Listing Thumbnail

    Drata Security & Compliance Automation Platform

     Info
    Sold by: Drata 
    Deployed on AWS
    An AWS Security Competency Partner, Drata is a GRC solution that enables companies to continuously monitor security and compliance controls, automatically collect evidence needed for an audit, and manage and remediate risk. Drata also allows you to share your real-time compliance posture with prospects and customers to build trust and accelerate growth.

    Overview

    Play video

    Drata's compliance automation platform integrates with hundreds of applications and systems to continuously monitor security controls and streamline over 20 compliance frameworks, standards, and regulations, such as SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and more. Drata integrates with 45+ AWS services and is a proud AWS Security Competency partner with an AI engine built on AWS Bedrock.

    Whether you're looking to get compliant quickly for the first time or want to streamline your complex GRC program, Drata scales with you. Get and stay compliant efficiently, build risk management into your GRC practice, and share your real-time compliance posture with prospects and customers to build trust and sell into new markets.

    Continuous automated monitoring alerts Drata customers when security controls aren't operating effectively to remediate, stay secure, and keep from falling out of compliance. Plus, automatic evidence collection makes the audit process as seamless as possible.

    For custom pricing, EULA, or a private contract, please contact AWS-Marketplace@drata.com , for a private offer.

    Highlights

    • Drata for Startups: Drata helps startups create a scalable foundation and systematic approach to compliance to unlock market opportunities and scale safely. Startups can speed up audit prep time with Drata's best-in-class automation and support from our compliance experts to achieve SOC 2 and ISO 27001 compliance quickly.
    • Drata for Commercial and Mid Market: Drata helps companies with audit experience establish a scalable GRC program and structured process for risk management. Streamline compliance tasks and substantially reduce manual workloads while leveraging compliance to increase revenue and build trust.
    • Drata for Enterprise: Customers can optimize and customize their mature GRC programs and depend on reliable compliance outcomes. Organizations can manage and remediate risk and leverage Drata workspaces and workflows to keep pace with the complexity of advanced compliance programs.

    Details

    Sold by

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata. Review certifications and security standards before purchase.

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Drata Security & Compliance Automation Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    Foundation Package for 1-50 FTE Companies
    List price for 1-50 FTE Company
    $15,000.00

    Vendor refund policy

    All Orders are non-cancellable and all fees and other amounts you pay under this Agreement are non-refundable.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    Included in your contract, Drata provides onboarding, live chat (in product), and continuous enablement. Onboarding includes integration setup, assistance configuring compliance policy and controls in the platform, and guidance on utilizing our network of auditors and technology/service partners to serve you in your compliance journey. support@drata.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Centralized Risk Management, Compliance and Auditing, Security
    Top
    10
    In Centralized Risk Management, Compliance and Auditing, Security
    Top
    10
    In Legal & Compliance, Compliance and Auditing

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Compliance Framework Support
    Supports continuous monitoring and automation for over 20 compliance frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    Cloud Service Integration
    Integrates with 45+ AWS services and leverages AWS Bedrock for AI-powered compliance monitoring
    Automated Security Control Monitoring
    Provides continuous automated monitoring with real-time alerts when security controls are not operating effectively
    Evidence Collection Mechanism
    Automatically collects compliance evidence to streamline audit processes and reduce manual documentation efforts
    Multi-System Application Connectivity
    Integrates with hundreds of applications and systems to enable comprehensive security and compliance tracking
    Compliance Automation
    Automates evidence collection across 35+ security and compliance frameworks including SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR
    Cloud Service Integration
    Deep integrations with 40+ AWS services providing comprehensive cloud security and compliance visibility
    AI-Powered Security Management
    AI Agent provides intelligent task management, smart recommendations, and real-time audit documentation generation
    Custom Test Support
    Supports custom automated tests built directly in-platform or via API for self-hosted and custom-built systems
    Multi-Product Security Platform
    Offers comprehensive trust management solutions including compliance automation, third-party risk management, and trust center capabilities
    Compliance Framework Support
    Supports multiple compliance frameworks including SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, PCI DSS, and POPIA
    Automated Evidence Collection
    Enables automated evidence collection and continuous control monitoring across security workflows
    Cloud Integration Capabilities
    Seamless integration with 30+ AWS services and over 100 cloud platform integrations
    Continuous Monitoring
    Provides 24/7 continuous monitoring with capability to reduce time to compliance by up to 90%
    Security Control Management
    Offers automated user access reviews, vendor risk management, and centralized security and compliance workflow management

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    No security profile
    -
    -
    -
    -
    -
    -
    -
    -

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    3.3
    4 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    75%
    0%
    0%
    0%
    4 AWS reviews
    |
    1071 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Omar H.

    Drata's smooth experience

    Reviewed on Jul 17, 2025
    Review provided by G2
    What do you like best about the product?
    Drata is very easy and intuitive to use, it saves a lot of intensive manual work, and we use if very frequently. The support is very responsive and fast, one of the best support teams we have dealt with. The implementation phase was also easy in terms of setting up the connections, integrations, and just kicking off the process. Drata supports a wide range of integrations too!
    What do you dislike about the product?
    Maybe one downside which is really specific is that there is no support for asset-based risk assessment, which is totally fine since there is a scenario-based risk assessment section that is well documented and supported and contains many features.
    What problems is the product solving and how is that benefiting you?
    Drata is helping us with getting certified in SOC2, ISO27001, and GDPR. It's helping us with policy writing, control mapping, framework understanding, risk assessment, asset inventory, vendor management, awesome integrations, and automated monitoring of controls as well as giving us a dashboard to measure our progress.
    Computer & Network Security

    Great GRC platform

    Reviewed on Jul 16, 2025
    Review provided by G2
    What do you like best about the product?
    Intuitive interfaces that are easy to use
    What do you dislike about the product?
    Nothing at the moment. Its a solid tool,
    What problems is the product solving and how is that benefiting you?
    holistic GRC automation
    Manufacturing

    Easy to use, constantly improving, and easy to understand GRC platform

    Reviewed on Jul 14, 2025
    Review provided by G2
    What do you like best about the product?
    It's constantly improving - the changes in the little time we have been using the platform has been enormous.

    Customer Support and compliance team are also top notch - they've never not been able to help.

    The amount of integrations are staggering, and they all work pretty well in my experience. We've rarely had any issues in that area.
    What do you dislike about the product?
    Some omissions in features that would truly make it an 'all-in-on' GRC tool - such as a NC register - sometimes hold it pack a little.
    What problems is the product solving and how is that benefiting you?
    Implementing different security frameworks, and hand holding along the way
    Jim G.

    Fantastic platform and even better CSM!

    Reviewed on Jul 09, 2025
    Review provided by G2
    What do you like best about the product?
    We really like the fact that it has several views on the controls, we also like that it is helping us get through SOC2 and ISO at the same time.
    It was easy to rollout - everyone was good to go with one walk through (I found doing a 1x1 with Exec was easiest)
    What do you dislike about the product?
    When you leave a page, nothing is saved so you have to save your settings that you had already put in SOC/ISO(compliance) , readiness, etc. Super annoying. If you hit the back button on the browser, it will take you there, but if you have opened a lot of items - it takes forever
    What problems is the product solving and how is that benefiting you?
    Help us get to SOC2 and ISO compliance. The templates in the Policies were fantastic! Really saved us a lot of time
    Alejandro R.

    Great platform with a ton of features and excellent account management

    Reviewed on Jul 09, 2025
    Review provided by G2
    What do you like best about the product?
    The application truly provides a great template for GRC. Everything from personnel management, risk management, policy maintenance, framework compliance and access review is a standard feature within the application. It allows organizations to be as involved (or not) as they want. It also has easy to use integrations to multiple platforms.
    Account management and support are also equally as important. Drata has both. Even with my organization's internal resource transition, our customer success manager Ben, was ready to assist with the plethora of questions any new user would have. He continually provided supplemental information via self-help links, and was quick to respond to questions via a call or email. The times that we had to involve support our success manager was involved until a resolution was found.
    What do you dislike about the product?
    The application is very expansive; it has a ton features. Greener organizations may find it difficult to understand how all the modules are interrelated.
    What problems is the product solving and how is that benefiting you?
    Policy maintenance
    SOC2 audit repository and guidelines
    Vendor Management
    Risk Management
    Personnel Compliance Management
    View all reviews