Managed Compliance: Drata

What’s Included

Managed Compliance Services include a Drata license subscription, the scope of which is determined by the subscription tier selected by Client. The capabilities available to Client will vary based on the applicable license and are subject to the terms of that subscription.
Subject to Client’s selected license tier, the Drata platform may provide access to the following capabilities:
  • Client may select and activate pre-built frameworks (e.g., SOC 2, ISO 27001, HIPAA, PCI-DSS) to automate evidence collection, control mapping, and audit readiness across their chosen regulatory or industry standards.
  • Enables structured identification, assessment, and tracking of organizational risks within the Drata platform, supporting a continuous risk management program aligned with Client’s compliance objectives.
  • Provides automated, policy-driven compliance monitoring through native integrations, enabling continuous control testing and real-time compliance posture visibility across Client’s environment.
  • Facilitates third-party risk assessments and ongoing vendor monitoring, allowing Client to track and manage the compliance posture of vendors within the Drata platform.
  • Supports periodic, auditable reviews of user access permissions across connected systems, helping Client demonstrate adherence to least-privilege principles required by most compliance frameworks.
  • Allows Client to extend the Drata platform with custom integrations, control tests, and data fields to accommodate compliance requirements unique to Client’s environment or frameworks not covered by pre-built options.
  • Note: Drata licensing is billed on an annual commitment basis.