• HOME
  • CATEGORIES

    • CATEGORIES

    • Application Development

      • Observability Platforms
      • Integrated Development Environment (IDE) Software
      • Enterprise Agile Planning Tools
      • Integration Platform as a Service
      • AI-Augmented Software Testing Tools
      • View All
    • Artificial Intelligence

      • AI Code Assistants (Transitioning to AI Coding Agents)
      • Generative AI Knowledge Management Apps/General Productivity
      • AI Application Development Platforms
      • Conversational AI Platforms
      • Artificial Intelligence Applications in IT Service Management (Transitioning to AI Applications in IT Service Management)
      • View All
    • Cloud Computing

      • Backup and Data Protection Platforms
      • Cloud Database Management Systems
      • Strategic Cloud Platform Services
      • Server Virtualization (Transitioning to Server Virtualization Platforms)
      • Hybrid Cloud Storage
      • View All
    • Customer Relationship Management

      • Contact Center as a Service
      • CRM Customer Engagement Center
      • Digital Experience Platforms
      • Web Content Management
      • Field Service Management
      • View All
    • Data and Analytics

      • Analytics and Business Intelligence Platforms
      • Data Science and Machine Learning Platforms (Transitioning to AI Platforms For Data Science and Machine Learning)
      • Data Integration Tools
      • Process Mining Platforms (Transitioning to Process Intelligence Platforms)
      • Data and Analytics Governance Platforms
      • View All
    • Education

      • Manager and Leadership Training
      • Corporate Learning Technologies
      • eLearning Authoring Tools
      • Higher Education Student Information System Software as a Service (Transitioning to Higher Education SaaS Student Information Systems)
      • Digital Learning Content Providers
      • View All
    • Enterprise Networking and Communications

      • Unified Communications as a Service
      • Global WAN Services
      • Intranet Packaged Solutions
      • Edge Distribution Platforms
      • SD-WAN
      • View All
    • Finance

      • Expense Management Software
      • Financial Close and Consolidation Solutions
      • Financial Planning Software
      • Cloud Financial Management Tools
      • Accounts Payable Applications
      • View All
    • Healthcare and Life Sciences

      • Medical Device Security Solutions (Transitioning to Medical Device Risk Management Platforms)
      • Health Navigation Solutions
      • Claim Editor Software
      • Revenue Cycle Management Software (Transitioning to Revenue Cycle Management Solutions)
      • Digital Health Platforms (Transitioning to Healthcare Provider Industry Cloud Platforms)
      • View All
    • Human Resources

      • Employee Recognition and Reward Systems
      • Workforce Management Applications (Transitioning to Workforce Management (WFM) Technology)
      • Digital Employee Experience Management Tools
      • Talent Acquisition (Recruiting) Suites
      • Cloud HCM Suites for Regional and/or Sub-1,000 Employee Enterprises
      • View All
    • IT Infrastructure and IoT

      • Enterprise Wired and Wireless LAN Infrastructure (Transitioning to Enterprise Wired and Wireless LAN)
      • IT Service Management Platforms
      • Endpoint Management Tools
      • Container Management
      • Infrastructure Monitoring Tools
      • View All
    • IT Security

      • Endpoint Protection Platforms
      • Email Security
      • Managed Detection and Response
      • Security Information and Event Management
      • Security Awareness Computer-Based Training
      • View All
    • Legal

      • Contract Life Cycle Management
      • Electronic Signature
      • Governance, Risk and Compliance Tools, Assurance Leaders
      • Compliance Monitoring Solutions
      • E-Discovery Solutions
      • View All
    • Manufacturing

      • Enterprise Asset Management Software
      • Manufacturing Execution Systems
      • Global Industrial IoT Platforms
      • PLM Software in Discrete Manufacturing Industries
      • Computer-Aided Design (CAD) Software
      • View All
    • Marketing

      • Video Editing Software
      • Email Marketing
      • Multichannel Marketing Hubs
      • Voice of the Customer Platforms
      • Customer Data Platforms
      • View All
    • Productivity and Collaboration

      • Document Management
      • Collaborative Work Management
      • Visual Collaboration Applications
      • Knowledge Management (KM) Software
      • Adaptive Project Management and Reporting
      • View All
    • Public Sector and Government

      • Government ERP Solutions
      • Government Budgeting and Planning Solution
      • Cloud-Based ERP for U.S. Local Government
      • Citizen Service Delivery
      • Government Contracting Software
      • View All
    • Retail

      • Digital Commerce
      • Digital Commerce Payment Vendors (Transitioning to Digital Commerce Payment Platforms)
      • Retail Workforce Management Applications (Transitioning to Retail Workforce Management Technology)
      • Retail Assortment Management Applications: Long Life Cycle Products
      • Digital Shelf Analytics
      • View All
    • Sales

      • Revenue Enablement Platforms
      • Configure, Price and Quote Applications
      • Sales Force Automation Platforms (Transitioning to CRM Sales Platforms)
      • Revenue Intelligence (Transitioning to Revenue Action Orchestration)
      • Search and Product Discovery
      • View All
    • Supply Chain Management

      • Supply Chain Planning Solutions
      • Transportation Management Systems
      • Real-Time Transportation Visibility Platforms
      • Warehouse Management Systems
      • Supply Chain Strategy, Planning and Operations Consulting
      • View All
    • Utilities

      • Geospatial Information Systems for Energy and Utilities
      • Mobile Workforce Management Software for Utilities (Transitioning to Mobile Workforce Management Solutions for Power and Utilities)
      • Energy Management and Optimization Systems
      • Energy Trading and Risk Management
      • Advanced Distribution Management Systems
      • View All
    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

      • Application Development
      • Artificial Intelligence
      • Cloud Computing
      • Customer Relationship Management
      • Data and Analytics
      • Education
      • Enterprise Networking and Communications
      • Finance
      • Healthcare and Life Sciences
      • Human Resources
      • IT Infrastructure and IoT
      • IT Security
      • Legal
      • Manufacturing
      • Marketing
      • Productivity and Collaboration
      • Public Sector and Government
      • Retail
      • Sales
      • Supply Chain Management
      • Utilities
      Browse All Categories

      Application Development

      69 markets
      • Observability Platforms
      • Integrated Development Environment (IDE) Software
      • Enterprise Agile Planning Tools
      • Integration Platform as a Service
      • AI-Augmented Software Testing Tools
      • API Management
      • Enterprise Low-Code Application Platforms
      • Robotic Process Automation
      • Business Process Automation Tools
      • DevOps Platforms (Transitioning to DevSecOps Platforms)
      • Business Orchestration and Automation Technologies
      • Enterprise Architecture Tools
      • Custom Software Development Services
      • Code Review Tools
      • Digital Adoption Platforms
      • Domain Registrars
      • Game Engine Software
      • Website Builders
      • Developer Productivity Insight Platforms
      • Public Cloud IT Transformation Services (Transitioning to Public Cloud Optimization and Transformation Services)
      • API Generation Software
      • Feature Management
      • AI Agents for Application Developers
      • Application Platforms (Transitioning to Cloud-Native Application Protection Platforms)
      • Application Crowdtesting Services
      • Prototyping Software
      • Mobile App Analytics
      • Test Data Management
      • Virtual Reality Development Software
      • Green Software Engineering
      • Application Testing Services, Worldwide (Transitioning to Quality Engineering Services)
      • Event Brokers
      • Application Integration Platforms
      • AI-Augmented Code Modernization Tools
      • Independent Third-Party Software Support of Megavendors
      • Application Development Life Cycle Management (Transitioning to DevOps Platforms)
      • Digital Twin of an Organization Platforms
      • Microsoft 365 Implementation and Support Services
      • BPM-Platform-Based Case Management Frameworks
      • Microsoft Product Support Services
      • Product Roadmapping Tools for Software Engineering
      • AI Agent Development Platforms for Software Engineering
      • Multiexperience Development Platforms
      • Application Portfolio Management Tools
      • Application Composition Platform
      • Internal Developer Portals
      • Load Testing Tools
      • Cloud Development Environments
      • Mobile Development Frameworks
      • SAP S/4HANA Application Services, Worldwide (Transitioning to Cloud ERP Services)
      • B2B Gateway Software
      • Blockchain Consulting and Proof-of-Concept Development Services
      • Citizen Application Development Platforms
      • Mobile Application Testing Services
      • Value Stream Management Platforms
      • Oracle Cloud Application Services, Worldwide (Transitioning to Cloud ERP Services)
      • SAP Application Services, Worldwide
      • SAP SuccessFactors Service Providers (Transitioning to Cloud ERP Services)
      • Service Mesh
      • API and MCP Testing Tools
      • Business-Outcome-Driven Enterprise Architecture Consulting (Retired)
      • Oracle Application Services, Worldwide (Transitioning to Cloud ERP Services)
      • Rapid Mobile App Development Tools
      • SAP Selective Test Data Management Tools
      • Augmented Reality Development Software
      • Blockchain as a Service
      • Mobile Application Management (Transitioning to Endpoint Management Tools)
      • Mobile Back-End Services
      • R&D Outsourcing Providers
      View More
  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. Drata
Logo of Drata

Drata

byDrata
in DevOps Continuous Compliance Automation Tools
3.8

Overview

Product Information on Drata

Updated 13th October 2025

What is Drata?

Drata is a software designed to automate the process of continuous security and compliance monitoring for organizations. The software integrates with cloud services, identity providers, and developer tools to enable real-time evidence collection and policy enforcement, supporting frameworks such as SOC 2, ISO 27001, and GDPR. Drata assists businesses in managing risk, maintaining audit readiness, and tracking compliance workflow through customizable controls and automated alerts. The software provides detailed reporting, role-based access controls, and documentation management to streamline compliance operations and help organizations reduce manual effort associated with regulatory requirements.

Drata Pricing

Drata software uses a subscription-based pricing model with multiple tiered plans that vary based on features, compliance frameworks, and number of users or employees. Pricing is structured to provide different levels of automation and support, and is typically billed annually with options varying according to organization size and compliance needs.

Overall experience with Drata

Benefits Consulting Analyst
<50M USD, Healthcare and Biotech
FAVORABLE

“Easy-To-Use Compliance Platform With Robust Security Features But Few Custom Options”

4.0
Aug 10, 2025
Efficient automation compliance platform that is user-friendly and seems to sustain very good posture. I have not run into any issues in my limited (approx. 3 months) months of usage. It is a great compliance platform that may fall short in extra options towards customization, but this adds to the value since I do not need to take time out of my busy schedule to rebuild.
INFRASTRUCTURE ARCHITECT
<50M USD, Healthcare and Biotech
CRITICAL

“Solid, stable product with constant improvement, but not perfect.”

3.0
Aug 21, 2025
Solid product with a reliable account representative and easy to use support model.

About Company

Company Description

Updated 4th March 2025

Drata is a cyber GRC platform that enables businesses of all sizes to maintain compliance efficiently, proactively monitor risks, and stay audit-ready. Its mission is to serve as the trust layer for its customers, with a commitment to modernizing GRC through AI-driven automation. Drata assists thousands of businesses globally to manage compliance for frameworks such as SOC 2, ISO 27001, GDPR, HIPAA, and various custom frameworks. This is achieved through constant, automated control monitoring and evidence collection. With its global team based in San Diego, California, Drata resolves the main business problem of streamlining regulatory compliance processes.

Company Details

Updated 4th March 2025
Company type
Private
Year Founded
2020
Head office location
San Diego, United States
Number of employees
501 - 1000
Website
https://drata.com

Do You Manage Peer Insights at Drata?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Reviewer Insights for: Drata

Drata Likes & Dislikes

Like

User-friendly interface and robust features have made it easy to maintain security and compliance.

Like

I like that the product is organized appropriately for what it does. The UI is clean and easy to navigate. Engaging support is very simple and can be done right from the main UI. I also like the fact that they are constantly making updates to incrementally improve the functionality of the product.

Like

The most impressive aspect is its automation of compliance processes, which significantly reduces the manual effort required for maintaining certifications.

Dislike

Customization is not extensive, which I do not find as a drawback at this time. I can see this causing potential issues in the future with more unique workflows. Some modules that have a need for risk management or specific trust center control sets may find it a challenge to incorporate into the platforms field of use.

Dislike

The documentation for the product leaves much to be desired. I have found that the documentation makes assumptions about the user's GRC knowledge or knowledge of the product itself. The documentation lacks depth and detail, but is nevertheless still functional overall. Some things with the UI are unnecessarily clunky for 2025; specifically when working in an Audit and viewing controls. When you filter the controls you want to look at to a specific list, then click to look at the details of a specific control, when you return to the list, 9 times out of 10, your filter has been removed. This creates the need for constantly filtering the list. I also don't care for the fact that, as far as I can tell, the product does not support creating Risk Assessments. It will allow you to document and manage your risks, but can't be used to perform a risk assessment. This seems like a miss to me. I also find the lack of continuity when it comes to security reviews between prospective vendors and current vendors to be slightly annoying. Regardless of whether the vendor is a potential or confirmed option, the available review types within the product should be the same. My org specifically treats reviews of prospective vendors the same as current vendors and would prefer our product to have the option to treat them the same as well.

Dislike

Notable downside of Drata is its complex setup process which can be time consuming.

Top Drata Alternatives

Logo of ActiveState Platform
1. ActiveState Platform
4.4
(4 Ratings)
Logo of CloudBees Platform
2. CloudBees Platform
4
(1 Ratings)
View All Alternatives

Peer Discussions

Drata Reviews and Ratings

3.8

(7 Ratings)

Rating Distribution

5 Star
14%
4 Star
71%
3 Star
14%
2 Star
0%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.5

Integration & Deployment

4.3

Service & Support

4.3

Product Capabilities

4.1

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • INFRASTRUCTURE ARCHITECT
    <50M USD
    Healthcare and Biotech
    Review Source

    Solid, stable product with constant improvement, but not perfect.

    3.0
    Aug 21, 2025
    Solid product with a reliable account representative and easy to use support model.
  • Benefits Consulting Analyst
    <50M USD
    Healthcare and Biotech
    Review Source

    Easy-To-Use Compliance Platform With Robust Security Features But Few Custom Options

    4.0
    Aug 10, 2025
    Efficient automation compliance platform that is user-friendly and seems to sustain very good posture. I have not run into any issues in my limited (approx. 3 months) months of usage. It is a great compliance platform that may fall short in extra options towards customization, but this adds to the value since I do not need to take time out of my busy schedule to rebuild.
  • Senior Associate
    10B+ USD
    Insurance (except health)
    Review Source

    Automating Compliance Processes: Drata's Revolutionary Approach

    4.0
    Sep 2, 2024
    Drata steamlines compliance and security management with its user-friendly platform, automating many of the tasks associated with maintaining certifications. It simplifies the audit process and offers comprehensive insights into compliance status. However the initial setup may require a learning curve.
  • IT Associate
    50M-1B USD
    Telecommunication
    Review Source

    Achieving ISO 27001 Alignment Through Innovative Product

    4.0
    May 3, 2024
    Great product, helping our company align with the ISO 27001 security framework. The support via the chat is outstanding and responsive.
  • IT MANAGER
    50M-1B USD
    Insurance (except health)
    Review Source

    Automated insights for compliance

    4.0
    Mar 18, 2024
    Very productive tool to pull in data and also to improve the standpoint for compliance and governance.
Showing Result 1-5 of 8

Recommended Gartner Insights

  • Market Guide for DevOps Continuous Compliance Automation Tools

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.