When a parent company mandates SOC 2 across its portfolio, the challenge is rarely the framework itself. For a software business operating inside a multi-entity holding structure, the real problem was how to launch a compliance program for one business unit without creating a pricing, scoping, and administration mess that would break every other unit that followed. They needed a platform that could handle shared corporate infrastructure without exposing it, separate evidence and personnel cleanly across business units, and scale commercially in a way that did not penalize early adopters. That combination proved harder to find than expected.
[ The Problem ]
A compliance mandate designed for one company, applied to many.
The trigger was a parent-level SOC 2 mandate arriving at a business unit with a hosted product launch on the horizon. Being certified, or visibly in progress, mattered commercially. But the operating environment was a shared Microsoft infrastructure serving multiple business units with separate P&Ls, separate audit scopes, and no appetite for a platform fee that early adopters would absorb on behalf of everyone else.
Manual auditor-only paths were priced out of reach, with estimates running near $20K compared to a target closer to $5K to $7.5K. Spreadsheets and screenshots were not going to survive an audit. And any tool that required corporate IT to ingest a large shared directory and sort it out later was a non-starter. The compliance model had to work at the portfolio level before it could work at the business-unit level, and most tools were not built for that.
[ What they needed ]
Before selecting a platform, the team was trying to:
- Launch a SOC 2 program for the first business unit without locking in a model that would not scale to others
- Separate personnel and evidence cleanly across business units while sharing some corporate controls
- Pre-filter a shared identity directory so corporate IT was not exposed to the full compliance scope
- Find auditor relationships that could bring the total software-plus-audit cost within budget
- Structure pricing so each business unit could be attributed its own cost without subsidizing future adopters
- Ensure the contracting model could be reused across the portfolio without renegotiating from scratch each time
[ Why Drata won ]
Selected over Vanta, which could not match Drata's multi-business-unit architecture or its ability to pre-filter shared Microsoft Entra directories before they entered the compliance scope.
Entra pre-filtering resolved the corporate IT blocker: the team needed to connect a shared identity directory without exposing the full scope to each business unit's audit. Drata's ability to filter users and groups upstream was the specific capability that shifted the evaluation away from Vanta.
Tenant and workspace design matched the portfolio structure: rather than forcing a single-entity compliance model onto a multi-business-unit organization, Drata's architecture allowed each unit to maintain its own audit scope while sharing underlying corporate controls where appropriate.
Pricing was restructured around the buyer's actual problem: removing the platform fee and moving to a per-tenant, per-framework rate card gave each business unit a predictable, attributable cost. That was not a discount negotiation. It was a commercial model that could survive internal P&L allocation and scale without penalizing early adopters.
Roadmap gaps were handled with credibility, not avoidance: when personnel scoping was not fully available, Drata brought product leadership into the conversation, provided a timeline, and offered contract contingency language. The buyer accepted measured product risk because the mitigation was specific and binding.
[ How Drata solved it ]
Drata's tenant and workspace model gave the team a credible architecture for the problem they actually had: one corporate IT layer, multiple business units, each needing its own audit scope without full separation of underlying infrastructure. That structural fit was the foundation of the win.
Drata's Microsoft Entra pre-filtering capability addressed the most sensitive corporate IT concern directly. Rather than ingesting a large shared directory and scoping it down after the fact, the team could filter users and groups before they entered Drata at all. That distinction mattered and was the point where Vanta lost ground in the evaluation.
Integration coverage across AWS, Azure, Intune, Workday, KnowBe4, SharePoint, Jira, and Bitbucket aligned with the intended automation path for the first business unit, with migration and manual CSV options available for systems that required custom connections. Drata's auditor relationships supported the broader business case by bringing the combined software-plus-audit cost within the target range the team had set. And when a personnel scoping feature was not yet fully available, Drata acknowledged the gap plainly, provided roadmap visibility with product leadership involvement, and offered contract language with a contingency if the feature did not land on schedule.
[ Before and after Drata ]
Before Drata, the compliance program had no viable path to scale across business units without creating cost-allocation friction, corporate IT exposure, and audit scope confusion. After, the first business unit is audit-ready and the portfolio has a repeatable architecture, a predictable pricing model, and a contracting pattern that does not require renegotiation for each new unit that joins.
[ Business outcome ]
The first business unit now has an active SOC 2 program in motion, with a hosted product launch no longer blocked by compliance readiness. The compliance architecture is designed to extend across the portfolio, with a pricing model that attributes cost to each business unit independently and does not require renegotiation as additional units join.
Corporate IT retained control over shared infrastructure without being pulled into a brittle admin role for each audit. The combined software-plus-audit cost came in well below the manual-only alternative, and the contracting structure gives the organization a repeatable pattern for onboarding future business units without starting from scratch.