Skip to main content
Drata logo

Drata

Security and trust center evidence

drata.comCompliance and GRCLast verified 17 Sep 2026

Summary

Drata has 3 registry-verified rows and 9 vendor-stated rows in the CertReports index, last verified 17 Sep 2026. The strongest row is HIPAA: Vendor displays a HIPAA badge on its trust centre (claim; BAA availability not yet captured). This page is independent of the vendor’s own trust centre: dates, sources and caveats come from CertReports captures.

Reviewer brief

As of 17 Sep 2026, Drata states on its trust centre that it holds a SOC 2 Type II report. As of 17 Sep 2026, Drata is listed in the FedRAMP registry as FedRAMP Authorized, with authorization issued 5 Dec 2025 and audited by Schellman Compliance, LLC. As of 17 Sep 2026, Drata is listed in the CSA STAR registry with a STAR Level 1 self-assessment (CAIQ) issued 24 Aug 2021, and is listed in the EU-US Data Privacy Framework registry as active, with certification issued 5 May 2022 and set to expire 14 Apr 2027. As of 17 Sep 2026, Drata states on its trust centre that it holds ISO/IEC 27001:2022, ISO/IEC 42001:2023, ISO/IEC 27017:2015, ISO/IEC 27018:2019, SOC 3, GDPR, and CCPA/CPRA coverage, and displays a HIPAA badge on its trust centre though BAA availability is not yet captured. As of 17 Sep 2026, no public evidence found for PCI DSS or other frameworks not listed in these rows.

  • SOC 2: Drata states on its trust centre that it holds a SOC 2 Type II report (as of 17 Sep 2026).
  • FedRAMP: Listed in the FedRAMP registry as Authorized, issued 5 Dec 2025, audited by Schellman Compliance, LLC (as of 17 Sep 2026).
  • HIPAA: Vendor displays a HIPAA badge on its trust centre; BAA availability not yet captured (as of 17 Sep 2026).

Facts only, each dated; nothing here is inferred, scored or advised. Brief generated 17 Sep 2026; it is regenerated whenever a row changes.

Among compliance and grc vendors

3verified rows

Category median 1, across 118 indexed compliance and grc vendors. Drata has more verified rows than 100 percent of them.

audit managementcompliance automationgovernancesoc 2

Compliance grid

Subprocessors (2)

  • DO
    Description of Services
  • SM
    Status Monitoring Amazon Web Services

Change history

  1. 17 Sep 2026CCPA / CPRA evidence addedA CCPA / CPRA row entered the index with state Vendor-stated.
  2. 17 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
  3. 17 Sep 2026HIPAA evidence addedA HIPAA row entered the index with state Vendor-stated.
  4. 17 Sep 2026ISO/IEC 27001 evidence addedA ISO/IEC 27001 row entered the index with state Vendor-stated.
  5. 17 Sep 2026ISO/IEC 27017 evidence addedA ISO/IEC 27017 row entered the index with state Vendor-stated.
  6. 17 Sep 2026ISO/IEC 27018 evidence addedA ISO/IEC 27018 row entered the index with state Vendor-stated.
  7. 17 Sep 2026ISO/IEC 42001 evidence addedA ISO/IEC 42001 row entered the index with state Vendor-stated.
  8. 17 Sep 2026SOC 2 evidence addedA SOC 2 row entered the index with state Vendor-stated.
  9. 17 Sep 2026SOC 3 evidence addedA SOC 3 row entered the index with state Vendor-stated.
  10. 17 Sep 2026Subprocessor added: Description of ServicesDescription of Services appeared on the subprocessor list.

Similar vendors with evidence

Related by product tags and the Compliance and GRC category, ranked by shared tags, description similarity and overlapping evidence. Never by popularity.