Glamdring

Compliance automation

Drata price: plans listed, no price published (Sep 2026)

Drata publishes no price. Its plans page, checked 28 September 2026, lists three GRC plans, three Assurance plans and a separate Third-Party Risk Management product and sends every price to sales.

Glamdring Research12 min6 sources checked

Engraving of a surveillance camera on a bracket above a door access control panel

Drata publishes no price. Its plans page, checked 28 September 2026, lists three GRC plans (Foundation, Advanced and Enterprise), three Assurance plans with the same names and a separate Third-Party Risk Management product, with no figure against any of them. The page’s only pricing route is a “Get Personalized Pricing” link to Drata’s sales team.1 What the page does publish is the shape of a quote: a 50-employee cap and one framework on the entry GRC plan, domain and questionnaire limits on the Assurance plans, and add-ons on every tier.1

TL;DR

  • Drata’s cost is set by quote. Neither drata.com/plans nor drata.com/pricing showed a list price for any plan, product or add-on on 28 September 2026.1,2
  • The entry GRC plan, Foundation, covers up to 50 full-time employees and one pre-mapped framework chosen from five: SOC 2, ISO 27001, Cyber Essentials, HIPAA and GDPR.1 Drata advertises 30+ pre-built frameworks, so a buyer who needs one outside those five is negotiating Advanced or an add-on.3
  • Assurance is a separate plan line for Trust Center and AI questionnaire work. Its approved-domain limit steps from 100 to 300 to unlimited across the three tiers.1
  • Published third-party Drata prices are estimates, and some are pinned to plan descriptions that no longer match Drata’s page. None of them is Drata’s price.4,5
  • The quote to ask for names the plan, headcount band, framework count, add-ons, domain limit and questionnaire limit in writing.

Which plans does Drata publish?

Drata’s plans page lists seven offerings in three groups: three GRC plans, three Assurance plans and one Third-Party Risk Management product.1 The page’s section links split the tiers into a GRC Platform and an Assurance Platform. The entry GRC card carries a Compliance Automation label, the two higher cards carry a GRC label, and Third-Party Risk Management has its own card with no tiers.1 Drata sits in our compliance-automation category.

Plan lineTierPublished limitsAdds over the tier belowPrice published
GRCFoundationUp to 50 FTEs; 1 pre-mapped framework from SOC 2, ISO 27001, Cyber Essentials, HIPAA or GDPREntry tier: pre-built integrations, Trust Center Standard, AI Questionnaire Assistance Standard, risk management, custom controls, compliance as code, Open API accessNo
GRCAdvanced“Any Available Framework”Custom connections and tests; custom fields and formulasNo
GRCEnterpriseNone statedRisk Management Pro, Compliance as Code Pro, User Access ReviewNo
AssuranceFoundationUp to 100 approved domains; AI assistance for 10 questionnairesEntry tier: branded Trust Center, knowledge base, clickwrap NDA support, SAML/SSO (JIT), AI Questionnaire AssistanceNo
AssuranceAdvancedUp to 300 approved domains; 1 Open API access and 1 webhook accessSCIM, Docusign/Ironclad NDA integration, standard Salesforce and HubSpot integrations, Google Drive document syncNo
AssuranceEnterpriseUnlimited approved domains, Open API access and webhook accessEnterprise dashboards, Pro Salesforce and HubSpot integrations, Microsoft Dynamics, data warehouse sync, Microsoft PurviewNo
Third-Party Risk ManagementSingle listingNone statedVendor inventory sync, vendor questionnaire automation, inherent and residual risk tiering, automated assessment reportsNo

Source: drata.com/plans, checked 28 September 2026. Drata states that its feature list “is not a comprehensive list of all solutions available” and directs buyers to a sales representative for an exact breakdown.1

What do Drata’s GRC plans include?

Foundation covers one pre-mapped framework for an organisation of up to 50 full-time employees, Advanced opens the framework choice, and Enterprise adds the Pro risk and compliance-as-code modules plus user access review.1

Foundation’s inclusion list is broader than its limits suggest: pre-built integrations, Trust Center Standard, AI Questionnaire Assistance Standard, risk management, custom controls, compliance as code and Open API access.1 The constraint is the framework. Foundation’s single framework must be SOC 2, ISO 27001, Cyber Essentials, HIPAA or GDPR.1

Drata’s catalogue is much wider. It advertises 30+ pre-built frameworks, including DORA, FedRAMP, CMMC, NIS 2, Essential Eight and CPS 230.3 An organisation whose first obligation sits outside Foundation’s five needs either Advanced, which lists “Any Available Framework”, or Foundation’s Additional Frameworks add-on.1 The page doesn’t say whether that add-on lifts the five-framework restriction.

Advanced adds custom connections and tests, and custom fields and formulas.1 Its framework line gives no count, and Additional Frameworks stays on the add-on list for Advanced and Enterprise.1 The number of frameworks either tier includes is a term to settle in the quote.

Enterprise adds Risk Management Pro, Compliance as Code Pro and User Access Review.1 Two of those move from the add-on list to the inclusion list as a buyer steps up. User Access Review is an add-on on Foundation and Advanced, and Risk Management Pro is an add-on on Advanced.1 Custom Frameworks and Workspaces remain add-ons on both Advanced and Enterprise, and Enterprise’s add-on list also carries Additional Custom Tests and Agentic TPRM Assessment.1

The decision changes at the add-ons. A Foundation or Advanced quote that already carries User Access Review and Risk Management Pro belongs beside an Enterprise quote, because Enterprise includes both.

What do Drata’s Assurance plans include?

The Assurance plans combine Drata’s Trust Center with AI Questionnaire Assistance, and the tiers differ mainly on access limits and integrations with sales and identity systems.1

Assurance Foundation includes a branded Trust Center that hosts security reports, documents and policies, up to 100 approved domains, a knowledge base, clickwrap NDA support, automated access approvals, a custom URL, SAML/SSO (JIT), Slack and Teams integration, and document sync from Drata only.1 Its questionnaire allowance is AI assistance for 10 questionnaires, with upload through the app, multi-language support, a Chrome extension and responses through Slack. Additional approved domains and additional questionnaires are add-ons.1

Advanced adds configurable access expiration dates, Docusign and Ironclad NDA integration, SCIM, one Open API access and one webhook access, standard Salesforce and HubSpot integrations, document sync from Drata and Google Drive, internal product portals for questionnaire assistance, and support for Word, PDF and TXT files.1

Enterprise adds enterprise dashboards, unlimited Open API and webhook access, Pro Salesforce and HubSpot integrations, a Microsoft Dynamics integration, custom permission profiles, data warehouse sync and Microsoft Purview.1 On the questionnaire side it adds upload in Salesforce, upload through the API, status webhooks and what Drata calls questionnaire-driven revenue through the Salesforce integration.1

The page’s comparison table sets approved domains at up to 100, up to 300 and unlimited across the three tiers.1 It gives a different questionnaire figure from the Foundation card, though. The table’s row for questionnaire upload via app reads “Standard Up to 100” for Foundation, against the card’s 10 questionnaires.1 Confirm which limit governs before signing.

One overlap also needs settling. GRC Foundation already lists Trust Center Standard and AI Questionnaire Assistance Standard.1 The page doesn’t say how those compare with Assurance Foundation, so a buyer taking both lines should ask whether the quote counts the same Trust Center twice.

Where does Third-Party Risk Management fit?

Third-Party Risk Management is a separate listing with a capability list and no tiers. Drata’s line for it reads “Defensible, evidence-based vendor decisions powered by agentic AI”.1

Its listed capabilities include vendor inventory sync and enrichment, vendor questionnaire automation, custom risk rules and criteria, inherent and residual risk tiering, automated assessment reports, agentic evidence collection from Trust Centers, agentic follow-up and re-assessment, and a third-party risk register.1 GRC Enterprise separately lists Agentic TPRM Assessment as an add-on.1 The page doesn’t explain how that add-on relates to the standalone product, so a buyer who needs vendor risk should price both routes.

What does Drata publish instead of a price?

Drata publishes plan limits, inclusion lists and a route to its sales team. The page carries the label “Plans and Pricing”, its pricing call to action is “Get Personalized Pricing”, which links to Drata’s contact-sales page, and the Enterprise column of its comparison table carries a Contact Sales button.1

The drata.com/pricing address, captured the same day, carried Drata’s agentic trust platform material, product descriptions and three customer stages (Startup, Growth and Enterprise). It showed no plan list and no price.2

Drata’s own SOC 2 cost guide follows the same pattern. It lists compliance platform subscriptions among the recurring costs of SOC 2, and treats security tools, internal team time, readiness and remediation as costs beyond the audit fee. It puts no figure on Drata’s own subscription.6

A vendor page establishes what the vendor says, and our research standard treats it that way. Here that cuts in the buyer’s favour. The plan limits above are Drata’s own statements, which is why they can be written into a quote and held to.

Why do other published figures for Drata disagree?

Other pages publish Drata figures because Drata doesn’t. Those figures are third-party estimates on different bases, and some are tied to plan descriptions that no longer match Drata’s page.4,5

Bright Defense, which describes itself as a Drata Gold Partner, prints Drata starting figures and labels them user-reported. The same page states that neither Vanta nor Drata publicly shares pricing on its website.5

SmartSuite, which presents its own GRC platform as a Drata alternative, attributes its Drata tier estimates to TrustRadius and its median to Vendr.4 Its page carries a review date of 11 December 2025 and describes six plans, including SafeBase-branded Trust Center plans and a Drata Foundation plan with standard Risk Management and Vendor Risk Management modules. It gives the entry SafeBase plan up to 25 approved domains.4

Drata’s page on 28 September 2026 reads differently. Assurance Foundation allows up to 100 approved domains, GRC Foundation lists risk management with no vendor risk module, and third-party risk has its own listing.1

An estimate pinned to a plan name inherits whatever that plan contained on the day the estimate was collected. Read a published Drata figure as a report about a scope that may not match the current plan. Compare scope before comparing numbers.

What will a Drata quote turn on?

The published limits name the variables: headcount, framework count, tier, add-ons, approved domains and questionnaire volume.1 Bright Defense states that Drata’s pricing is based on the number of frameworks and the employee count.5 SmartSuite reports that Drata’s website describes each plan as offering a fixed number of frameworks and features, with flexible add-ons.4

Ask for a quote that states, in writing:

  1. The plan line and tier for GRC, Assurance and Third-Party Risk Management, each priced separately.
  2. The employee band, and what happens on Foundation when headcount passes 50.
  3. The frameworks included, by name.
  4. Each add-on by name, including Additional Frameworks and User Access Review.
  5. The approved-domain limit and the questionnaire limit, with the 10-versus-100 discrepancy resolved.
  6. Term length and renewal terms, which the plans page doesn’t state.

Then budget the rest. Drata’s SOC 2 cost guide lists audit fees, readiness work, security tools and internal team time alongside the platform subscription, so the Drata quote is one line of the compliance budget.6

Drata’s structure is one way to package this work. Our Laika and Vanta comparison sets two other compliance-automation systems side by side.

What Drata’s plans page cannot tell you

  • A price for any plan, product or add-on.
  • How many frameworks Advanced and Enterprise include.
  • Which questionnaire limit governs Assurance Foundation: 10 on the plan card or up to 100 in the comparison table.
  • What the note “First 25 Free” beside the approved-domains row means for billing.
  • How GRC Foundation’s Trust Center Standard relates to the Assurance Foundation plan.
  • Contract length, renewal terms or discounts.
  • Which features the comparison table marks against each tier. The table shows inclusion with marks that don’t survive as text, so this article reports only the plan cards and the table’s written values.

The verdict changes if Drata publishes a list price or a per-employee rate. Until then, Drata costs whatever the written quote says. Glamdring’s email briefing carries new research as it’s published.

Frequently asked questions

Does Drata have a free plan or free trial?

Drata’s plans page lists no free plan, and every listing leads to a demo request or sales.1 SmartSuite reports that Drata offers a limited free trial on request to its sales team, citing TrustRadius.4 The Drata pages checked for this article don’t mention a trial.

How do you judge whether Drata is good value?

Judge it quote against quote, on the same scope. Price the same frameworks, headcount band, add-ons and Trust Center limits from each shortlisted vendor. Then add the audit fees, tools and internal time that Drata’s own SOC 2 cost guide lists outside the subscription.6 Without a published price, there’s no public figure to judge value against.

What is Drata valued at?

The most recent figure in the sources checked here is $2 billion, the valuation reported for Drata’s $200 million Series C, announced in December 2022.5 That figure comes from Bright Defense, a Drata partner. It’s a funding-round valuation from 2022, not a current market value.

Is Drata cheaper than Vanta?

The published evidence can’t settle it. Bright Defense states that neither Vanta nor Drata publicly shares pricing on its website, and this article checked only Drata’s own pages.5 Request both quotes on the same frameworks, headcount and Trust Center needs, then compare them line by line.

Sources checked

  1. How Much Does a SOC 2 Audit Cost?Checked September 28, 2026

Company-owned pages establish what a company says. They do not prove a market conclusion. Each source is dated so readers can judge each claim.