosted on G2.com.

What do you dislike about DoControl?

Framework coverage is still growing. SOC 2 and CIS are fine; some of the mappings we need for ISO 27001 required manual work. The misconfiguration module is also clearly newer than the data access side, and the check library per app varies. Google Workspace is deep, some others are shallow. Review collected by and hosted on G2.com.

What problems is DoControl solving and how is that benefiting you?

SaaS misconfigurations and compliance drift across Google Workspace, Microsoft 365, and Slack. Audit prep time for our SaaS controls dropped from about three weeks to four days, and posture stays current between audits instead of once a year. Review collected by and hosted on G2.com.

Show More

Current UserValidated ReviewerSource: Organic

See what 19 reviewers think of DoControl

4.7 out of 5 · Verified reviews from real users

[
Read all reviews
](https://www.g2.com/products/docontrol/reviews)