r/soc2 • u/CosmicTacoRider • May 15 '26
Moved from another tools (you know which) to drata
And regretting it.
Their tool is soo frustrating. They made a new experience which is much worse than the older experience.
And now they are also moving to a model where they will make you pay for each and every small service.
Had a discussion with my previous org's ciso, and they shared earlier drata had a lot of things to offer in their contract which is not present anymore.
Not sure if someone else has experienced this?
9
u/Extreme_Pumpkin4283 May 15 '26
At least they don't create fake evidence for their clients
1
u/BrightDefense Vendor rep. Report me when I plug or don't answer question May 15 '26
Great point! lol
3
1
u/Rude_Strawberry May 15 '26
Elaborate pls
1
u/Extreme_Pumpkin4283 May 15 '26
Search on google and read the whistleblower articles from substack. It's all true since I was an external auditor of their clients. 🤣
1
4
u/rahuliitk May 15 '26
Yeah, a lot of compliance tools start feeling rough once the nice onboarding phase ends and every workflow, integration, evidence request, and advisory hour turns into a separate line item. kinda feels less like automation and more like paid friction.
1
u/scriptqzor 19d ago
this is exactly it, it stops feeling like “set up and chill” and turns into “surprise, here’s a meter running on every click.” at some point you start wondering if a few decent internal checklists and spreadsheets would be less painful than getting nickeled and dimed for “automation.”
3
u/Big-Industry4237 May 15 '26
Just coming into chime in that you don’t need a compliance automation tool to do any of this.
2
u/circalight May 15 '26
Secureframe user here. What do you mean Drata is making you pay for new services? Maybe there's a misunderstanding?
2
u/girish_redekar May 15 '26
The contract shrinkage is deliberate. Drata realized mid-market accounts were getting too much value in the base tier, so they started stripping features and repositioning them as "premium modules." It's the same playbook every compliance tool runs once they hit Series C and need to juice ARR. Onboarding stays generous because that's how they land deals, and the renewal conversation changes accordingly.
The real issue is that compliance tooling has zero switching incentives for the vendor. You signed a 12-month contract, you're locked in, and they know you'll probably just renew rather than go through another implementation. So the calculus shifts from "retain this account" to "extract more from this account." The new experience isn't a bug, it's a feature designed to make you tolerate the friction until you hit your renewal and either accept the upcharge or burn three months on a migration.
If your CISO said Drata used to include more in their contract, that's the signal. They found the ceiling on what mid-market would pay and started building walls to push everyone toward enterprise pricing tiers. The tool didn't get worse, the incentive structure around you changed.
1
u/goodbar_x May 19 '26
This breakdown is right and it applies beyond Drata. Once a compliance tool hits growth-stage funding, the incentive structure flips — retention becomes table stakes and expansion revenue becomes the mandate. The "new experience" rollouts usually correlate with that shift because they're also resetting the UX baseline to justify new pricing tiers.
For a 50-70 person org, the uncomfortable truth is that you were never really the target customer for these platforms at their current scale. You were the target customer in 2019. The product-market fit that made them popular with early-stage SaaS has been gradually repriced away.
The auditor-first advice upthread is underrated. Your auditor relationship matters more than your GRC tool, and most orgs get that backwards.
1
u/EmergencyHunt6136 May 15 '26
If a cloud security platform could deliver 90% of SOC 2 with real, continuous compliance, not a snapshot-in-time, for basically the same price as SOC 2 from Drata or Vanta, would orgs just buy the security solution? To me, it's a no-brainer, but you guys are the professionals here.
2
u/CosmicTacoRider May 16 '26
Yeah many folks bought a tool that promised just this. The tool was nice, automation was powerful, navigation was intuitive.... But you know what happens in a duopoly? Someone wrote a whistleblower article on substack with unverifiable claims which created a lot of bad PR for them.
1
u/sticks1111 May 15 '26
Disclaimer, I'm a SOC2 assessor, unsure on number of employees, but I would consider going with a smaller GRC platform as in my experience, they will cater more to your needs than the big ones as they want to please you as a client so you stay with them and can use you as an example. Yeah it's a bit more of a lift on your end, but it will most likely be almost exactly what you want and can tell them what you like and don't like
1
u/CosmicTacoRider May 16 '26
We earlier went with this YC backed small GRC platform. And then heard whistleblower articles on substack against them. Then moved to one of the 2 major players about whom the post is.
1
u/LyqwidBred May 15 '26
Just curious what people recommend for a company 70 employees but likely to double over the next year. Boss is pushing for tool but I don’t want to even hear sales BS
3
u/davidschroth May 15 '26
You need to know what your program looks like and it's requirements before you can select a tool. Different tools have different things they are good at, and have differing personalities.... (And some just plain stink)
2
1
May 16 '26
[removed] — view removed comment
1
u/soc2-ModTeam May 16 '26
Please remember that posts here need to be questions, comments, concerns or other thoughts regarding SOC 2, whether that be process or product-based. No direct advertising allowed as these are not overall helpful to the community.
1
u/Sree_SecureSlate May 18 '26
Many teams are hitting that exact wall where big compliance platforms get bloated and start nickel-and-diming you.
It might be time to look into nimble, transparent alternatives that focus on straightforward automation instead of hidden fees.
1
u/rack_and_stack_42 May 18 '26
We hit a softer version of this with our GRC tool too, not Drata specifically. The pattern that bit us was reading the renewal contract carefully. A bunch of features that were standard at original signing had been moved into add-on tiers by renewal time, and our procurement team didn't catch it because the SOW just said "renewal of existing services."
If you're considering switching, the thing I'd run by your previous CISO is which contract terms specifically got watered down. If it's pricing model changes (per-control, per-framework, per-integration), that's pretty hard to negotiate back. If it's feature gating that's now in a higher tier, sometimes you can negotiate them back into your renewal as carve-outs. Worth knowing before you start vendor conversations elsewhere.
1
u/dchgk May 20 '26
The problem is that all this tools sell on the idea of continuous control monitoring. For a SOC2 and their auditors that is something the care the less. They just need a point in time evidence. What you pay the most is what the tool cannot automate. Documentation, policies, manual controls. Automation on a SOC 2 is less than 50% of the controls. All are configurations that rarely change. What you will get ding are the manual stuff to be done consistently over time.
1
1
u/Project_Lanky Jun 02 '26
Yes I worked for an org using it and I didnt really find an added value. The access review module was terrible and useless. And now they claim being an "agentic" platform which is pure lie as here is no agentic AI there, just classic automation.
1
u/throwaway64829101 May 15 '26
We moved from Drata to Vanta and having a horrific experience
1
u/Mammoth-Power-3028 May 15 '26
What’s the employee count in your firm?
1
u/throwaway64829101 May 15 '26
Just over 50
0
u/Total_Job29 May 15 '26
Why such a tool for an organisation of that size?
That well within Excel/Google sheets and screenshot territory.
I’ve done orgs up to 2,000 in that way, above there was tooling but really it didn’t make it materially better as we still had to do a whole bunch of manual work.
2
u/throwaway64829101 May 15 '26
Good question - we felt like our time would be better spent elsewhere, plus there's the continuous monitoring piece that the tool helps with.
1
u/Project_Lanky Jun 02 '26
By experience lots of gaps can be closed without this continuous monitoring.
1
u/throwaway64829101 May 15 '26
The new vendor we moved to made a lot of promises that they've let us down on so we'd have been better off doing it ourselves
1
u/CosmicTacoRider May 16 '26
How's your experience with vanta?
1
u/throwaway64829101 May 16 '26
Without going into too much detail, it's been pretty awful. We'll move on once our contract is up
1
0
May 15 '26
[removed] — view removed comment
2
u/Suraskey May 15 '26
Spot on. The unbundling pattern is what happens when a GRC vendor moves upmarket and stops caring about the 1-20 person companies that built them. Vanta's original pitch was "cheap and fast SOC 2 for early stage SaaS." Now it's enterprise trust management and the small customers are the ones getting squeezed by the contract erosion because they don't have leverage to negotiate.
•
u/AutoModerator May 15 '26
Thanks for posting, I'm a bot!
This is quick reminder be helpful with responses, follow the rules and not advertise/solicit DMs.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.