C
Chief Information Officer
"Solid Framework for Security Audits and Compliance"
I appreciate the thoughtfully designed UI, the AI chatbot, and the relatively fast human support (special thanks to Terrious for exceptionally quick and accurate assistance). Integrations with other tools have room for improvement, but overall it's been a better experience than some competitors. I also like Drata Autopilot and how easy it is to quickly test integrations to confirm their capabilities. Some integrations are limited, offering little control and only high-level functionality, but support often compensates. That said, the onboarding and accelerator program is too high-level. It collects standard documents and fills general fields but doesn't address real pain points. The policy templates are generic; if you have zero policies, you could use them, but if you already have policies, they're of little value. If they understood your business and current state, then helped align existing policies with requirements, the accelerator would be much better. Overall, Drata is great if you already know what's needed for compliance. For us, it's provided a solid framework for ISO 27001, saving weeks of planning and likely hundreds of hours long-term, as most things can be managed through the platform—policies, vendor reviews, documents, automated integrations, annual trainings, etc. However, it's not a magic solution; time to certification depends heavily on your compliance posture. If you're a beginner, it could take months to write policies, review vendors, set up integrations, and remediate failures.
"Simple and Intuitive Compliance Solution"
The new trust center functionality is amazing—it streamlines the security verification process with customers, cutting the time in half or more. Sometimes the user experience is a bit cumbersome when reviewing many policies, requiring many clicks, but it's a one-time issue, so not a major concern. The main benefits: significantly reduced compliance costs by half, allowing cost savings; drastically reduced hours spent on compliance tasks by half, enabling more efficient resource allocation; seamless scalability to additional frameworks; enhanced security through a simplified approach. Relying solely on individuals to assess security can be risky, but Drata offers a straightforward yes/no system that drives focused improvements and mitigates risks.
C
Compliance Manager und Datenschutzbeauftragte
"Great for ISO27001 ISMS Setup with MS365 Integration"
For us, Drata's pre-built framework and control/policy suggestions were ideal for rebuilding our ISMS to ISO27001. The MS365 integration and automated verification that all employees have acknowledged policies are very helpful in daily operations. When questions arise, the help pages are comprehensive, and if that doesn't resolve it, support is quick to assist and even implements improvement suggestions. The price is reasonable for the extensive service provided. The audit area is somewhat limited if you link JIRA tickets as evidence because permissions to open them are missing. With Drata, we have almost all ISMS topics in one place and can track everything effectively. The involvement of control and risk owners, along with reminders, makes our lives easier.
M
Manager of Security and Compliance
"Affordable and Easy-to-Use Compliance Tool with Trust Center"
Drata is simple and user-friendly. It covers a wide range of security controls and requirements, making it easy to align multiple employees on compliance. The pricing is an easy sell to leadership, especially compared to other solutions we evaluated. I like that it includes a trust center, which was relatively easy to set up. One issue: when there's an error, such as when we auto-populate data through a test, and the test fails, clicking into it sometimes hits an error page, preventing you from seeing what's failing. This can happen repeatedly, leaving you with a failing control and no way to diagnose it. Despite that, it serves as a central hub for all compliance efforts, helping with tracking and coordination and saving us a significant amount of time.
"Centralized Compliance with Strong Automation"
What I appreciate most about Drata is its ability to centralize compliance activities, making it easier to track requirements, evidence, and overall status in one place. Automated monitoring and integrations significantly reduce manual follow-up for evidence collection, while clear dashboards make it easy to spot gaps and know what needs attention. Overall, it makes compliance work more organized, efficient, and manageable. One area for improvement is the UI/UX; some workflows and settings can take time to navigate or understand, especially when searching for specific features. Integrations are helpful but occasionally require additional troubleshooting or manual steps when evidence doesn't sync as expected. More intuitive navigation, clearer in-platform guidance, and better visibility into integration or sync issues would enhance the experience. Drata helps solve the challenge of managing compliance across different systems, teams, and evidence sources. Instead of relying on manual tracking, we can centralize controls, automate evidence collection through integrations, and quickly identify gaps or outstanding actions. This saves time, reduces administrative work, and makes it easier to stay audit-ready and coordinate efforts across teams.
"Organizes All Your Compliance Work"
Drata's standout feature is how it organizes all the controls needed for certification under your chosen framework. If employees haven't read required policies or completed training, Drata sends reminders, or you can easily check the dashboard to see who needs a nudge. Another highlight is its beautiful design—it's genuinely one of the aesthetically pleasing software options. The intuitive GUI makes Drata easy to use, and the numerous ready-made templates simplify implementation. Compliance can be complex, but the customer support chat is very responsive, with knowledgeable staff who quickly address technical or compliance queries. Frequency of use: Initially, you'll use Drata heavily, but once it's running, it becomes a tool for tracking gaps toward certification. I also appreciate that Drata makes it easy to share our compliance efforts with potential customers via a trust center, where you can customize what to display and share via a URL. We use this before onboarding new customers to streamline their compliance review. Some evidence is static, and it's possible to upload non-real evidence, but with increasing integrations, evidence becomes real-time and up-to-date. Drata helps us align internal policies and controls and communicate them across the organization, building trust throughout our supply chain and with customers.
"Simplifies SOC 2 Compliance for Small Teams"
The main advantage of Drata is how it eliminates much of the manual effort in compliance. At Waterly, we're a lean team, so having a single platform that tracks controls, evidence, policies, integrations, and audit prep is crucial. For me, the biggest value is managing SOC 2 without constantly juggling spreadsheets or chasing down evidence. It provides a quick overview of our status, highlights what needs attention, and keeps us audit-ready without requiring a dedicated compliance team. I'd say vendor management could use improvement—I find it creates a rigid structure and would prefer more flexibility. I'd also appreciate having registers for departments, job titles, systems, and processes within Drata. As I mentioned earlier, Drata solves the problem of keeping compliance organized and continuously monitored without manual oversight. For Waterly, that means automated evidence collection, control tracking, policy management, risk assessment, and integrations all in one place. The biggest benefit is time savings. It helps me quickly identify areas for attention, keeps us prepared for SOC 2 audits, and enables a small team to manage a mature compliance program without a full-time compliance person.
"Effortless Certification Management"
I really like how Drata streamlines managing certifications like SOC and GDPR. It's excellent for jump-starting the process with templates and an AI-powered help center that offers insights and documentation guidance. The platform consolidates everything into one easy-to-navigate hub, eliminating the need for multiple spreadsheets and shared drives. Setup is quick, and ongoing management is straightforward with reminders and a friendly interface. The UI/UX is top-notch, providing great tools for workload management. I love the clean design with color-coding that makes it easy to track subcomponents. The risk assessment section is particularly useful, allowing me to handle everything in one place with quick progress checks and vendor reviews. Automated evidence collection saves time and improves event tracking. I also appreciate the quick start program that got us operational quickly, highlighting how easy it is to integrate Drata. It's hard to find anything that doesn't work well. Based on my experience with other systems, there's nothing that doesn't function properly. However, I'd like to see more integrations in the connection catalog. There are numerous vendors and new programs emerging, and I'd love for Drata to expand its connectivity options. Specifically, in observability, only Datadog and New Relic are offered, and these don't integrate well unless you're on their highest tiers. There are better alternatives, so I'd like to see more observability integrations. I centralize my certification management with Drata, making it easy to set up and maintain SOC, GDPR, and ISO standards. The templates, logical structures, and reminders reduce the hassle of managing spreadsheets. This user-friendly platform streamlines my processes, enhancing efficiency.
P
People and Development Manager
"User-Friendly Compliance Platform with Excellent Support"
Drata has been a cornerstone of our compliance operations since 2023. The platform's intuitiveness stands out—from continuous monitoring to audit preparation, it organizes complex processes into a digestible format. Seamless integrations have automated numerous manual tasks, saving us countless hours. Performance has been consistently reliable and responsive. What truly differentiates Drata is its customer service; the team is responsive, knowledgeable, and always ready to assist. For any company pursuing SOC 2, Drata is an investment that yields returns. The initial setup can be somewhat overwhelming due to the platform's breadth, but once you explore and become familiar, it becomes manageable. This is more of a learning curve than a flaw. Drata has brought order and efficiency to our compliance program. Previously, tracking controls and knowing our compliance status was challenging; now everything is compartmentalized and easy to monitor. Audits are significantly smoother because everything is pre-organized and accessible. Instantly seeing where we're compliant and where gaps exist has been invaluable, eliminating last-minute scrambling.
"Streamlined SOC 2 Evidence Collection and Policy Creation"
Drata significantly simplified our SOC 2 journey by automating the collection of all required evidence. I also appreciated the straightforward policy templates provided. Prior to adopting Drata, we attempted to draft our own policies, which turned into a frustrating and divisive experience. The templates from Drata were clear and concise, making it far easier to gain team agreement. In terms of value, the hours saved, reduced stress, and added clarity easily justify the cost. A minor downside is that some tests occasionally produce inconsistent results—for instance, the data client might indicate one day that a user's hard drive wasn't encrypted, only to show it as encrypted the next day. Drata addressed these glitches, but it's something to note. Additionally, customizing certain tests can be challenging. For example, Control DCF-71 (Unique Accounts Used) is tied to employees having distinct infrastructure accounts. We use Google Workspace for internal access, where all employees have unique accounts, and we also have an Azure connector for our product environment, which includes client accounts for end users as well as employee accounts. Drata consistently flags the Azure user accounts as non-compliant because they aren't linked to the Google Workspace connector, forcing me to manually add exceptions for each client. I haven't found a way to adjust settings to change this behavior. Overall, Drata is fantastic—it made SOC 2 dramatically more manageable. As a small business, we were overwhelmed until we found it; it simplified everything, allowed us to focus on what mattered, and lifted a huge burden by handling most of the evidence collection.